Unmanaged iOS Phishing Resistance and iCloud Private Relay
Last Updated:
Overview
Unmanaged iOS devices running iOS 17 or earlier fail to satisfy the Okta phishing resistance policy requirement when iCloud Private Relay is enabled. This authentication failure occurs because the policy requires disabling iCloud Private Relay for Safari and native applications using Safari authentication view controllers. Disabling iCloud Private Relay temporarily or exposing the IP address in Safari resolves the authentication failure.
NOTE: Apple resolved this issue in iOS 18 and later releases. This article applies only to iOS 17 and earlier versions.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Verify
- Apple iOS 17 and earlier
- Apple Safari
Cause
When an authentication policy specifies unmanaged iOS phishing resistance, iCloud Private Relay interferes with the authentication flow. This interference affects only Safari and native applications utilizing Safari authentication view controllers. This issue does not affect Google Chrome or Mozilla Firefox.
Solution
How is the iCloud Private Relay authentication issue resolved?
Resolve the authentication failure by disabling iCloud Private Relay before authenticating and re-enabling the feature after the authentication completes.
- Disable iCloud Private Relay before authenticating.
- Re-enable iCloud Private Relay after authentication completes.
Exposing the IP address provides a workaround for authenticating inside Apple Safari.
Expose the IP address within the Safari browser to keep iCloud Private Relay enabled during authentication.
- Open a new tab in Safari.
- Tap the Aa reader button.
- Select Show IP Address.
- Choose Continue on the privacy dialog.
Temporarily disabling iCloud Private Relay provides a workaround for native applications using Safari-based authentication views.
Temporarily disable iCloud Private Relay in the iOS settings before executing the authentication flow in the native application.
- Navigate to Settings > iCloud > Private Relay.
- Turn off iCloud Private Relay.
- Execute the authentication flow in the native application.
