Configure Allowed Factors Policy For Okta Device Access Desktop MFA
Last Updated:
Overview
Administrators configure the Allowed Factors policy for Okta Device Access Desktop multi-factor authentication (MFA) by deploying a specific registry key to Windows endpoints. This configuration restricts or orders the authentication methods available to end-users during desktop login.
Applies To
- Okta Identity Engine (OIE)
- Okta Device Access Desktop MFA
- Windows
Solution
How is the Allowed Factors policy configured for Okta Device Access Desktop MFA?
Configure the Allowed Factors policy by enabling direct authentication and adding the required registry key with the accepted multi-factor authentication values.
- Activate the UseDirectAuth setting in the following registry path:
- Add the AllowedFactors registry key under the following registry path:
- Populate the AllowedFactors key using the
REG_MULTI_SZvalue type with the accepted factors.
NOTE: Populate the entries vertically. Do not separate the entries with commas, as they do not appear on the list of available factors to enroll.
