
kbazp (kbazp) asked a question.
mfa enrollment policy from managed devices only
We need to allow users to be able to do MFA self-enrollment from company managed devices only.
Is there way to create MFA enrollment policy for managed device only?
We are on OIE

Hi Aleksey,
Thanks for contacting the OKTA Community.
For managed devices you can create the authentication policy : Go to Security > Authentication Policies > Add Policy .
Please find the attached screenshot for your reference. You can create the policy based on device state as Registered and device management as Managed.
Thank you for your reply, the question is about MFA enrollment policy not authentication policy.
Hi @avshch (BCRC) This is not currently supported. MFA Enrollment policies are triggered only based on the following restrictions:
You may be able to restrict this, but it would mean to change all the authentication policies to managed devices only to have the MFA enrollment rule fall under “when user is accessing Okta/Applications”.
You can suggest Feature Enhancement for this use case on the Okta Community page by going to the Community→ Ideas tab. Features suggested in our community are reviewed and can be voted and commented on by other members. High popularity will increase the likelihood of it being picked up by the Product Team and it being implemented.
More details here.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Ask Away: OIG Product Experts Answer Your Questions Thru Thur., Dec 14