About Okta temporary access codes
Okta supports a temporary access code (TAC) authenticator. A TAC is a short-lived code that lets a user sign in when they can’t use their usual authenticators, for example when they lose their phone or forget their security key. Once signed in, the user can enroll new authenticators. Okta expects the administrator who creates a code to verify the user’s identity first, then hand the code over through a secure channel.
With Persona, the employee proves who they are with a government ID and selfie verification. Persona compares the name on the ID with their Okta profile, and only then generates the temporary access code and shows it to the employee. This helps protect account recovery against social engineering, deepfakes, and account takeover, and your helpdesk never handles the code.
How it works
- Your helpdesk sends the employee a Persona verification link.
- Persona looks up the employee in Okta by their Okta login email.
- The employee completes a government ID and selfie verification. Persona compares the government ID with the employee’s Okta profile.
- If the verification passes, Persona generates a temporary access code in Okta and shows it on the final screen.
- The employee signs in to Okta with the code and enrolls a new authenticator.
Use a Persona organization dedicated to your workforce, separate from any organization that verifies your customers, so employee and customer data stay apart. Ask your Persona contact if you don’t have one yet.
Okta Configuration Guide
Follow the steps below to issue Okta temporary access codes with Persona. The Okta temporary access code wizard in the Persona Dashboard walks you through the same steps and checks your setup as you go.
1. Configure Persona Marketplace Integration for Employee Data
Context
Persona requires API access to your Okta tenant, both to look up the employee and to generate their temporary access code.
In order to ensure the employee being verified matches the Okta account being recovered, Persona compares the values extracted from the employee’s government ID with the first and last name stored in their Okta user profile.
Please ensure that the names that are stored in Okta are employee legal names, rather than preferred names or nicknames.
Connect Okta
- Follow the Okta Marketplace integration guide to create an Okta API credential, and add it under Integrations > Marketplace > Okta in the Persona Dashboard.
- Grant the credential the
okta.users.read,okta.users.manage, andokta.authenticators.readscopes, and an admin role that can view users and manage their temporary access codes for the employees in scope. - Use Test to check the connection before continuing.
2. Turn on the temporary access code authenticator in Okta
Persona can’t generate a code until the authenticator is on for the employee.
- In the Okta Admin Console, go to Security > Authenticators, select Add Authenticator, and add Temporary Access Code.
- Set the minimum, maximum, and default expiry lengths, the character length, and the code complexity. Persona generates codes with the default expiry length.
- Leave Allow multi-use codes off unless you want a code to work more than once. Persona asks for single-use codes.
- On the Enrollment tab, check that the authenticator is Optional for the employees who may recover this way.
- In the authentication policy for the app employees sign in to, such as the Okta Dashboard, add a rule that allows Temporary Access Code as an authentication method. A temporary access code is a single knowledge factor, so a rule that requires two factor types won’t accept it.
- Copy the authenticator’s ID from Security > Authenticators > Temporary Access Code. It looks like
aut8j8vbvcr5b4a8l0g7. You’ll need it in the next step.
3. Configure the Persona inquiry template
Persona provides a ready-made inquiry template for this flow, with the workflows that look up the employee and generate the code. The wizard installs it in your workforce organization and applies your answers to it. Check the following before you publish.
- In the two Find or Create Account steps and the Fetch Account Object step, select your account type.
- In the two Get Okta User steps and the Generate a temporary access code for a user step, select the Okta credential from Step 1.
- In the Generate a temporary access code for a user step, replace
REPLACE_WITH_OKTA_TAC_AUTHENTICATOR_IDwith the authenticator ID from Step 2. - In the government ID verification template, check that the Inquiry comparison check is on and fails the verification on a mismatch, so a code is only generated for the person named in Okta.
- Review the success and failure workflows. They email the employee when an inquiry completes or fails, and email your administrators when Persona can’t find the employee in Okta after repeated attempts. Set the recipients and contact addresses to your own.
- Publish the verification templates, then the workflows, then the inquiry template.
4. Start account recovery for an employee
Okta doesn’t send a locked-out employee to Persona on its own, so your helpdesk starts recovery.
- In the Persona Dashboard, go to Inquiries and create an inquiry from the installed template.
- Set the Reference ID to the employee’s Okta login email, or set the account type to No Account. Otherwise the inquiry creates a second account for the employee, and Persona can’t recognize repeat attempts. If you leave both out, the employee enters their email in the flow.
- Send the employee the inquiry link.
When the employee passes, the final screen shows their temporary access code with a copy button. The code is only shown once. An employee who leaves the screen without copying it needs a new inquiry.
5. Test the integration
- Send an inquiry to a test employee and complete it.
- Confirm that the final screen shows a temporary access code, and that the copy button copies the code itself.
- Sign in to Okta as the test employee with the code, and enroll a new authenticator.
- Test the failure path too. Fail an inquiry on purpose and confirm that no code is generated.
Okta allows one active temporary access code per user, so each test run replaces the previous code. Test with a user whose current code you don’t need.
Related resources
- Okta integration overview
- Using Persona Workflows to manage Okta users & profiles
- Okta: Configure the temporary access code authenticator
Plans Explained
Okta Integration by plan
| Startup Program | Essential Plan | Growth Plan | Enterprise Plan | |
|---|---|---|---|---|
| Okta Integration | Not Available | Not Available | Limited | Available |