Skip to content
Help Center

Issue Okta temporary access codes with Persona

View Markdown Contact support Contact support 6 min read
On this page

About Okta temporary access codes

Okta supports a temporary access code (TAC) authenticator. A TAC is a short-lived code that lets a user sign in when they can’t use their usual authenticators, for example when they lose their phone or forget their security key. Once signed in, the user can enroll new authenticators. Okta expects the administrator who creates a code to verify the user’s identity first, then hand the code over through a secure channel.

With Persona, the employee proves who they are with a government ID and selfie verification. Persona compares the name on the ID with their Okta profile, and only then generates the temporary access code and shows it to the employee. This helps protect account recovery against social engineering, deepfakes, and account takeover, and your helpdesk never handles the code.

How it works

  1. Your helpdesk sends the employee a Persona verification link.
  2. Persona looks up the employee in Okta by their Okta login email.
  3. The employee completes a government ID and selfie verification. Persona compares the government ID with the employee’s Okta profile.
  4. If the verification passes, Persona generates a temporary access code in Okta and shows it on the final screen.
  5. The employee signs in to Okta with the code and enrolls a new authenticator.

Use a Persona organization dedicated to your workforce, separate from any organization that verifies your customers, so employee and customer data stay apart. Ask your Persona contact if you don’t have one yet.

Okta Configuration Guide

Follow the steps below to issue Okta temporary access codes with Persona. The Okta temporary access code wizard in the Persona Dashboard walks you through the same steps and checks your setup as you go.

1. Configure Persona Marketplace Integration for Employee Data

Context

Persona requires API access to your Okta tenant, both to look up the employee and to generate their temporary access code.

In order to ensure the employee being verified matches the Okta account being recovered, Persona compares the values extracted from the employee’s government ID with the first and last name stored in their Okta user profile.

Please ensure that the names that are stored in Okta are employee legal names, rather than preferred names or nicknames.

Connect Okta

  1. Follow the Okta Marketplace integration guide to create an Okta API credential, and add it under Integrations > Marketplace > Okta in the Persona Dashboard.
  2. Grant the credential the okta.users.read, okta.users.manage, and okta.authenticators.read scopes, and an admin role that can view users and manage their temporary access codes for the employees in scope.
  3. Use Test to check the connection before continuing.

2. Turn on the temporary access code authenticator in Okta

Persona can’t generate a code until the authenticator is on for the employee.

  1. In the Okta Admin Console, go to Security > Authenticators, select Add Authenticator, and add Temporary Access Code.
  2. Set the minimum, maximum, and default expiry lengths, the character length, and the code complexity. Persona generates codes with the default expiry length.
  3. Leave Allow multi-use codes off unless you want a code to work more than once. Persona asks for single-use codes.
  4. On the Enrollment tab, check that the authenticator is Optional for the employees who may recover this way.
  5. In the authentication policy for the app employees sign in to, such as the Okta Dashboard, add a rule that allows Temporary Access Code as an authentication method. A temporary access code is a single knowledge factor, so a rule that requires two factor types won’t accept it.
  6. Copy the authenticator’s ID from Security > Authenticators > Temporary Access Code. It looks like aut8j8vbvcr5b4a8l0g7. You’ll need it in the next step.

3. Configure the Persona inquiry template

Persona provides a ready-made inquiry template for this flow, with the workflows that look up the employee and generate the code. The wizard installs it in your workforce organization and applies your answers to it. Check the following before you publish.

  1. In the two Find or Create Account steps and the Fetch Account Object step, select your account type.
  2. In the two Get Okta User steps and the Generate a temporary access code for a user step, select the Okta credential from Step 1.
  3. In the Generate a temporary access code for a user step, replace REPLACE_WITH_OKTA_TAC_AUTHENTICATOR_ID with the authenticator ID from Step 2.
  4. In the government ID verification template, check that the Inquiry comparison check is on and fails the verification on a mismatch, so a code is only generated for the person named in Okta.
  5. Review the success and failure workflows. They email the employee when an inquiry completes or fails, and email your administrators when Persona can’t find the employee in Okta after repeated attempts. Set the recipients and contact addresses to your own.
  6. Publish the verification templates, then the workflows, then the inquiry template.

4. Start account recovery for an employee

Okta doesn’t send a locked-out employee to Persona on its own, so your helpdesk starts recovery.

  1. In the Persona Dashboard, go to Inquiries and create an inquiry from the installed template.
  2. Set the Reference ID to the employee’s Okta login email, or set the account type to No Account. Otherwise the inquiry creates a second account for the employee, and Persona can’t recognize repeat attempts. If you leave both out, the employee enters their email in the flow.
  3. Send the employee the inquiry link.

When the employee passes, the final screen shows their temporary access code with a copy button. The code is only shown once. An employee who leaves the screen without copying it needs a new inquiry.

5. Test the integration

  1. Send an inquiry to a test employee and complete it.
  2. Confirm that the final screen shows a temporary access code, and that the copy button copies the code itself.
  3. Sign in to Okta as the test employee with the code, and enroll a new authenticator.
  4. Test the failure path too. Fail an inquiry on purpose and confirm that no code is generated.

Okta allows one active temporary access code per user, so each test run replaces the previous code. Test with a user whose current code you don’t need.

Plans Explained

Okta Integration by plan

Startup ProgramEssential PlanGrowth PlanEnterprise Plan
Okta IntegrationNot AvailableNot AvailableLimitedAvailable

Learn more about pricing and plans.

Last updated on .

Was this page helpful?If something is missing, let us know and we will take a look.
Thanks for the feedback. It helps us improve these docs.