Okta Desktop MFA Configuration without Adaptive MFA
Last Updated:
Overview
This article outlines necessary changes to configure Desktop MFA with the Device Access SKU only (without the Adaptive MFA SKU).
Applies To
- Okta Identity Engine (OIE)
- Okta Device Access (ODA)
- Desktop MFA for Windows
Solution
Okta Device Access (ODA) requires the device certificate to be deployed to the computer. An external Certificate Authority (CA) or Okta's CA can be used for this purpose.
Follow those steps to use the CA specifically for Okta Device Access:
- In the Okta Admin Console, go to Security > Device Integrations.
- Ensure to select the Device Access tab. Do not configure Endpoint Management because the Desktop (Windows and macOS only) platform will not be available, according to the Unable to Add Platform for Mac and Windows in Device Integrations article when the Adaptive MFA SKU is not available.
- Click on Add SCEP configuration.
- In the MDM, deploy a configuration profile set to Computer Level.
