<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

FastPass Same-Device Enrollment UI Update

Multi-Factor Authentication
Okta Identity Engine

Overview

Okta is rolling out an enhancement that streamlines same-device enrollment for Okta Verify and FastPass. The change is now an Early Access feature. It will become the default experience when the feature is generally available (GA) in production, which is planned for early 2027.

 

Enable Same-device enrollment (Early Access now) and Flexible Okta Verify Authenticator Configuration (Early Access in August 2026) to control which users see the Same-device enrollment experience.

Applies To

  • Okta Identity Engine (OIE)
  • Okta FastPass enrollment
  • Okta Verify

Solution

Same-device enrollment offers a phishing resistant, intuitive UI to complete Okta Verify and FastPass enrollment. A majority of new FastPass enrollments are initiated from the same desktop the user is trying to access - making mobile-only instructions the #1 drop-off driver for end-users.

 

Same-device enrollment eliminates copy-pasting URLs and double-auth prompts, reducing setup time by about 40%. A simpler, clearer journey means fewer help-desk tickets and faster time-to-MFA compliance. ​

 

Old experienceNew experience (with Flexible Okta Verify Authenticator Configuration)
  • When users enrolled into Okta Verify on a desktop browser and they did NOT have a FastPass enrollment for Okta Verify, the Sign-In Widget showed mobile-only setup steps (QR code, SMS / email link).
  • Users had to pull out a phone or fall back to the “workaround” of launching the Okta Verify desktop app first.
  • When users enrolled into Okta Verify on a mobile browser, the Sign-In Widget showed SMS/email link as the only enrollment methods.
  • The desktop Same-device enrollment flow only appears for users who are assigned to FastPass-only as required.
  • The mobile Same-device enrollment flow appears for all users
  • The Sign-In Widget detects the platform and offers a one-click Set up Okta Verify flow on the current device.
  • A secondary link still allows enrollment on another (mobile) device if Okta Verify Enrollment options is set to Any method.

Desktop

Desktop - Set up Okta Verify

Desktop

Desktop - Set up Okta Verify

Mobile

Old Experience Mobile

Mobile

SIW Gen 2

Mobile New Experience SIW Gen 2

SIW Gen 3

Mobile New Experience SIW Gen 3

What your end users will see with Flexible Okta Verify Authenticator Configuration and Same-device enrollment

  • Desktop:
    • For users with FastPass-only set to required in enrollment policy: 
      • A blue Set up Okta Verify button that launches the desktop installer (or the already-installed app) and walks the user straight through FastPass enrollment on that machine.
      • Mobile enrollment from a desktop device still works when Okta Verify Enrollment options is set to Any method. If a user prefers to bind FastPass to a phone, they simply click the set up Okta Verify on a mobile device link. The familiar QR / SMS / email choices appear exactly as before.
    • For users with TOTP or Push set to required in enrollment policy:
      • A QR code for mobile enrollment
      • Instructions on how to download the app and enroll into Okta Verify on mobile
  • Mobile browsers:
    • A blue Set up Okta Verify button launches the already-installed mobile app and walks the user straight through Okta Verify/FastPass enrollment on that device. If the user does not have Okta Verify installed, they should click Download here which redirects them to the mobile app, then return to the browser and select Set up Okta Verify.

 

A Super Admin can enable the feature by navigating to Settings Features in the Admin Console and toggling on Same-Device Enrollment for Okta FastPass.

 

 

Recommended Admin Actions Before GA

TaskWhySuggested Timing

 

Review the new flow in a preview org by walking through an enrollment flow for FastPass on desktop and mobile. 

 

Validate it against your sign-in policies and branding.As soon as possible

Update any screenshots or step-by-step guides provided to employees.

Legacy documentation that assumes a QR code first will confuse users.Before enabling in production
Communicate the change to your help-desk / IT trainers.Reduce surprise tickets when users see the new button.Alongside documentation updates
Send feedback via your Customer Success Manager (CSM) or an Okta Support ticket.Helps us polish the flow ahead of General Availability.During Preview

 

Loading
Okta Support - FastPass Same-Device Enrollment UI Update