<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
What is SIGNED_NONCE
Okta Identity Engine
Multi-Factor Authentication
Overview

This article explains why the use of FastPass will show in the system logs as SIGNED_NONCE.

  • This is related to the user enrolling in Okta FastPass.
  • This can be for desktop devices, enrollment of the Okta Verify mobile application, or when a user authenticates with FastPass.


During the enrollment process, the extended Activate factor for user System Log event will show the following result:
 

Outcome > Reason User set up SIGNED_NONCE factor

During the authentication process, the extended Authentication of user via MFA with Okta Verify will show in the extended System Log event the following result:

Authentication of user via MFA event 

System > DebugContext > DebugData > Factor SIGNED_NONCE

Extended event .      Extended event 

Applies To
  • Multi-factor Authentication (MFA)
  • System log
  • Okta Identity Engine (OIE)
  • Okta FastPass
Solution

When moving to Okta Identity Engine (OIE), if a user enrolls in Okta Verify, they will also be enrolled in FastPass automatically. Per the OIE documentation:

  • Regardless of which verification option is selected, end users are still automatically enrolled in all of them. They appear in the app's Account Details page as Authentication Code, Push Notification, and This Device.
  • Enrolling end users in all the methods automatically, but letting one control which methods are shown to them when authenticating, is intended to simplify the end-user experience in case some methods are added or removed later.

 

Related References

Loading
What is SIGNED_NONCE