<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009hbQ2TCAUOkta Identity EngineOkta Device AccessAnswered2025-09-13T09:01:51.000Z2023-10-06T15:42:26.000Z2023-10-31T21:59:48.000Z

HelpdeskA.96249 (Customer) asked a question.

desktop mfa not prompting with MFA after entering password

when i login with my user account it only primpts for the one time password. it never sends the push notification. the device is on the network.

 

also the info here

 

https://support.okta.com/help/s/article/desktop-mfa-troubleshooting-steps-when-user-is-not-getting-prompted-for-mfa?language=en_US

 

in step 5 for the registry changes is somewhat different than what is listed here

 

https://help.okta.com/oie/en-us/content/topics/oda/windows-mfa/configure-win-mfa-policies.htm

 

so not sure which is correct


  • HelpdeskA.96249 (Customer)

    i figured it out...

     

    it was the sign on > application username format that needed to be changed in the admin console for the application. it was actually through watching this youtube video that i figured it out. https://www.youtube.com/watch?v=JVq5_ikXgXI

     

    i would like to get clarity though in the registry key changes that are needed. since the information online is somewhat conflicting.

     

    okta really needs to update their kb on the deployment and configuration. having to sort through 3+ different resources to configure this is disappointing

     

    Expand Post
  • a0n5s (a0n5s)

    @HelpdeskA.96249 (Customer)​ I would also like to know if desktop mfa is easy to use, many of our customers need this feature. thanks.

    • HelpdeskA.96249 (Customer)

      since it is currently in EA the documentation is a bit inconsistent across their KB articles. but configuration is pretty basic and so is the functionality. since its early on in the product Lifecyle there are some very specific requirements youll need to meet to be able to hae the application available for deployment, as well as additional licensing cost.

       

      but in my testing it seems to work adequately. there are some nuances right now that i am trying to sort through with their support before i can really start pushing it out. still trying to make okta device access the default credential authenticator and not display any other Windows Hello configuration a user might have setup. using any of these other ones bypasses okta desktop MFA right now.

      Expand Post
      • a0n5s (a0n5s)

        thanks. So now the default windows credential provider can't disalbe?

      • HelpdeskA.96249 (Customer)

        you can disable it currently but cannot disable the other Windows Hello configurations like PIN and fingerprint. or at least Okta support hasnt come up with a solution for me yet. also right now the offline access doesnt work at all and their support just confirmed it is a bug that needs to be fixed. even though the service is in EA, they really need to have some updated issue tracker page so that i am not wasting my time testing features that are known broken.

        Expand Post
This question is closed.
Loading
desktop mfa not prompting with MFA after entering password