<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Windows Hello Is Not Supported For Okta FastPass User Verification In Virtual Desktop Infrastructure

Okta Identity Engine
FastPass

Overview

Okta does not support Windows Hello for satisfying Okta FastPass User Verification in Virtual Desktop Infrastructure (VDI) environments because virtual machines lack native biometric hardware and Okta Verify cannot utilize redirected virtual channels. To satisfy User Verification policies in virtualized operating systems, administrators must deploy Okta Verify Passcode. When deploying Okta Verify and FastPass in VDI environments, Windows Hello biometrics or PINs fail to satisfy User Verification requirements.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Verify for Windows (version 4.9.0 and higher)
  • Okta FastPass
  • Virtual Desktop Infrastructure (VDI)

Cause

Virtual machines are hardware-abstracted guest operating systems that lack direct hardware access to native biometric sensors and physical Trusted Platform Modules (TPM). While Remote Desktop Protocol (RDP) or Citrix Independent Computing Architecture (ICA) can redirect Windows Hello for Business for session logon, this virtual channel does not expose a locally accessible Key Storage Provider (KSP) to user-mode third-party applications. Okta Verify requires direct local cryptographic application programming interface (API) calls to bind and sign application-specific user verification keys and cannot communicate across these virtual channels. Additionally, sealing a cryptographic key against a specific hypervisor virtual TPM locks the key to that single virtual machine instance, which breaks user enrollment when reconnecting to a different host in a pooled VDI environment.

Solution

How is Okta Verify Passcode implemented in Virtual Desktop Infrastructure?

Okta Verify Passcode bypasses Windows Hello and utilizes the Windows Cryptography API: Next Generation (CNG) to manage user verification keys. During enrollment, Okta Verify prompts for a six-digit passcode and uses it to encrypt and seal the private user verification key. When an Okta application sign-on policy requires user verification, Okta Verify prompts for this passcode to unlock the private key and cryptographically sign the authentication challenge. Because the key is managed via Windows Software Key Storage rather than a hardware-bound TPM, the key containers serialize and roam safely across pooled VDI hosts using profile containers.

What are the deployment and configuration steps for Okta Verify Passcode?

Install Okta Verify for virtual desktop golden images, templates, or mobile device management distributions using specific command-line switches.

  1. Open a command prompt or deployment tool.
  2. Enter the following installation command, replacing <your-org> with the specific Okta organization URL and <VDI_MODE> with the appropriate operation mode.

1› OktaVerifySetup-x.x.x.x.exe OrgUrl="https://<your-org>.okta.com" AuthenticatorOperationMode="<VDI_MODE>" UserVerificationType="OktaVerifyPasscode"
 

Review the accepted values for the installation parameters by referencing this table.

Parameter
Accepted Values
Description
AuthenticatorOperationMode
VirtualDesktopStatic
Use for persistent or dedicated VDIs where users are statically assigned to the same virtual machine instance.
AuthenticatorOperationMode
VirtualDesktopLayered
Use for non-persistent or pooled VDIs where users connect to arbitrary virtual machines and user profiles roam.
UserVerificationType
OktaVerifyPasscode
Bypasses Windows Hello and configures Okta Verify to use the application-managed passcode.

NOTE: Setting AuthenticatorOperationMode automatically defaults UserVerificationType to OktaVerifyPasscode.

Which profile persistence paths are required for layered Virtual Desktop Infrastructure?

Ensure the following directories and registry paths persist in the user profile container when deploying in VirtualDesktopLayered mode with profile management tools.

  • C:\Users\%USERNAME%\AppData\Local\Okta\OktaVerify
  • C:\ProgramData\Okta\OktaVerify
  • %APPDATA%\Microsoft\Crypto\Keys
  • %LOCALAPPDATA%\Microsoft\Credentials
  • %LOCALAPPDATA%\Microsoft\Vault
Loading
Windows Hello Is Not Supported For Okta FastPass User Verification In Virtual Desktop Infrastructure | Okta Support