This article outlines why it is not possible to move an Okta Verify account between two Windows user profiles on the same machine.
- Multi-Factor Authentication (MFA)
- Okta Identity Engine
- Devices
- Okta FastPass
This happens because the secret stored by Okta Verify is encrypted using Windows data protection, which is tied to a user account.
Also, when a Windows device has multiple operating systems (OS) user profiles, and the same account is added to Okta Verify on several user profiles, the most recent enrollment by the last user profile works. If the same Okta Verify account is used in a different user profile, the authentication fails.
Users will need to create a new Okta Verify enrollment once they begin using their new Windows user profile.
If the Okta authentication requires a second factor, ensure that users have another factor set up so that they can access the Okta Dashboard and complete re-enrollment of the new Okta Verify account.
Related References
- For more information about the Okta Verify options, see Configure Okta Verify options.
