Okta and Duo AMR Claim Forwarding for Factor IdPs
Last Updated:
Overview
Users using Okta as Factor IDP (as their MFA provider) may be affected by Salesforce's phishing-resistant MFA enforcement for privileged users. When using Okta as a Factor Identity Provider (IdP), they experience unexpected Salesforce prompts for passkey enrollment because the Authentication Method Reference (AMR) claims are missing. Okta resolves this by deploying AMR claim sharing support for Factor IdPs on July 24, 2026.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Factor Identity Provider (IdP)
Cause
Okta currently does not forward AMR claims from Factor IdPs to downstream applications. When a Factor IdP performs phishing-resistant MFA and returns values such as phr in the OpenID Connect (OIDC) response, Okta omits these values from the Security Assertion Markup Language (SAML) assertion or token sent to Salesforce. Consequently, Salesforce does not receive the phishing-resistance signal and prompts affected users to enroll a Salesforce-native passkey.
Solution
How is the missing Authentication Method Reference claim resolved?
Workaround until July 24, 2026: Affected users will be prompted to enroll a Salesforce-native passkey (built-in authenticator or security key) on first login. This is self-service, takes a few seconds, and does not require any admin or IT assistance. Once enrolled, they can log in normally.
After July 24, 2026: The necessary signal from factor IdP/Duo will be forwarded to Salesforce, and no additional Salesforce passkey enrollment will be required for new admin logins.
