Okta Verify: Windows Security Prompt Appears Behind FastPass in Elevated (Administrator) Mode
Last Updated:
Overview
During authentication using Okta FastPass, the authentication flow may appear to hang, freeze, or become unresponsive.
Specifically, when Okta Verify attempts to perform user verification (such as prompting for a Windows Hello PIN or biometrics), the Windows Security screen pops up underneath (behind) the FastPass screen. Because this window is hidden from view, users cannot interact with it without manually shifting windows, leading to an interrupted sign-in experience.
This behavior typically occurs on Windows workstations where either Okta Verify or the calling web browser is being executed with elevated (Administrator) privileges.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Verify
- Multi-Factor Authentication (MFA)
- FastPass
Cause
Operating the Okta Verify application with elevated privileges is not supported by Okta. Running in an elevated context introduces a known compatibility and security boundary issue:
- Integrity Level Mismatch: Operating in elevated mode prevents the secure, standard user-level Windows Security/Hello prompt from properly gaining focus and rendering in front of the elevated Okta Verify window.
- Process Communication Failures: Elevation blocks the application from communicating correctly with standard, non-elevated user-level processes and browser extensions.
Solution
To resolve this behavior, both Okta Verify and any applications that trigger the authentication flow must run in a standard, non-elevated user context.
The Okta Engineering team recommends adjusting the workflows and system configurations to ensure that:
- Okta Verify is launched as a standard user (ensure the application shortcut or executable is not configured to Run as administrator in its compatibility properties).
- The Web Browser or any other application that triggers the authentication prompt runs in a standard, non-elevated user context.
