A user receives a new phone or tablet and installs Okta Verify. However, the application fails to receive push notifications, or Okta rejects the Multi-Factor Authentication (MFA) codes it provides during an authentication challenge.
When a user replaces a device, Okta Verify requires re-enrollment because Okta ties the account to the original hardware. To resolve this, the user must set up Okta Verify on the new device via the Okta End-User Dashboard or by using Bluetooth to synchronize from the original device. After setting up the new device, Okta Verify push notifications and MFA codes function correctly.
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Verify
- iOS devices
- Android devices
- Multi-Factor Authentication (MFA)
When a user enrolls a device in Okta Verify, Okta links the account to the specific application and hardware. Consequently, replacement devices require re-enrollment to ensure that push notifications and codes function correctly. Additionally, restoring a device from a backup removes stored biometric data, necessitating re-enrollment.
How does a user set up Okta Verify on a new device?
The following video demonstrates the Okta Verify setup process on a new device.
NOTE: If the user cannot sign in or access their settings because the organization requires Okta Verify, the user must contact their Information Technology (IT) team to request a multifactor authentication reset.
If the original device is available, use the following steps to add an existing Okta Verify account to a new device using Bluetooth:
- Open Okta Verify on the original device.
- Select the account.
- Choose Add account to another device and follow the instructions.
- Install Okta Verify on the new device.
- Open the application and select Add Account from Another Device.
- Scan the QR code displayed on the original device.
- Enter the 6-digit PIN displayed in Okta Verify on the new device into Okta Verify on the original device to confirm the pairing.
- Follow the instructions to complete the setup.
If the original device is unavailable, use the following steps to add a new device from the Okta End-User Dashboard:
- Sign in to Okta using a different factor.
- Select the Name dropdown menu in the Okta End-User Dashboard.
- Choose Settings.
- Navigate to Extra Verification or Security Methods.
NOTE: This section appears only if the organization configures it as an option. If it is not present, the user must contact their IT team.
Use the following steps to configure a new device if Okta Verify resides under Security Methods:
- Select Set up another.
- Confirm the identity when Okta prompts.
- Select Set up to confirm setting up Okta Verify. This action displays a QR code to scan for setting up the new device.
Use the following steps to configure a new device if Okta Verify resides under Extra Verification:
- Select Remove.
- Choose Yes to confirm the removal when prompted by Okta.
- Follow the on-screen instructions. Confirm the identity with a security method, if required.
- Select Set up in the Okta Verify row.
- Choose Set up again to confirm configuring a new Okta Verify.
- Select the device type (Android, iOS) and select Next. This action displays the QR code to scan for setting up the new device.
Scanning the Okta Verify enrollment QR code securely links the new device to the user account. Ensure the user selects the correct device type (iPhone or Android) when enrolling in Okta Verify. Selecting the incorrect device type causes Okta to return the following error:
Unrecognized QR code.
To resolve this error, the user must request a multifactor authentication reset and clear the browser cache and cookies.
NOTE: If a user restores Okta Verify on the device from a backup, they might need to remove the existing accounts from the Okta Verify application, then re-enroll them using the steps above.
Complete the following steps to remove an account on iOS devices:
- Open the Okta Verify application on the device.
- Select Edit.
- Choose the "Red icon" next to the account.
- Tap Delete.
Complete the following steps to remove an account on Android devices:
- Open the Okta Verify application on the device.
- Tap the three dots to the right of the account.
- Tap Delete.
