<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7VOKSA3Okta Classic EngineMulti-Factor AuthenticationAnswered2024-04-30T09:18:25.000Z2018-03-06T09:28:23.000Z2019-08-12T20:41:59.000Z
  • MichaelG.21991 (Customer)

    This is something we asked about before committing to Okta MFA. Like us, you are probably looking for something like the google authenticator extension app or similar. Okta does not currently have something like this. The reasoning given was that it technically wouldn't be a viable second factor since you can get the second factor on the same computer as where you are attempting to log into the system. I can't argue with that, however it does pose a problem (particularly for us) where there are partners that don't have access to another factor due to being in secure offices (no phones, etc).

    Expand Post
    Selected as Best
  • Hello my name is Bogdan from Okta customer support.

     

    Curently Okta supports Windows Hello and U2F security key (FIDO 1.0).

    These two factors should allow your users to use MFA on their Desktops and sign-in into Okta.

    We also support Email Authentication as an MFA factor, though Email Authentication is not a best practice. When you add it as a factor, you must accept the risk of using it. The following message appears:

    We do not recommend that you use email as a second factor experience for Okta. This experience is a very insecure method of additional verification as: 
    • Email can be compromised by third parties
    • Email is not always transmitted over secure protocols
    • Email can also be used, depending on the recovery flow, for primary credential recovery
     Although we do offer email as a factor experience for convenience and to help our customers migrate off of legacy identity platforms, we do not consider it to be a secure, modern method for secondary authentication. To continue enabling this feature, please click "I accept the risk" below.”

    Using this Kb you can find additional details about the factors mentioned above.

    https://help.okta.com/en/prod/Content/Topics/Security/MFA.htm

     

    Thank you,

     

    Bogdan Musat

    Technical Support Engineer

    Okta Global Customer Care

     

    Expand Post
  • j5v7c (j5v7c)

    Hello,

     

    ​If you receive a great answer to your question, please help readers find it by marking it the best answer. Hover over the answer and click "Best Answer." 

     

    Thank you,

    OHC Team
    Expand Post
  • VipinV.44200 (Customer)

    I was expecting a solution from Okta to provide its own soft token that can be used in Development Center which has restricted accesss for carrying mobile devices,
  • j5v7c (j5v7c)

    Hi Vipin,

     

    We will doc your question and route it to the proper tech specialist who can give you a more detailed answer.

     

    Thanks for your feedback,

     

    ​Dylann Fezeu

    Okta Help Center Team
    Expand Post
  • teju.shyamsundar1.4926262186631091E12 (Product Strategy, EMEA)

    Hi Vipin

     

    Is the question around providing a desktop version of the Okta Verify application? While we do not offer the Okta Verify app on desktops, the best practice here (if possible) is to authenticate using a U2F hard token - Yubikey, for example, which replaces the need for a mobile phone in the development centers. Outside of this, we also have the option to use email as factor in scenarios where employees are not able to authorize via a mobile device.

    Expand Post
  • VipinV.44200 (Customer)

    I was thinking of something like the RSA soft tokens, we want to get away with RSA and see if some other option is available .

  • MichaelG.21991 (Customer)

    This is something we asked about before committing to Okta MFA. Like us, you are probably looking for something like the google authenticator extension app or similar. Okta does not currently have something like this. The reasoning given was that it technically wouldn't be a viable second factor since you can get the second factor on the same computer as where you are attempting to log into the system. I can't argue with that, however it does pose a problem (particularly for us) where there are partners that don't have access to another factor due to being in secure offices (no phones, etc).

    Expand Post
    Selected as Best
This question is closed.
Loading
Does Okta provide a soft token for desktops MFA similar to Okta Verify on mobile devices?