<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Okta Verify Satisfying Multiple Authentication Rules Conditions
Multi-Factor Authentication
Okta Identity Engine
Overview

Okta Verify can satisfy multiple authentication rules factor requirements when authenticating with biometrics (TouchID / FaceID).

Applies To
  • Okta Identity Engine (OIE)
  • Okta Verify FastPass
  • Authentication rules
Cause

As stated in the rules disclaimer, not every form of Okta Verify can satisfy more than one authentication rule condition.

Rule


For Okta Verify to satisfy multiple factor requirements, it must satisfy the Additional factor types (Possession factor) and Biometric factor types =.

Solution

The form of Okta Verify that can satisfy multiple factor requirements is FastPass and push notification with Biometrics.

Below, see a comparison between when a user authenticates with Okta Verify FastPass, Okta Verify Push, and Okta Verify One-Time Passcode.

  • For Okta Verify FastPass, the authentication has the USER_VERIFYING properties, which are considered biometric factor types.

Okta Verify FastPass event

 

  • In the case of Okta Verify Push notification, the USER_VERIFYING properties are considered biometrics factor type only if the user has biometrics enabled on the Okta Verify application. 

Okta Verify Push notification event

 

  • In the case of Okta Verify One Time Passcode, the factor properties do not include USER_VERIFYING, and it will not satisfy the multiple-factor requirement; the user will be prompted for a second factor.

Okta Verify One Time Passcode event

Recommended content

Loading
Okta Verify Satisfying Multiple Authentication Rules Conditions