Okta FastPass on macOS - JAMF Issue
Last Updated:
Overview
When an enrolled OV (Okta Verify) FastPass user tries to authenticate over a Cisco VPN connection on an Apple macOS, the Okta Verify app on macOS (which is open and not closed) does nothing. The option on the screen will appear to Open Okta Verify, but it is impossible to click on it.
The SSO extension is registered as per the Configure an SSO extension for managed macOS devices documentation, and when viewing the macOS Console output, the following error is:
Cisco AnyConnect Secure Mobility Client 0x16501c650 - SOAuthorizationCoordinator::tryAuthorize: The requested URL is not registered for AppSSO handling. No further action needed
Applies To
- Okta FastPass
- Okta Verify (OV)
- Okta Identity Engine (OIE)
- JAMF Configuration
Cause
A misconfiguration of JAMF causes this issue.
Solution
The documentation notes the following:
- Hosts: Enter the Okta org domain. For example,
acme.okta.com. - If implementing a custom URL domain in the org, click + Add, and then enter the custom URL domain. Do not include
https://or any other protocol scheme. After completing this step, there are two domains:acme.okta.comandid.acmecorp.biz.
The guidance "Do not include https:// or any other protocol scheme." applies to both steps 5 and 6 of the Configure an SSO extension for managed macOS devices). If entering the protocol, the integration will not succeed, which may result in errors.
