<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Desktop Password Sync Notification to Enable Offline Login in macOS Sequoia Can Cause Keychain Deletion
Okta Device Access
Okta Identity Engine
Overview

Machines previously enrolled in Okta Desktop Password Sync receive the following pop-up notification during login after upgrading to macOS Sequoia:

 

Example of Password Sync notification

 

The pop-up is to enable offline login.  Choosing Enter Previous Password and entering the previous macOS password will result in everything being OK, clicking Cancel will make the pop-up reappear later, however, clicking Use Identity Provider Password will result in the following:

  • The keychain is wiped
  • Touch ID fingerprints deleted
  • Device Access enrolments deleted
  • Okta Verify FastPass enrolments deleted
  • Loss of access to any protected data
Applies To
  • Okta Desktop Password Sync
  • macOS
  • Sequoia
  • Okta Identity Engine (OIE)
Cause

This is a new feature released in macOS Sequoia. Despite the pop-up showing the Okta Verify logo, the pop-up and the options presented to the end user are all handled by code in the OS, which Okta Verify does not have control over.

Solution

When presented with this notification, ensure that Enter Previous Password is selected and the old password is correctly entered. Doing otherwise will result in keychain deletion.

Loading
Desktop Password Sync Notification to Enable Offline Login in macOS Sequoia Can Cause Keychain Deletion