<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
iOS Safari Authentication and Phishing-Resistant Factor Issues with iCloud Private Relay
Multi-Factor Authentication
Okta Identity Engine
Overview

This article describes authentication problems and issues with phishing-resistant factor restraints that occur on unmanaged iOS devices using the Safari browser when Apple's iCloud Private Relay feature is enabled.

Applies To
  • iOS
  • Safari
  • Okta Authentication Policies
  • Phishing-Resistant Authentication
  • Device Management
  • Okta Identity Engine (OIE)
Cause

When iCloud Private Relay is enabled on unmanaged iOS devices, it can interfere with expected network behavior during authentication attempts in Safari. This interference can prevent phishing-resistant factor restraints, as configured in authentication policies, from functioning correctly.

Solution

To mitigate these issues on unmanaged iOS devices:

  1. Disable iCloud Private Relay on the device before attempting authentication via Safari.
  2. Once authentication is successfully completed, iCloud Private Relay can be re-enabled.

For additional workarounds, see the Unmanaged iOS Phishing Resistance and iCloud Private Relay article.

 

Related References 

Loading
iOS Safari Authentication and Phishing-Resistant Factor Issues with iCloud Private Relay