Overview
An industry-wide Chinese regulation, not specific to Okta, related to the publication of apps on app stores in China was communicated to iOS developers in late 2023 and early 2024.
Out of an abundance of caution, Okta notified its customers that Okta Apps for iOS* could have become unavailable on the China App Store on April 1, 2024, and highlighted other, Okta-supported MFA authenticator options.
Since that time, the Okta Apps for iOS remain available on the China App Store and we are not aware of any iOS apps in our category being removed. We are committed to customer success and to providing secure, convenient, authenticator options for customers and their global users.
No customer action is required, though Okta recommends additional backup authenticators be available if needed.
If iOS app availability in the China app store changes, Okta anticipates advance notification and will communicate with customers promptly.
*Okta Apps refers to the Okta Verify and Okta Mobile iOS apps for Apple iOS iPhones and iPads.
Summary
- Okta Apps continue to be available on the Apple App Store in China.
- Okta Apps for iOS users can continue to use and receive updates for the Okta Apps, and receive push notifications to authenticate successfully in China. If a change in availability occurs, they will not be able to update the Okta Apps using the China App Store.
- The Okta Apps for iOS are available on Apple App Stores outside of China and can be downloaded and installed from those stores, even from China.
- There is no change to your users’ ability to install or update desktop (for example, macOS or Windows) or sideloaded Android versions of the Okta Apps.
Customer Scenarios and MFA Authenticator Options
No customer action is required. Below are potential scenarios for your org(s) and MFA authenticator options to evaluate if alternatives are desired
Customer Scenarios
Customer Org Scenario 1: Users in China who need to download, install, or update the Okta Apps on iOS devices through the China App Store. This means those users have Apple IDs associated with the China App Store.
-
Okta Apps for iOS users can continue to use and receive updates for the Okta Apps and receive push notifications to authenticate successfully in China.
-
If a change in availability occurs, they will not be able to update the Okta Apps using the China App Store, but can continue to use the apps. If iOS app availability in the China app store changes, Okta anticipates advance notification and will communicate with customers promptly.
Customer Org Scenario 2: Users are enabled to access Apple App Stores outside of China (e.g., EU, US, or Singapore)
-
No action is required. Users will continue to have access to the Okta Apps.
Customer Org Scenario 3: No users using or will need to use the iPhone or iPad (Apple iOS) versions of the Okta Apps while in China.
-
No action is required.
MFA Authenticator Options
Users in China of Okta Apps for iOS can continue to use and receive updates for the Okta Apps and receive push notifications to authenticate successfully in China. If alternatives to Okta Apps for iOS devices (iPhones or iPads) are desired, below are alternative options for customer consideration.
Option 1: Continue to use the Okta Apps for iOS with a change in Region
-
For managed corporate devices associated with Apple App Stores outside of China, the Okta Apps could be pre-installed and sent to the user directly. Updates would continue to be available through Apple App Stores outside of China. Managed devices refer to devices enrolled in an MDM provider, which can be configured by following the Okta Docs, Managed Devices section. NOTE: Users may also change their App Store region. Refer to Apple Support’s Change your Apple Account country or region article.
Option 2: Migrate to using the Okta Apps on another platform
-
The Okta Apps can be sideloaded onto Android mobile devices for use in China.
-
Okta Verify for macOS and Windows can be installed for authentication with FastPass, which the Okta Identity Engine supports.
Option 3: Reconfigure Authentication
-
Okta recommends leveraging Passkeys for authentication. Alternatively, orgs can implement a WebAuthN compliant authentication tool with strong authenticators such as a dedicated hardware key or biometrics. For additional authenticator/factor options and configuration information, please see Okta Docs MFA factor configuration (Classic Engine, Identity Engine).
Please contact Okta Support if you require assistance.
