<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
How to Enable FIPS Encryption on Okta Verify
Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine
Overview

This feature is currently in Early Access (EA). To enable it for the Okta Org, please contact Okta Support. Once enabled, follow the steps below.

Applies To
  • Okta Verify
  • Multi-Factor Authentication (MFA)
Cause
 
 
Solution

NOTE: If this feature is not available in the org, please open a ticket with Okta Support, referencing this article. 
 

In Okta Classic Engine

  1. First, enable the feature by going to Okta Admin Console > Settings > Features > FIPS compliance.

FIPS compliance

  1. After that, go to Security > Multifactor. The Factor Types screen appears with Okta Verify as the default selection.
  2. Under Okta Verify > Okta Verify Settings, click Edit.
  3. To enable, select Enable FIPS-mode encryption.
  4. Click Save once the changes are made.

Enable FIPS-mode encryption


In Okta Identity Engine

  1. First, enable the feature by going to Okta Admin Console > Settings > Features > FIPS compliance.

FIPS compliance

  1. After that, go to Security > Authenticators.

  2. From the Setup tab, select Edit Okta Verify.
    Edit button 

  3. In the FIPS Compliance field, choose whether Users enrolling in Okta Verify can use FIPS compliant devices only or Any device.

  4. Click Save once all the desired changes are made.
    FIPS compliance 


FIPS Compatibility Mode for Okta FastPass on Desktop devices

The FIPS compatibility mode for push (ported from classic) relies on a previous set of NIST definitions of AAL2, which have since been superseded (for example, phishing resistance is now required for AAL2). As a result, this checkbox does not achieve the desired compliance (this is why it is not General Availability (GA) for FastPass). Okta is working to achieve FedRAMP Moderate compliance (including FIPS) for FastPass across all platforms.
 

Loading
How to Enable FIPS Encryption on Okta Verify