Okta Verify Network Settings Error Occurs on iOS Devices
Last Updated:
Overview
Incorrect date and time settings, disabled notifications, or Domain Name System (DNS) configurations cause Okta Verify to fail on iOS devices. Adjusting the device settings, isolating the network, or contacting the mobile carrier resolves the issue. When attempting to use Okta Verify on an iOS device, the following error message displays even when no Virtual Private Network (VPN) is active:
Your network settings are preventing Okta Verify from working properly
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Verify
- iOS
Cause
This error occurs when device or carrier network settings interfere with Okta Verify's ability to communicate with Okta servers. Potential causes include incorrect date and time settings on the device, disabled notifications for the Okta Verify app, network-level DNS configurations, or issues with the mobile carrier network configuration.
Solution
How does the user verify the device date and time settings?
Ensure the date and time on the iOS device are set to update automatically by navigating to General > Date & Time and toggling Automatic Date & Time.
- Go to Settings, select General, and choose Date & Time.
- Toggle Set Automatically off.
- Wait a few seconds, then toggle Set Automatically on.
How does the user check the Okta Verify notification settings?
Enable notifications for push verification to function correctly by accessing the Okta Verify settings on the device.
- Go to Settings > Apps.
- Tap Okta Verify.
- Tap Notifications and ensure that Allow Notifications is enabled.
Isolate the Network to Determine the Source of the Issue
Determine whether the issue is specific to Wi-Fi or cellular by alternating between connection types and attempting to sign in.
- If connected to Wi-Fi, turn it off and attempt to sign in using cellular data.
- If using cellular data, connect to a trusted Wi-Fi network and try signing in again.
- If the issue only occurs on one network type, the problem lies with that specific network configuration.
Review the Network DNS Settings for Potential Blocks
Check the router, firewall, or private DNS settings to ensure that Okta domains are not blocked by security features.
- Router/Firewall: If on a Wi-Fi network, check the router or firewall settings. Security features like DNS Rebind Protection interfere with Okta. Add Okta domains to the allowlist if necessary.
- Private DNS: Check if a Private DNS or a third-party DNS filtering app is in use. Temporarily disable it and attempt the sign-in process again.
Configure iOS Devices to Override DNS Settings
Prevent interference from alternate DNS servers on iOS devices running Okta Verify 9.68.0 or higher by navigating to the device settings and selecting Okta Verify to place overrides on specific Okta-managed domains to use Google DNS. Non-Okta DNS traffic on your device will not be affected. For more information about DNS overrides see DNS Rebind Protection Prevents Okta Verify from Establishing Secure Connections.
- Go to Settings.
- Select General.
- Select VPN & Device Management.
- Select DNS.
- Choose Okta Verify.
