.. configure-okta-policies.rst .. _config-policies: ===================================== Configuring Okta Policies ===================================== This section describes how to create user groups and configure phishing-resistant authentication policies in Okta to support the Yubico FIDO Pre-reg integration. Creating User Groups ======================= Create groups for new and existing users in Okta. For information on how to do this, see `Create groups for new and existing users (Okta documentation) `_. Configuring Global Session Policy =================================== Create a Global Session Policy that is configured to establish the user session with any factor that is *not a password*. For information on how to do this, see `Configure a global session policy (Okta documentation) `_. Configuring Authenticator Enrollment Policy ============================================= Authenticator enrollment policies let you manage how and when your end users enroll authenticators, for example to use “WebAuthn Only”. For more information, see `Configure an authenticator enrollment policy (Okta documentation) `_.