<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Verify Release Control and Auto-Update Behavior for Windows and macOS

Okta Classic Engine
Okta Identity Engine
Okta Verify

Overview

Okta Verify handles conflicting auto-update policies differently depending on the operating system and deployment method. When a Windows device connects to multiple Okta tenants, Okta Verify must determine which release control policy takes precedence. For macOS devices, administrators require a specific Mobile Device Management (MDM) deployment approach to control Okta Verify updates and prevent unauthorized App Store downloads.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Verify
  • Windows
  • macOS

Solution

How does Okta Verify determine auto-update precedence for Windows devices connected to multiple tenants?

The following list details how Okta Verify determines the auto-update policy for Windows devices connected to multiple Okta tenants based on the application version and registry configurations.

  • Okta Verify versions prior to 6.11: Okta Verify selects the tenant policy non-deterministically. When a device connects to multiple tenants with conflicting release-control settings, Okta Verify selects either tenant policy randomly during an update check.
  • Okta Verify version 6.11 and later: Okta Verify selects the tenant policy deterministically. Okta Verify sorts the tenants alphabetically by organization ID and uses the first tenant as the source of truth for the release-control and auto-update policy.
  • Administrator override (all versions): Administrators can set the signin URL registry value to a specific organization URL. The auto-update policy of that specific tenant always takes precedence, overriding the default selection logic.

 

Administrators Can Control Okta Verify Updates on macOS Devices Using a Standalone Package

To achieve manual version control and disable auto-updates for macOS devices in a Mobile Device Management (MDM) environment like Microsoft Intune, administrators must deploy Okta Verify exclusively using the standalone package file by following these guidelines.

  • Download the standalone package (PKG) file from the Okta Admin Console.
  • Deploy the PKG file to macOS devices exclusively via the MDM solution. Deploying via the standalone PKG file does not support auto-updates.
  • Perform subsequent version upgrades by manually downloading the newer PKG file and redeploying it through the MDM solution.

 

NOTE: If endpoints have the Apple App Store enabled or if users sign in with personal Apple IDs, Okta Verify appears in the Mac App Store. If a user manually attempts to update or download Okta Verify from the App Store, the App Store version conflicts with or overwrites the standalone PKG installation.

Loading
Okta Verify Release Control and Auto-Update Behavior for Windows and macOS | Okta Support