## TL;DR
Okta enrollment links expire, commonly after a few days or after first use, and there is nothing wrong with the user's account. The fix is an admin resend from the Okta console plus telling the user to complete enrollment promptly this time. If it keeps happening, check the org's enrollment token lifetime setting.

## The query
```text
okta enrollment token expired: what to tell the user
```

## Use this when
- user says the Okta setup link no longer works
- new hire never finished enrollment and the invite lapsed
- repeated expired-token tickets for the same team

## Not for
- account lockouts or wrong-password errors
- MFA factor already enrolled but not working
- deprovisioned users (do not re-enroll them)

## Steps
1. In the Okta admin console, find the user and confirm their status is still staged or pending. Expected output: status confirms enrollment was never completed
2. Resend the activation email or generate a new enrollment link from the user's profile actions. Expected output: a fresh activation message goes out
3. Tell the user the new link also expires, and to complete enrollment now on the device they will actually use. Expected output: the user confirms receipt
4. Walk them through installing the authenticator app and scanning the QR code. Expected output: enrollment completes and the factor shows active
5. If it expires a third time, check the org's enrollment token lifetime setting before resending again. Expected output: you know whether the lifetime needs lengthening

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_cr3iGuCBBs-Mc0kTjGDMBg
