Okta Password Reset for HYPR Affirm
When a requester successfully completes a HYPR Affirm verification flow, HYPR can send the requester to an Okta password reset page as the outcome, where they set a new Okta password. This integration suits account recovery workflows where the user has lost access and needs a fresh credential after verifying their identity.
This integration requires an Okta integration configured in HYPR Control Center and the appropriate Okta password policy configuration to allow self-service resets.
For where the Okta Password Reset outcome is selected in the verification flow editor, see Configure Verification Steps → Verified Outcome.
Some functionality is limited. This article is subject to change as the feature develops.
Okta Password Policy Configuration
The ability to reset a password in Okta depends on the tenant's password-policy configuration. To check the configuration, go to Security > Authentication in your Okta tenant.
Okta displays the configured password policies for your Okta tenant.
To allow password resets for your users under a policy such as the preceding default policy, the policy must have a rule at the bottom that allows password resets.
Active Directory Users Synced to Okta
If your Okta tenant has users synced with Active Directory, the default rule in the Active Directory policy might not permit password resets.
For your users to reset their passwords, you must add a new rule.
For detailed information, see the Okta knowledge base article Users unable to reset AD password through Okta.
Related
- Configuring HYPR Affirm — author and configure verification flows
- Verified Outcome — outcome configuration in the workflow editor