<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008gKCClCAOOkta Classic EngineAuthenticationAnswered2024-04-16T10:25:38.000Z2023-01-18T19:15:21.000Z2023-01-19T22:19:30.000Z

ko0ms (ko0ms) asked a question.

Device Trust setup on a per app basis but not for signing into Okta initially.

Hi! We are looking to start implementing device trust here in our organization tied into our MDM, Kandji and eventually Google's MDM. Additionally, we want to enforce phishing resistant MFA across specific applications but not for all. Our ideal setup would be:

 

  • You do not need to be enrolled in our MDM to get to the Okta dashboard.
  • You do need to have a phishing resistant MFA method to sign into your Okta dashboard, Okta verify will be disabled for this sign in process.
  • You do not need to enrolled in our MDM to get HR or Finance applications like Rippling, Expensify, etc.
  • You do need to be enrolled in our MDM to access specific applications like Google, Slack, Jira, etc.
  • We need to allow Okta verify to be used for device enrollments through DEP. Okta verify should be available as an option during enrollment only.

 

Is this setup doable, especially the piece of using Okta verify for only device enrollments but not allowing it as an option when signing into the dashboard?


This question is closed.
Loading
Device Trust setup on a per app basis but not for signing into Okta initially.