<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Canceling Okta Verify FastPass Fingerprint Requires Multiple Attempts

Okta Classic Engine
Okta Identity Engine
FastPass

Overview

Okta Verify FastPass requires two cancellations before presenting the user with the option to verify with a different factor. This occurs because Okta automatically attempts to satisfy the Multi-Factor Authentication (MFA) requirement using the biometric key of the enrolled device, re-triggering the prompt once if the user cancels it. This is expected behavior, as Okta prioritizes the most secure factor before allowing a fallback.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Verify FastPass
  • Multi-Factor Authentication (MFA)

Cause

This behavior occurs because Okta FastPass with biometrics automatically attempts to satisfy the MFA requirement using the biometric key of the enrolled device. When an administrator enables FastPass, Okta first tries to complete authentication silently or through a biometric prompt. If the user cancels that prompt, the browser re-triggers the FastPass attempt once more before finally presenting the Verify with something else option.

Solution

Why does Okta Verify FastPass require multiple cancellations?

This is expected behavior when FastPass with biometrics is active. Okta prioritizes the most secure and seamless factor, which is FastPass, before allowing fallback to other factors like Okta Verify Push or YubiKey. Administrators do not need to take further action.

Loading
Canceling Okta Verify FastPass Fingerprint Requires Multiple Attempts | Okta Support