<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta and Duo AMR Claim Forwarding for Factor IdPs

Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine

Overview

Users using Okta as Factor IDP (as their MFA provider) may be affected by Salesforce's phishing-resistant MFA enforcement for privileged users. When using Okta as a Factor Identity Provider (IdP), they experience unexpected Salesforce prompts for passkey enrollment because the Authentication Method Reference (AMR) claims are missing. Okta resolves this by deploying AMR claim sharing support for Factor IdPs on July 24, 2026.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Factor Identity Provider (IdP)

Cause

Okta currently does not forward AMR claims from Factor IdPs to downstream applications. When a Factor IdP performs phishing-resistant MFA and returns values such as phr in the OpenID Connect (OIDC) response, Okta omits these values from the Security Assertion Markup Language (SAML) assertion or token sent to Salesforce. Consequently, Salesforce does not receive the phishing-resistance signal and prompts affected users to enroll a Salesforce-native passkey.

Solution

How is the missing Authentication Method Reference claim resolved?

Workaround until July 24, 2026: Affected users will be prompted to enroll a Salesforce-native passkey (built-in authenticator or security key) on first login. This is self-service, takes a few seconds, and does not require any admin or IT assistance. Once enrolled, they can log in normally.


After July 24, 2026: The necessary signal from factor IdP/Duo will be forwarded to Salesforce, and no additional Salesforce passkey enrollment will be required for new admin logins.

 

Related References

Loading
Okta Support - Okta and Duo AMR Claim Forwarding for Factor IdPs