<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000AJRTBrCQPOkta Classic EngineAuthenticationAnswered2025-02-13T16:30:40.000Z2025-02-12T16:35:31.000Z2025-02-13T16:30:40.000Z

SecN.79290 (Customer) asked a question.

02/11/25 Release Notes - "Enforce Number Challenge for Desktop MFA (Identity Engine only)"

With the latest update of the Okta Release notes (02/11/2025) - there is a line item towards the bottom of GA features labeled "Enforce Number Challenge for Desktop MFA (Identity Engine only)." We originally had this set to "never" but this morning, users are reporting this as being enforced.

 

I have since changed the setting to "Only for high risk sign-on attempts" for the time begin. Is this something that will be default now?


SecN.79290 likes this.
  • @SecN.79290 (Customer)​ - forgot to mention that you can disable it via Okta Admin Dashboard > Security > General > Okta Device Access , but we recommend you keep it enabled to prevent users from approving incorrect push notifications.

    Selected as Best
  • Hi @SecN.79290 (Customer)​ , Thank you for reaching out to the Okta Community! 

     

    I've checked with the internal team and confirmed that now that the feature went into GA, all orgs have it enforced. 

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    The new Okta Help Center YouTube channel is your go-to resource for tips, troubleshooting, and best practice videos. Subscribe today.

    Expand Post
  • SecN.79290 (Customer)

    Mihai, thank you for the response! I understand more now that I have read more into admin portal.

     

    Thank you!

  • @SecN.79290 (Customer)​ - forgot to mention that you can disable it via Okta Admin Dashboard > Security > General > Okta Device Access , but we recommend you keep it enabled to prevent users from approving incorrect push notifications.

    Selected as Best
This question is closed.
Loading
02/11/25 Release Notes - "Enforce Number Challenge for Desktop MFA (Identity Engine only)"