
ptx21 (ptx21) asked a question.
I have Okta RADIUS running on my Cisco ASA and Okta RADIUS Installed on my DC. I am trying to enforce MFA On my Anyconnect VPN client. so that when users try to get on the VPN, they are required to provide a second level authentication after their password. I already enable MFA on Okta Admin and added all Domain Users, but users still dont get the MFA prompt when they log into the VPN

Hello @ptx21 (ptx21)
Thanks for posting.
When integrating with Okta RADIUS, the maximum supported number of enrolled factors is dependent on the size of resulting challenge message. Okta recommends that no more than eight ( 8 ) be enrolled at one time.
In the following document you will find a chart with the available MFA factors and if they are supported to be used with AnyConnect VPN + Radius.
Please notice, that if you are trying to use Okta Verify, it is Supported - as long as challenge is avoided.
For example:
MFA-only or password, MFA for TOTP.
Push can work with primary auth + MFA as the push challenge is sent out-of-band.
Additionally, in the same document, there is a workflow to configure it.
https://help.okta.com/en/prod/Content/Topics/integrations/cisco-radius-intg.htm?Highlight=cisco%20radius
Let us know if this helps you.
Daniela Chavarria.
Okta Inc.