> For the complete documentation index, see [llms.txt](https://docs.oort.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.oort.io/understanding-check-failures/oort-insights/identity-posture-management-insights/users-sharing-authenticators.md).

# Users Sharing Authenticators

Detects users whose phone number-based authenticators or Okta hardware security keys are registered to multiple accounts, which reduces individual accountability and can allow a single compromised or shared device to be used to access more than one identity.

Users should not share authentication credentials and should have their own dedicated authenticator so that a compromised or stolen device cannot be used to gain unauthorized access across multiple accounts within your organization.

**Recommended Actions**

Review the failing users to determine whether the shared authenticator represents an unintentional security gap or a known legitimate case, such as an admin account sharing with its associated day-to-day account. Link any accounts with a legitimate sharing need in Identity Intelligence so that these accounts will no longer fail the check, as linked accounts are treated as intentionally associated.

For all other cases, remove the shared authenticator from the additional accounts and contact the affected users. If a large number of users are failing this check, review your account onboarding process to ensure new accounts are not being provisioned with a shared or generic phone number or hardware security key.

**Compatibility**

[Okta](/integrations/okta-data-integration.md)

[Duo](/integrations/duo-security-integration.md)

[Microsoft Entra ID](/integrations/azure-active-directory-integration.md)
