<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00008mNGmCCAWOkta Classic EngineAdministrationAnswered2025-09-13T09:01:51.000Z2023-02-16T23:52:58.000Z2023-02-21T16:35:53.000Z

an8zk (an8zk) asked a question.

How do I configure an application policy to only permit certain devices?

To elaborate on the question, I working in a purely OS environment, no ldap, Kandji(MDM), and Google workspace. Im seeing articles about leveraging your mdm for device trust and all.

 

But when it comes to creating the actual application sign on policy how do I restrict even further than merely the device platform? Can I leverage expression language to permit only certain mac addresses?


  • Hi @an8zk (an8zk)​ , Thank you for reaching out to the Okta Community!

     

    This is currently not supported. You can't configure anything beyond the client list mentioned in the app sign-on policy UI. 

     

    You can suggest this as a feature enhancement on the Okta Community page by going to the Community Ideas tab. Features suggested in our community are reviewed and can be voted and commented on by other members. High popularity will increase the likelihood of it being picked up by the Product Team and it being implemented.  

    More details here: 

    https://support.okta.com/help/s/blog/a674z000001cj7YAAQ/okta-ideas-faq?language=en_US

     

     

    Hope my answer helps! 

    --------------------------------

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    Expand Post
  • a0n5s (a0n5s)

    @an8zk (an8zk)​ what's your OS? Mac or Windows? is it support Mac Touch ID or Windows Hello? you can set up MFA by WebAuthn and only allow Mac Touch ID and Windows Hello. So user can only add one device for WebAuth. But I don't know whether Okta Classic Support AAGUID, it is a early access feature in OIE.

  • an8zk (an8zk)

    Sorry. IOS is what I was getting at. Interesting. Thank you for this, will look into restricting access this way.

This question is closed.
Loading
How do I configure an application policy to only permit certain devices?