<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Unmanaged iOS Phishing Resistance and iCloud Private Relay

Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine

Overview

Unmanaged iOS devices running iOS 17 or earlier fail to satisfy the Okta phishing resistance policy requirement when iCloud Private Relay is enabled. This authentication failure occurs because the policy requires disabling iCloud Private Relay for Safari and native applications using Safari authentication view controllers. Disabling iCloud Private Relay temporarily or exposing the IP address in Safari resolves the authentication failure.

NOTE: Apple resolved this issue in iOS 18 and later releases. This article applies only to iOS 17 and earlier versions.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Okta Verify
  • Apple iOS 17 and earlier
  • Apple Safari

Cause

When an authentication policy specifies unmanaged iOS phishing resistance, iCloud Private Relay interferes with the authentication flow. This interference affects only Safari and native applications utilizing Safari authentication view controllers. This issue does not affect Google Chrome or Mozilla Firefox.
 

Solution

How is the iCloud Private Relay authentication issue resolved?

Resolve the authentication failure by disabling iCloud Private Relay before authenticating and re-enabling the feature after the authentication completes.

  1. Disable iCloud Private Relay before authenticating.
  2. Re-enable iCloud Private Relay after authentication completes.
    iCloud Private Relay

Exposing the IP address provides a workaround for authenticating inside Apple Safari.

Expose the IP address within the Safari browser to keep iCloud Private Relay enabled during authentication.

  1. Open a new tab in Safari.
  2. Tap the Aa reader button.
  3. Select Show IP Address.
  4. Choose Continue on the privacy dialog.
Example of workaround iCloud Private Relay  Workaround iCloud Private Relay

Temporarily disabling iCloud Private Relay provides a workaround for native applications using Safari-based authentication views.

Temporarily disable iCloud Private Relay in the iOS settings before executing the authentication flow in the native application.

  1. Navigate to Settings > iCloud > Private Relay.
  2. Turn off iCloud Private Relay.
  3. Execute the authentication flow in the native application.
 
Loading
Okta Support - Unmanaged iOS Phishing Resistance and iCloud Private Relay