← Course Home
Okta Certified Administrator · Part II

Security Enforcement

23% of Part II — the final and most policy-heavy use case.

Security Enforcement

Task 2: Set Up an MFA Enrollment Policy

5 tasks · this deck covers task 2 of 5

↑ Security Enforcement Overview

The Task

"Set up an MFA enrollment policy"

Task 1 turned an authenticator on. This task is about controlling who gets asked to enroll in it, when, and how much runway they get before enrollment becomes mandatory.

The Mechanism

Authenticator enrollment policies manage "how and when your end users enroll authenticators." Each authenticator can be designated Required, Optional, or Disabled for enrollment.

These policies are rule-based — scoping enrollment by conditions like which app a user is accessing, or their geographic location.

The Distinction — Not the Same as Sign-On Policies

Enrollment policies are separate from sign-on policies, but they interact: "Okta may prompt users to enroll more authenticators if the global session policy, app sign-in policy, or password policy require them."

In other words, a sign-on policy can demand a factor the user hasn't enrolled yet — and that's what triggers the enrollment prompt, even outside the enrollment policy's own rules.

The Gotcha — Two Grace Period Types

End date — daily enrollment prompts until a specific date, then enrollment becomes mandatory
Skip count (Early Access) — prompts continue until the user skips a set number of times, then mandatory

Once either grace period expires, the option to proceed without enrolling disappears entirely.

The Angle — What Trips People Up

Watch for these in your own sandbox run:

→ Confusing enrollment policy (who enrolls, when) with sign-on policy (what's required at login) — they're separate, interacting systems.

→ Not realizing skip-count grace periods are an Early Access feature, not available by default.

One Line To Remember

Enrollment policies set each authenticator to Required/Optional/Disabled, scoped by rules (app, location). They're distinct from sign-on policies, though sign-on policies can still trigger enrollment prompts. Two grace period types: end-date (daily prompts until a date) or skip-count (Early Access) — either way, once it expires, enrollment becomes mandatory.

Sources: help.okta.com — about-mfa-enrollment-policies.htm