
DennisT.63689 (Customer) asked a question.
I have my AnyConnect RADIUS app working fine, however, I want to force phishing resistant factors so Okta Verify Push or Fob/Yubikey should be the only ones allowed. Unfortunately there doesn't seem to be a way to force this like we can for other applications. Am I missing something?

Hi Dennis, yes RADIUS is 30+ years old now and there are no more ways to make it work with newer authentication techniques. Okta highly recommend using the SAML integration for AnyConnect. This allows for more modern authentication techniques to be used. You might want to check in with support for your specific factor support questions.
Hi Mark. Yes, I understand that we can't make RADIUS perform new tricks, however, can Okta not be configured with an authentication policy that allows us to set acceptable factors like with other apps? Okta is the one that sends back the list of enrolled factors to the user via RADIUS for them to choose (1-Push, 2-SMS, etc.) so I would assume that this is something that can be done. Allowing someone to use a non phishing resistant method defeats the purpose of MFA to begin with.
Those policies are not available in that app because most if not all modern authentication techniques (including phishing resistant) require the use of a browser to work. This browser can not be started as part of a RADIUS flow.
Forgive me, I'm not following. I can use a Yubikey or Okta Verify Push notification with RADIUS so why can I not mandate that those are the only available options to use? Sorry if I'm being dense.
Hello @DennisT.63689 (Customer) Thank you for reacting out to our Community!
You should be able to do this thought the Application policy. Keep in mind that with Radius the Primary method of authentication would be Password, as such in Okta you can setup an app policy with 2 factor types: To require users to provide two distinct factor types (Password + Another factor or Password / IdP + Another factor).
Please check our policy doc below:
https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/add-app-sign-on-policy-rule.htm
However if you have additional MFA enabled on your Org for your users, they might be able to use them as well. For this you will need change the enrolment policy to satisfy your requirements.
For this please see our doc below:
https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/about-mfa-enrollment-policies.htm
Community members help others by clicking Like or Select as Best on responses. Try it today.
Earn Today: New Okta Community Badges Have Arrived
Ask the Experts: Now Thru 1/31 Okta FastPass Engineering and Product Teams Answer Your Questions
Hi Paul. It doesn't look like I can assign my RADIUS app to any of the authentication policies?
Hello @DennisT.63689 (Customer) It seems this is expected behaviour, and the policy that applies to Radius is the Organisation Global policy.