<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta macOS Desktop MFA Fails With a Spinning Wheel When the Authentication Policy Lacks TOTP

Okta Identity Engine
Okta Device Access

Overview

Removing the Okta Verify Time-Based One-Time Password (TOTP) method from the Authentication Policy causes macOS Desktop Multi-Factor Authentication (MFA) to fail because the local client requires an offline factor. Re-enabling the TOTP method in the Authentication Policy resolves the issue. Affected macOS users fail to complete the MFA step during desktop login, and the local client hangs with an endless spinning wheel displaying "Approve the request in the Okta Verify App on your mobile device" or gets stuck on an enrollment QR code screen.

Applies To

  • Okta Identity Engine (OIE)
  • macOS
  • Okta Device Access (ODA)
  • Jamf Connect
  • Okta Verify

Cause

Okta Desktop MFA for macOS requires establishing and validating an offline authentication factor during account linking and login. Okta Verify TOTP is the only supported offline authenticator for macOS Desktop MFA. When administrators remove the TOTP method from the Authentication Policy, Okta explicitly disallows its use. However, the local macOS client still requires an offline factor to complete the device-binding and authentication sequence. Because the client cannot bypass the offline factor requirement and the server policy rejects the TOTP factor, the client continuously polls for an authenticator state that never materializes, resulting in an infinite spinning wheel or an un-scannable QR code loop.

Solution

How is the macOS Desktop MFA login failure resolved?

Re-enable the Okta Verify Time-Based One-Time Password (TOTP) method in the allowed authentication methods for the Authentication Policy governing the desktop login flow.

  1. In the Okta Admin Console, navigate to Security and select Authentication Policies.
  2. Select the rule governing the desktop login flow.
  3. Verify the rule uses the Allow specific authentication methods setting.
  4. Select the Okta Verify - TOTP checkbox.
  5. Save the changes.
Loading
Okta macOS Desktop MFA Fails With a Spinning Wheel When the Authentication Policy Lacks TOTP | Okta Support