iOS Device Not Managed by Okta Successfully Authenticates with an Authentication Policy That Requires Registered & Managed Devices
Last Updated:
Overview
This article discusses inconsistencies with the "Managed" status of iOS devices. When an iOS device is managed in MDM but not in Okta, and has Single Sign-On Extension (SSOe) configured, it will be flagged as managed in the Okta System Log if it authenticates via the SSOe. This behavior is expected.
Single Sign-On Extension is configured, and the device authenticates via the Single Sign-On Extension:
Applies To
- iOS devices
- Okta Verify
- Single Sign-On Extension (SSOe)
- Okta Identity Engine (OIE)
Cause
If the device does not also push a managed app configuration for Okta Verify with the managementHint, then, when SSOe fails, and the user uses Universal Link, they will become unmanaged.
Solution
To resolve this behavior, deploy the managementHint to both the Single Sign-On Extension (SSOe) and the Okta Verify Managed App configuration for iOS devices.
This ensures the device is counted as managed in all authentication flows.
