<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00001ZswZD0AZOkta Classic EngineOkta VerifyAnswered2026-04-23T21:11:53.000Z2026-04-23T18:39:55.000Z2026-04-23T21:11:53.000Z

Mo A. (JDP) asked a question.

Okta ODA SCEP cert - not trusted - Mac

We’re rolling out Okta Device Access (Desktop MFA) on macOS via Jamf Pro and noticed the Okta ODA SCEP cert installs but shows as “Not Trusted” in Keychain.

A few things we’re seeing:

  • Cert is there after enrollment
  • Shows not trusted in System keychain
  • Okta Verify / Desktop MFA still works fine for now

Main questions:

  • Is this expected, or should the cert be trusted automatically?
  • If it should be trusted, what’s the right way to handle that (Jamf profile, full chain, etc.)?
  • Any issues down the road when the cert expires if it stays untrusted?

We’ve already got some endpoints like this in rollout, so just want to make sure we’re not missing something.


Loading
Okta ODA SCEP cert - not trusted - Mac