<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Device Status when Authenticating with Another Factor Aside from FastPass
Devices and Mobility
Multi-Factor Authentication
Overview

The Okta Verify application must be installed on the device since it is used for silent checking and for managing the device's initial setup.

This login flow only applies if the end-user has logged in to FastPass at least once. The end user can choose another MFA (like SMS, etc.). 

Applies To
  • Okta Identity Engine(OIE)
  • Device Trust 2.0 / Device Integrations
  • Multi-Factor Authentication (MFA)
Solution

For the device to be evaluated, at least one of the policy rules must require the device's status to be Registered or Registered and Managed.
If there are Policies/Rules for OIE in this sample Scenario:

App Authentication Policy

Rule 1: Allow Users = Registered, Managed.
Rule 2: Deny Users = Any, Not Managed.

If no policies/rules are created, it will fall under the Default Policy that allows any user to log in.
Device trust 

 

Global Session Policy

MFA = Required
Establish the user session with = Any factor that meets the Authentication Policy requirements.

Not Managed Device Behavior (Login Flow)

  1. Enters username
  2. Prompted to Sign in with Okta FastPass, and an Error shows: 
Sorry, you can't access Okta Dashboard because you are not assigned this app in Okta.
 

Managed Device Behavior (Login Flow)

  1. Enter Username.
  2. Click Next.
  3. Enter the Password and click Verify.
  4. Prompted with which MFA to use: FastPass, Email, Phone, etc. (Whatever is set to optional or required).
  5. Select Phone (SMS).
  6. Receive a code via SMS.
  7. Enter Code.
  8. Successfully Logs in.


NOTE: Users need to log in with their usernames to choose other MFA options besides FastPass.
 

Conclusion

Okta System Log shows a successful log-in using Phone (SMS) as MFA instead of FastPass and shows that it is a Managed/Registered device.

 

System logs

System logs

 

Related References

Loading
Device Status when Authenticating with Another Factor Aside from FastPass