<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

ZTA Score and Okta Verify FastPass

Okta Device Access
Okta Identity Engine

Overview

When configuring an authentication policy with a custom expression that requires a specific Zero Trust Assessment (ZTA) score, the custom expression alone does not enforce login with Okta Verify FastPass. Consequently, the ZTA score fails to transmit to Okta if the authentication process bypasses Okta Verify FastPass. To resolve this, enforce login with Okta Verify FastPass or require device registration in an authentication rule.

Applies To

  • Multifactor authentication (MFA)
  • Okta Identity Engine (OIE)
  • CrowdStrike
  • Endpoint Security

Cause

If the authentication process bypasses Okta Verify FastPass, the ZTA score does not transmit to Okta.

Solution

What configuration ensures Okta receives the ZTA score during login?

Configure the authentication policy to enforce Okta Verify FastPass or require device registration to ensure Okta receives the ZTA score using one of the following methods.

  • Enforce login with Okta Verify FastPass based on a combination of enrollment policy and possession factor constraints.
  • Configure at least one authentication rule to require device registration. This triggers a silent check of the device, and if Okta Verify is present, Okta provides the ZTA score in the login process.

 

Related References

Loading
ZTA Score and Okta Verify FastPass | Okta Support