Device Check for CrowdStrike Integration
Last Updated:
Overview
The Zero Trust Assessment (ZTA) score is not transmitted to Okta during the login process. This article details how to gather the ZTA score.
Applies To
- Okta Identity Engine (OIE)
- Crowdstrike
- Custom expression
Cause
During the login process, the ZTA score is not transmitted to Okta and the user will not be evaluated by a rule that has a custom expression requiring a minimal ZTA score.
The custom expression alone will not trigger a device check from Okta Verify, and that information will not be obtained.
Solution
To gather the ZTA score, Okta Verify must be called during the authentication process.
This can be done in 2 methods :
- Have a rule in place that limits the user to accessing Okta or a specific application only with Okta Verify FastPass.
- Have at least one rule that applies to the authentication policy in question to require the device to be registered, which will trigger a silent check of the device by Okta Verify FastPass, and the response will also contain the ZTA score as well.
