This document provides the context and the solution for when Okta Verify for macOS keeps prompting for admin credentials for Keychain Access.
- Device Trust
- Okta Identity Engine (OIE)
- macOS
- Okta Verify
- Okta FastPass
- Keychain Access
- Simple Certificate Enrollment Protocol (SCEP)
When using Okta FastPass for Device Trust deployment on macOS, the Admin Credentials for Keychain Access window might pop up.
This is because either the certificate payload is not in the same profile as the SCEP payload, or because Okta Verify does not have access to the keychain.
- In the Jamf profile, the Allow all apps access option must be enabled.
- In Jamf, the certificate payload must be in the same profile as the SCEP payload.
