
adtfd (adtfd) asked a question.
Currently we are an global organisation which Corp owned iOS devices are using ABM alongside MEM to deploy and configure the remote configuration for setup to the device.
OKTA MFA options are SMS or OKTA Verify.
Current scenario is upon the new starter induction we ask the user to use an alternative device or phone number for SMS authentication. SMS authentication of the new work phone number is not able to be received in the setup assistant of the iPhone. We can ask users to use an alternative number but will sometimes refuse or we will suggest installing the authenticator app.
What we would like to know is what customisation even on a onetime setup like this or what other visible options are available to the new user at the first time setup of a iphone or ipad?

Hello @adtfd (adtfd) Thank you for reacting out to our Community!
If you are talking about MFA enrolment when the users are first signing into Okta, please see our authenticator list and enrolment policy documentations below:
https://help.okta.com/oie/en-us/Content/Topics/identity-engine/authenticators/configure-authenticators.htm
https://help.okta.com/oie/en-us/Content/Topics/identity-engine/policies/about-mfa-enrollment-policies.htm
Please keep in mind that it also depends on how users authenticate into Okta that might prompt them for an MFA, for this you need to setup or review your current sign on policy's. Our documentation below:
https://help.okta.com/en-us/Content/Topics/Security/policies/configure-signon-policies.htm#:~:text=The%20Okta%20sign%2Don%20policy,then%20add%20rules%20to%20it.
https://help.okta.com/oie/en-us/Content/Topics/identity-engine/policies/about-policies.htm
Community members help others by clicking Like or Select as Best on responses. Try it today.
Okta Identity Engine (OIE) Ask Me Anything: Get answers from product experts by clicking here.