<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007Vj5ZhCAJOkta Identity EngineAccess GatewayAnswered2024-04-16T12:43:33.000Z2022-03-17T21:06:32.000Z2022-03-20T17:30:53.000Z
  • Hello _Rony Gonzales,

     

    Thanks for posting,

     

    You are NOT seeing the Okta MFA because the 'JSON refresh token period' for the Desktop/ Outlook rich client is set by default to somewhere between 14-90 days. It is this that is authenticating the user each time NOT a new authentication call to Okta IdP. O365 caches this and doesn't present it to the Okta IdP for authentication. If there is no authentication or 1FA then we i.e. Okta cannot invoke the 2FA or second factor - does that make sense? So you have 2 (or 3) options to move forward: 

    1. Stick with ADAL enabled in your tenant, but reduce the effect of the 'JSON refresh token period' by making a O365 "configurable token lifetimes" change to 'MaxInactiveTime' and 'MaxAgeSingleFactor' properties 
    2. https://docs.microsoft.com/en-us/azure/active-directory/active-directory-configurable-token-lifetimes
    3. This will affect all user ON and OFF network - they will be asked to go through Okta Authentication more frequently with the Desktop/ Outlook client (although ADAL/ IWA will be used on network)
    4. But the effect of your MFA off network policy, will kick in and MFA for Outlook will be seen more often off-network

     

     

    • 3rd option - look out for Roadmap 'Device trust' enhancements

     

    Let us know if this helps you.

     

     

    Daniela Chavarria.

    Okta Inc.

    Expand Post
This question is closed.
Loading
NO VERIFICATION WINDOW IN OUTLOOK 2013