<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Okta Mobile is Not Supported on Okta Identity Engine
Administration
Okta Classic Engine
Okta Identity Engine
Overview

The following reconfiguration has been identified as part of the preparation needed to perform the upgrade to Okta Identity Engine (OIE). Note that additional Okta features may require reconfiguration or be disabled in order to complete the upgrade. Okta Mobile will not be supported on our Okta Identity Engine (OIE) platform. To access applications on mobile devices, it is recommended to use the mobile browser, which will offer most of the same functionality. However, Secure Web Authentication (SWA) through Okta Mobile will not be supported on OIE.

Applies To
  • Okta Mobile

  • Okta Identity Engine Upgrade
Cause

Okta Mobile and Secure Web Authentication (SWA) on mobile are not incorporated into the Okta Identity Engine (OIE) platform. The OIE platform is built on a modular, API-driven architecture that provides greater flexibility for identity and access management (IAM). OIE offers advanced authentication mechanisms, including adaptive authentication, OAuth, and OpenID Connect, which provide a more robust and secure authentication experience than SWA.

 

Solution
  1. Notify end users that Okta Mobile will not be available after the upgrade.

  2. Guide users to one of the following replacements based on the use case:

    • For accessing applications on mobile devices

      • Use the Launch Dashboard in Okta Verify or go to <orgName>.okta.com in a mobile browser. This provides the same experience for Security Assertion Markup Language (SAML), OpenID Connect (OIDC), and Web Services Federation (WS-Federation) flows.

    • For SWA applications

      • The mobile browser presents the credentials for the user to copy and paste into the application. For a more seamless experience, a password manager can be used to auto-fill the credentials after the first time.

    • For SWA applications with admin-managed credentials

      • Credentials are not presented to the user. One of the following actions is required:

        • Convert the application from SWA to use SAML or OIDC.

        • Change the application settings from being admin-managed.

        • Investigate third-party solutions, such as Cerby.

  3. To identify users of the Okta Mobile application, run one of the following System Log searches:

    • Okta Mobile on iOS:

      client.userAgent.rawUserAgent co "com.okta.ios.mobile"

      
      
    • Okta Mobile on Android:

      client.userAgent.rawUserAgent co "Dalvik/2.1.0" and client.userAgent.rawUserAgent co "OktaMobile"

      
      

       

Related References

Loading
Okta Mobile is Not Supported on Okta Identity Engine