CAPTCHA integration – best practices
By default, CAPTCHA integration is disabled in Okta's General Security settings.
Enabling CAPTCHA for Okta login can enhance the security of the authentication process by adding an additional layer of protection against automated login attempts. However, it's important to balance security with user experience to avoid unnecessary frustration for legitimate users.
CAPTCHA integration
We recommend you do not enable CAPTCHA because it increases friction in the user login experience, and users are already strongly secured if you follow our other configuration recommendations. However, we understand some customers might consider this option if breached before or there is a heightened risk. The two options for CAPTCHA provider are the following:
hCaptcha
reCAPTCHA v2 (Google)
Learn how to integrate CAPTCHA with your login process (Okta documentation).