Okta Verify Release Control and Auto-Update Behavior for Windows and macOS
Last Updated:
Overview
Okta Verify handles conflicting auto-update policies differently depending on the operating system and deployment method. When a Windows device connects to multiple Okta tenants, Okta Verify must determine which release control policy takes precedence. For macOS devices, administrators require a specific Mobile Device Management (MDM) deployment approach to control Okta Verify updates and prevent unauthorized App Store downloads.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Verify
- Windows
- macOS
Solution
How does Okta Verify determine auto-update precedence for Windows devices connected to multiple tenants?
The following list details how Okta Verify determines the auto-update policy for Windows devices connected to multiple Okta tenants based on the application version and registry configurations.
- Okta Verify versions prior to 6.11: Okta Verify selects the tenant policy non-deterministically. When a device connects to multiple tenants with conflicting release-control settings, Okta Verify selects either tenant policy randomly during an update check.
- Okta Verify version 6.11 and later: Okta Verify selects the tenant policy deterministically. Okta Verify sorts the tenants alphabetically by organization ID and uses the first tenant as the source of truth for the release-control and auto-update policy.
- Administrator override (all versions): Administrators can set the signin URL registry value to a specific organization URL. The auto-update policy of that specific tenant always takes precedence, overriding the default selection logic.
Administrators Can Control Okta Verify Updates on macOS Devices Using a Standalone Package
To achieve manual version control and disable auto-updates for macOS devices in a Mobile Device Management (MDM) environment like Microsoft Intune, administrators must deploy Okta Verify exclusively using the standalone package file by following these guidelines.
- Download the standalone package (PKG) file from the Okta Admin Console.
- Deploy the PKG file to macOS devices exclusively via the MDM solution. Deploying via the standalone PKG file does not support auto-updates.
- Perform subsequent version upgrades by manually downloading the newer PKG file and redeploying it through the MDM solution.
NOTE: If endpoints have the Apple App Store enabled or if users sign in with personal Apple IDs, Okta Verify appears in the Mac App Store. If a user manually attempts to update or download Okta Verify from the App Store, the App Store version conflicts with or overwrites the standalone PKG installation.
