We are preparing to implement user provisioning via Okta, and as a result, we want to completely disable any way for users to log in with any email other than the one tied to our Okta SSO.
For example, users can log in with username@mycompany.com with Okta SSO, but any other email will be rejected out of hand.
Right now there seems to be an out-of-box access policy that pretty much lets people sign up with any email address they want. This access policy is marked as a “Default” right next to our Okta policy which confusingly is also labeled “Default”