Okta Verify Prompt Appears When User on unregistered device is Denied Access by Authentication Policy
Last Updated:
Overview
When an authentication policy rule denies access to an application for users on unregistered devices, users are prompted to open or download Okta Verify, even though syslog records the user hitting the deny rule.
Applies To
- Okta Verify
- Authentication Policy
- Unregistered device
- Okta Identity Engine (OIE)
Cause
The system's design includes inline remediation for users to enroll in Okta Verify. This feature causes the prompt to appear, even when access is ultimately denied by the policy rule. It is not possible to create enrollment policy which results in a deny event disallowing enrollments from unregistered devices.
Solution
While the prompt to open or download Okta Verify appears, access is still denied as intended by the authentication policy. This behavior is due to the current inline remediation design for Okta Verify enrollment.
- The user will still be denied access to the application.
- The prompt to enroll in Okta Verify is a function of the inline remediation feature.
Currently, there is no option to disable the Okta Verify enrollment prompt for users denied access by an authentication policy on unregistered devices. The policy functions as expected, denying access regardless of the prompt.
