Okta Desktop Password Sync Uninstall Instructions (macOS)
Last Updated:
Overview
This article contains instructions for removing Desktop Password Sync for Mac devices.
Applies To
- Okta Identity Engine (OIE)
- Device Access
- Mac
- Password Sync
Solution
Please follow the steps below:
- In Mobile Device Management (MDM), look for the Desktop Password Sync configuration profile (not the actual policy created).
- Open the profile and click Edit.
- On the Scope tab, remove the target for the device that should be reset.
- Save the changes.
- Redistribute the profile to all devices.
- On the macOS device, confirm that the profile has been removed from Settings > General > Device Management (for older macOS devices, these may be found under Privacy & Security > Profiles).
- Ensure all Single Sign On (SSO) extension profiles, including credential extensions, have been removed. If any remain, macOS will not remove the registration.
- If the above were done correctly, Okta Verify should also be removed. If not, please uninstall the application.
- Restart the device.
- Verify the registration has been removed by using the terminal command:
There should be no mention of Okta.app-sso platform -s
NOTE: As this is a Password Sync integration (not SSO), the password that is in Okta has been applied to the macOS user, so when logging in again, it is the Okta password, not the original macOS user password.
This works fine on macOS 15.3.2 and older, but on 15.4 and 15.4.1, after doing these steps, the password is no longer accepted on the Lock Screen. Here are the steps to remediate that:
- Remove the standard SSO Configuration Profile. Verify it was removed from the Mac.
- Remove the SCEP Device Access Configuration Profile.
- Deploy the Okta Verify configuration profile without Password Sync/Platform SSO settings (to be used for FastPass).
- Reboot the Mac.
- Re-deploy the standard SSO configuration profile.
