<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009uIQ4QCAWOkta Classic EngineSingle Sign-OnAnswered2026-05-24T02:16:36.000Z2023-12-13T02:43:40.000Z2023-12-13T17:41:14.000Z

kbazp (kbazp) asked a question.

mfa enrollment policy from managed devices only

We need to allow users to be able to do MFA self-enrollment from company managed devices only.

Is there way to create MFA enrollment policy for managed device only?

We are on OIE


kbazp likes this.
  • b5n6c (b5n6c)

    Hi Aleksey,

    Thanks for contacting the OKTA Community.

    For managed devices you can create the authentication policy : Go to Security > Authentication Policies > Add Policy .

    Please find the attached screenshot for your reference. You can create the policy based on device state as Registered and device management as Managed.

    Image is not available
    

    Expand Post
  • avshch (BCRC)

    Thank you for your reply, the question is about MFA enrollment policy not authentication policy.

    • Hi @avshch (BCRC)​ This is not currently supported. MFA Enrollment policies are triggered only based on the following restrictions: 

      Edit 

      You may be able to restrict this, but it would mean to change all the authentication policies to managed devices only to have the MFA enrollment rule fall under “when user is accessing Okta/Applications”.  

       

       

      You can suggest Feature Enhancement for this use case on the Okta Community page by going to the Community Ideas tab. Features suggested in our community are reviewed and can be voted and commented on by other members. High popularity will increase the likelihood of it being picked up by the Product Team and it being implemented. 

      More details here.

       

       

      If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

       

      Hope my answer helps! 

      --------------------------------

      Ask Away: OIG Product Experts Answer Your Questions Thru Thur., Dec 14

      Expand Post
This question is closed.
Loading
mfa enrollment policy from managed devices only