<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Looping Login During Windows Hello for Business Setup
Multi-Factor Authentication
Okta Identity Engine
Overview

Looping Login During Windows Hello for Business Setup.

Applies To
  • Windows Hello for Business
  • Okta Identity Engine (OIE)
  • Okta Multi-Factor Authentication (MFA)
Cause

During the Windows Hello for Business enrollment process, Microsoft will require two-factor authentication.

If Microsoft is Federated with Okta and Okta MFA for Azure AD is checked, Okta must provide both primary and secondary factors in the authentication request.
Okta MFA from Azure AD

Solution

In this configuration, if Okta does not provide Multi-Factor Authentication (MFA), the response will be rejected, and a new request will be sent to Okta.

Check the App-level Sign-on Policy for Office 365 and ensure that User must select: Any 2 factor types is set.

Sign on policy

Loading
Looping Login During Windows Hello for Business Setup