ISPM Login and MFA Dashboard Detects Okta FastPass as an Authenticator
Last Updated:
Overview
The Identity Security Posture Management (ISPM) Login and Multi-Factor Authentication (MFA) dashboard displays users as enrolled in FastPass even if they lack the enrollment. This occurs because ISPM uses Okta API calls that automatically return FastPass as enrolled whenever the user enrolls in Okta Verify. This behavior is a known product limitation and functions as designed.
Observe this discrepancy by accessing the ISPM Login and MFA dashboard in the Inventory section.
Identify users with FastPass enabled by filtering the dashboard by Okta Verify and FastPass.
Confirm the user lacks FastPass enrollment in the Okta Admin Console by navigating to Directory, selecting People, choosing the user, and selecting More actions.
Applies To
- Okta Identity Engine (OIE)
- Identity Security Posture Management (ISPM)
- Multi-Factor Authentication (MFA)
- Login and MFA Dashboard
Cause
The Login and MFA dashboard in the ISPM inventory section collects data using Okta API calls. The specific API call shows both factors as enrolled as soon as the user enrolls in Okta Verify.
Solution
Why does the Identity Security Posture Management dashboard show FastPass as enrolled?
The ISPM dashboard collects data via the User Factors and Authenticators API calls. These API calls return the Okta Verify enrollment status of the user. Okta automatically displays users as enrolled in FastPass when the API response includes Okta Verify as an enrolled factor. This is a product limitation and currently works as designed.
