<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Additional Push Notifications when Using Passwordless Sign In

Okta Device Access
Okta Identity Engine

Overview

This article details a known issue in Okta Device Access (ODA) Windows Desktop MFA with Okta Verify version 5.6 and above.

While using Okta Desktop MFA with passwordless authentication a push notification is sent to the end user’s mobile device before clicking the “Sign In” button.

 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Device Access (ODA)
  • Desktop MFA
  • Windows Devices

Cause

Modifications to the Desktop MFA authentication policy can cause some users to receive an extra push notification. Okta recommends not modifying this policy.

In this case, an administrator configures an authentication policy to restrict the use of authentications to a specified list shown below. Once saving this policy they receive reports of users getting extra push notifications during the login flow.

authentication methods

Solution

  1. Remove the restriction on allowing or disallowing specific authenticators by selecting the option to Allow any method that can be used to meet the requirements.
    authentication methods   
  2. If the administrator wishes to restrict the authenticators displayed to end users, the following steps can be taken.
    1. Enable DirectAuth refer to the Enable FIDO2 for the Desktop MFA client documentation
    2. Configure the AllowedFactors list with the authenticators to be displayed to end users. Ensure if offline login is allowed to include the offline factors to display as well.
Loading
Okta Support - Additional Push Notifications when Using Passwordless Sign In