<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009nFwwYCASOkta Classic EngineMulti-Factor AuthenticationAnswered2024-04-03T16:09:08.000Z2023-10-26T13:45:59.000Z2023-10-27T07:13:45.000Z
  • MatthewH.10249 (State of Iowa)

    I think you are talking about Okta FastPass which is Okta Verify for Windows and MacOS. The following documentation does not make me think there is an option in Okta to prompt them to install on their desktop. Step4 in the following says you would deploy/install for them on managed (SCCM) devices and for all others you would have to come up with a way to let them know they need to download and install themselves.

     

    https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-configure.htm

    Expand Post
  • Hi Matthew,

    thank you for your answer. Installation is not a problem. We are able install them on mangled devices.

    The topic here is how can we ensure that users are enrolling for okta fastpass on their desktops (Mac or windows). Basically users get promoted to set up phone by default but can we make okta fastpass on desktops as default?

    Expand Post
  • MatthewH.10249 (State of Iowa)

    As a test, I removed my account from Okta Verify/Fast Pass on my Windows PC for a preview tenant and logged out of that tenant. I then clicked the [Sign in with Okta FastPass] button on my Okta hosted/redirect widget and this launched my Okta Verify client on my Windows PC which was closed and the widget screen changed showing the following text, [button] and <links>.

     

    Click "Open Okta Verify" on the browser prompt

    Didn’t get a prompt?

    [Open Okta Verify]

    Don’t have Okta Verify?

    <Download here>

    <Back to sign in>

     

    The Okta Verify app on my Windows PC shows the following text with an "Add account" button and a "Not now" link.

     

    Add an account to access Okta Dashboard

    You're about to set up an account for **tenant name** to securely sign in to your organization's app.

    [Add account]

    [Not now]

     

    So from my testing it seems it does prompt if you click the [Sign in with Okta FastPass] button on the Okta hosted widget. If you don't enable the "Show the "Sign in with Okta FastPass" button" option for the Okta Verify Authenticator in the Admin Console I'm not sure how Okta would know the user wants to use a PC client. Regarding my testing I will point out that I had to click the [Sign in with Okta FastPass] button twice before the widget screen would change and the Okta Verify PC client would open. I tried this several times and was consistent so it might be a bug.

     

    Hopefully someone from Okta will chime in on this as I too would like to know how to address this should we choose to not show the Fast Pass button.

    Expand Post
  • Thanks Matthew again for the detailed reply. Okta FastPass on the sign in widget is enabled in our test tenant

    here is the set up that I have on our test environment:

    • created a quick bookmark app
    • created a policy as below:
    • image
    • Now when my test account (assigned to the app) invokes the app, it prompts me to set up OV on mobile
    • image
    Expand Post
This question is closed.
Loading
Prompting Users for OV Desktop MFA instead of OV Mobile