<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Verify Fails to Re-add a Deleted Device as a Managed Device

Multi-Factor Authentication
Okta Identity Engine

Overview

Devices become unmanaged and fail Okta FastPass authentication when Okta Verify retains the enrollment after the device's deletion from the Okta Admin Console. To resolve this issue, re-enroll the device in Okta Verify and issue a new Simple Certificate Enrollment Protocol (SCEP) certificate if the device is managed.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Verify
  • Management Attestation

Cause

This issue occurs when Okta Verify retains the enrollment after the device's deletion from the Okta Admin Console. The Okta Verify logs display the following errors:

 

  • {✅ "Enrolling Authenticator": {"message": "URL: https://tenant.okta.com/idp/authenticators", "defaultProperties": "", "location": "LegacyServerAPI.swift:enrollAuthenticatorRequest(orgHost:metadata:deviceModel:appSignals:enrollingFactors:token:completion:):126"}}

 

  • {✅ "API": {"message": "Request URL: https://tenant.okta.com/idp/authenticators Response Code: 410 Debug Headers: { x-rate-limit-reset:1692193535 x-okta-request-id:[okta request id] x-rate-limit-limit:600 x-rate-limit-remaining:592} Error Response: {Error Code: E0000153, Error Id: oaeMKIDzpZmQhKdB1G3OPWk5Q, Error Summary: Invalid device id, it no longer exists.}", "defaultProperties": "", "location": "HttpClient.swift:logResponse(url:statusCode:headers:response:oktaRequest:):272"}}

 

 

  • {🛑 "API error": {"message": "error: serverAPIError(<OktaDeviceSDK.HTTPURLResult: 0x6000028e0120>, Optional(OktaDeviceSDK.ServerAPIErrorModel(errorCode: Optional(OktaDeviceSDK.ServerErrorCode.deviceDeleted), errorSummary: Optional("Invalid device id, it no longer exists."), errorLink: Optional("E0000153"), errorId: Optional("[ErrorID"), status: nil, errorCauses: Optional([["errorSummary": "Invalid device id [guoID], it no longer exists."]])))) for request at URL: https://tenant.okta.com/idp/authenticators", "defaultProperties": "", "location": "ServerAPIProtocol.swift:validateResult(_:for:):273"}}

 

  • {✅ "EnrollTransaction": {"message": "Rolling back transaction", "defaultProperties": "", "location": "OktaTransactionEnroll.swift:rollback():107"}}

 

  • {🛑 "Enrollment": {"message": "serverAPIError(<OktaDeviceSDK.HTTPURLResult: 0x6000028e0120>, Optional(OktaDeviceSDK.ServerAPIErrorModel(errorCode: Optional(OktaDeviceSDK.ServerErrorCode.deviceDeleted), errorSummary: Optional("Invalid device id, it no longer exists."), errorLink: Optional("E0000153"), errorId: Optional("[ErrorID"), status: nil, errorCauses: Optional([["errorSummary": "Invalid device id [guoID], it no longer exists."]]))))", "defaultProperties": "", "location": "EnrollmentManager.swift:fromDeviceAuthenticatorError(::):67"}}

 

  • {🛑 "Enrollment": {"message": "UNKNOWN_API_ERROR_CODE", "defaultProperties": "", "location": "AddAccountFlowCoordinator.swift:handleEnrollFailure(info:error:):485"}}

 

  • {✅ "Storage Management": {"message": "Key not found in storage: 00o1hpv5nxsjCOL2F0h8", "defaultProperties": "", "location": "UserDefaultsManager.swift:data(with:readUnencrypted:forbidCleanup:):122"}}

2023/08/16 09:45:07:496 -0400 {🛑 "Storage Management": {"message": "Failed to read org details for org [OrgID]: itemNotFound", "defaultProperties": "", "location": "OrgStorageManager.swift:getOrg(orgId:):81"}}

Solution

How is a deleted device re-added as a managed device?

Re-enroll the device in Okta Verify and issue a new certificate if necessary by following these guidelines:

  • Re-enroll the registered device in Okta Verify.
  • Issue a new SCEP certificate before re-enrollment if the device is managed with an SCEP certificate issued to the personal store.
Loading
Okta Support - Okta Verify Fails to Re-add a Deleted Device as a Managed Device