<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
User is Getting "Login failed" Error with Desktop MFA Using Both the Okta Verify Push Notification and Okta Verify OTP Code
Okta Identity Engine
Okta Device Access
Overview

Login failed error message is encountered on Desktop MFA for Windows using online factors (OV Push, OV OTP). Offline access using the OV OTP code is working.

 

Login error

Applies To
  • Okta Device Access
  • Desktop MFA for Windows (DMFA)
  • Okta Identity Engine (OIE)
Cause

The reported behavior happens when the Desktop MFA authentication policy rule is changed to Allowed with password + another factor and this will not be satisfied by the DMFA client.

The authentication policies on the DMFA app do not apply to the desktop login as they do for other apps through a web browser. The credential provider validates the password first and then only calls the app in Okta for the OV Push challenge.

Solution

Change the Desktop MFA Authentication Policy rule to Allowed with possession factor.

MFA rules

Loading
User is Getting "Login failed" Error with Desktop MFA Using Both the Okta Verify Push Notification and Okta Verify OTP Code