<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008bjturCAAOkta Classic EngineMulti-Factor AuthenticationAnswered2023-01-03T16:41:38.000Z2023-01-02T11:18:34.000Z2023-01-03T16:41:38.000Z
MFA: Best Practices for Enrolling in combination with MDM

Hello Okta fans,

 

I am a little bit at a loss because I don't know the solution.

 

We use Okta for SSO and we use MFA at Okta and application level (not really sure what's the best practice for this too).

 

Now our problem:

We use Kandji as an MDM solution. When new employees start, they'll receive their Okta credentials along with their new computer. When they follow the setup assistant on the computer they are asked to authenticate to Kandi via Okta to assign the computer to the user.

 

In the process MFA enrollment will also be required. The thing is, they can't set up Okta Verify on their new computers because they aren't fully set up yet.

 

Is there any way to defer MFA enrollment until the computer has been fully set up?

And how would you set up the requirement for MFA? On an Okta level or on an application level?

I want our users to stay logged in for a couple of days without the need to reauthenticate.

 

Thank you for your answers!


This question is closed.
Loading
MFA: Best Practices for Enrolling in combination with MDM