<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009ILb6qCADOkta Classic EngineMulti-Factor AuthenticationAnswered2024-04-03T16:09:08.000Z2023-06-06T18:56:36.000Z2023-09-21T15:42:29.000Z

MatthewH.10249 (State of Iowa) asked a question.

Disable Okta Verify Biometrics Issue

I have a pretty reputable/knowledgeable user (lead developer) that was having issues with his AD account being locked on a VM. He did not know his account was locked and when he went to login elsewhere he would get prompted by Okta Verify to provide his biometrics like normal but could not get past the biometrics. It was not until he would get the account unlocked that he could get past biometrics. During initial evaluation before he found out what was locking his account he had wondered if the biometrics could lock his account. I could not find any documentation to back that claim up and was later debunked but at that time he disabled his biometrics using the following information but even after restarting Okta Verify and his Android phone he continues to get a biometric prompt for Okta Verify.

 

https://help.okta.com/eu/en-us/Content/Topics/end-user/ov-config-biometrics-android.htm*Disable

 

My two question to the Community are:

  1. Is there any documentation like a knowledge base article that talks about how a locked account will impact Okta Verify biometrics?
  2. If a user disabled biometrics in Okta Verify but continues to get prompted for biometrics what can be done other than uninstalling and reinstalling Okta Verify?

 

Thanks and I hope you are having a great day!


  • User16594883467582706479 (Customer Support Online Experience)

    Hi, @MatthewH.10249 (State of Iowa)​ 

     

    Thank you for posting on our Community page!

     

    In my opinion, the best solution would be to un-enrol and re-enrol.  

     

    Basically, you need to remove the account and the device and re-enrol them.

     

    There are two steps to remove:

    1. In Okta Verify app, go the "Account details", then click on "Remove account" under "Manage account". You will again see the verify popup followed by the "Verify your identity", but then the delete should be successful.

    2. Go to your End User Dashboard to remove your Okta Verify enrollment for this phone. To go to End User Dashboard, sign in with yourcompany.okta.com as you usually would, then go to Settings. Scroll down to Extra Verification or Security Methods section. find Okta Verify, and find your device. You should see a "Remove" button next to it. Click that to complete the removal of this account. NOTE: it is OK if you see the "Sync biometric" notification again from OV when you respond to push. You'll just have to use your password or the code sent to your phone SMS to complete the sign in also (depending on what other than Okta Verify you have set up).

     

    Once "Remove" is complete, you should re-enroll RIGHT AWAY. Click the "Set up" or "Set up another" button next to Okta Verify. Follow the steps to get a QR code, and enroll.

     

    For clarity, even if you remove biometrics from the device settings, if they are asked for by the authentication policies, OV will keep asking for them.

     

    Thank you for reaching out to our Community and have a great day!

    _____________________________________________________________________________

    Watch and Learn: New Okta how-to videos, plus what's new this month in the May newsletter.

    _____________________________________________________________________________

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    _____________________________________________________________________________

     

     

    Expand Post
    Selected as Best
  • User16594883467582706479 (Customer Support Online Experience)

    Hi, @MatthewH.10249 (State of Iowa)​ 

     

    Thank you for posting on our Community page!

     

    In my opinion, the best solution would be to un-enrol and re-enrol.  

     

    Basically, you need to remove the account and the device and re-enrol them.

     

    There are two steps to remove:

    1. In Okta Verify app, go the "Account details", then click on "Remove account" under "Manage account". You will again see the verify popup followed by the "Verify your identity", but then the delete should be successful.

    2. Go to your End User Dashboard to remove your Okta Verify enrollment for this phone. To go to End User Dashboard, sign in with yourcompany.okta.com as you usually would, then go to Settings. Scroll down to Extra Verification or Security Methods section. find Okta Verify, and find your device. You should see a "Remove" button next to it. Click that to complete the removal of this account. NOTE: it is OK if you see the "Sync biometric" notification again from OV when you respond to push. You'll just have to use your password or the code sent to your phone SMS to complete the sign in also (depending on what other than Okta Verify you have set up).

     

    Once "Remove" is complete, you should re-enroll RIGHT AWAY. Click the "Set up" or "Set up another" button next to Okta Verify. Follow the steps to get a QR code, and enroll.

     

    For clarity, even if you remove biometrics from the device settings, if they are asked for by the authentication policies, OV will keep asking for them.

     

    Thank you for reaching out to our Community and have a great day!

    _____________________________________________________________________________

    Watch and Learn: New Okta how-to videos, plus what's new this month in the May newsletter.

    _____________________________________________________________________________

    Community members help others by clicking Like or Select as Best on responses. Try it today.

    _____________________________________________________________________________

     

     

    Expand Post
    Selected as Best
    • MatthewH.10249 (State of Iowa)

      @User16594883467582706479 (Customer Support Online Experience)​ thanks for the response! The steps you provided are exactly what we tried and we do not have biometrics set as a requirement anywhere in our Okta tenants but he is still getting prompted. I've suggested that he uninstall OV from his device and reinstall to see if that fixes the issue. He is a little reluctant to fully delete the app on his phone since he has OV configured for at least 4 Okta tenants and more multiple users.

      Expand Post
      • MatthewH.10249 (State of Iowa)

        If the person with the problem ends up reporting the issue via "Send feedback" I'll also open a support case. Thanks and have a great day!
      • MatthewH.10249 (State of Iowa)

        @Laura Negoi (Employee), the user just reported to me that after disabling biometrics in OV he had issues until his AD account lock issue was resolved but since then things are working fine and he is not being prompted for biometrics. At this point we are NOT going to open a support ticket as we would have no way to reproduce the issue. Hopefully these notes will still help you should you ever hear something similar from others in the future.

        Thanks for your time and help on this matter!
        Matthew
        Expand Post
This question is closed.
Loading
Disable Okta Verify Biometrics Issue