Exempt users without valid authentication methods
CyberArk Identity looks into the user’s Active Directory/LDAP or CyberArk Cloud Directory account for the mobile phone number or email address used for multifactor authentication. Normally, users without a mobile phone number or email address cannot log into CyberArk Identity Connector when you enable authentication policy controls.
To exempt users from multifactor authentication when their account does not have a mobile phone number and email address:
- Log in to the Identity Administration portal.
- Click Core Services > Policies.
- Select the relevant policy or create a new one.
- Click Login Polices > CyberArk Identity.
- Enable the Allow users without a valid authentication factor to log in setting in the Other Settings section.
- Click Save.