Configure Biometrics as Preferred or Required for Okta Verify Sign-In
Last Updated:
Overview
Administrators can configure biometric authentication, such as fingerprint or facial recognition, as preferred or required when users sign in with Okta Verify. This configuration determines whether users must enable biometrics during setup and whether they can disable the feature later.
Applies To
- Okta Identity Engine (OIE)
- Okta Verify
- Multi-Factor Authentication (MFA)
Solution
How is biometric authentication configured for Okta Verify?
Navigate to the authenticator settings in the Okta Admin Console to edit the Okta Verify configuration and set user verification to either required or preferred.
- Sign in to the Okta Admin Console.
- Navigate to Security > Authenticators.
- Select Actions and then Edit on the Okta Verify authenticator.
- Choose whether User Verification is Required or Preferred.
Administrators Can Set Biometric Verification as a Requirement
When administrators require user verification, users must enable biometrics on all platforms during setup, and Okta Verify Push requires biometric verification during authentication.
NOTE: Users cannot disable biometrics after setup is complete.
Administrators Can Set Biometric Verification as a Preference
When administrators set user verification as preferred, users can enable biometrics during setup or later in the application, and they can disable biometrics at any time after setup is complete.
