Skip to main content
Version: 11.3.0

Okta Password Reset for HYPR Affirm

When a requester successfully completes a HYPR Affirm verification flow, HYPR can send the requester to an Okta password reset page as the outcome, where they set a new Okta password. This integration suits account recovery workflows where the user has lost access and needs a fresh credential after verifying their identity.

This integration requires an Okta integration configured in HYPR Control Center and the appropriate Okta password policy configuration to allow self-service resets.

Workflow-side configuration

For where the Okta Password Reset outcome is selected in the verification flow editor, see Configure Verification Steps → Verified Outcome.

Beta feature

Some functionality is limited. This article is subject to change as the feature develops.

Okta Password Policy Configuration​

The ability to reset a password in Okta depends on the tenant's password-policy configuration. To check the configuration, go to Security > Authentication in your Okta tenant.

Okta admin navigation with Security expanded and Authentication selected

Okta displays the configured password policies for your Okta tenant.

Okta Authentication page on the Password tab, showing the Default Policy assigned to Everyone with Okta as the authentication provider

To allow password resets for your users under a policy such as the preceding default policy, the policy must have a rule at the bottom that allows password resets.

Default Policy rule list with the Default Rule active, granting change and reset access with Self-Service Password Reset set to Yes

Active Directory Users Synced to Okta​

If your Okta tenant has users synced with Active Directory, the default rule in the Active Directory policy might not permit password resets.

Okta password policies list with the Active Directory Policy selected above the Default Policy, applying to Active Directory

For your users to reset their passwords, you must add a new rule.

Active Directory Policy rules with a new Allow password reset rule at priority 1, granting Change and Reset access with Password reset set to Yes

For detailed information, see the Okta knowledge base article Users unable to reset AD password through Okta.