
MonteD.49528 (Customer) asked a question.
Passwordless Offline Biometrics for Desktop MFA
We are using Okta Verify for Windows v6.11.1.0 for Desktop MFA. We have been frustrated that the offline login has required a password because we want to be fully passwordless. We are excited about the new offline biometrics for desktop MFA feature that's in EA and we're trying to make it work. According to the documentation, enabling one or both and using the correct registry keys will actually make the offline login fully passwordless and users can login using only their face or fingerprint if they're offline.
We can't get it to skip the password prompt while offline though. Everything else works great. We believe we have all the right registry keys. Has anybody been able to make this work yet, or do we just need to wait for the next round of bug fixes since this feature is EA?
At HKLM\SOFTWARE\Policies\Okta\Okta Device Access we have the following keys:
- AllowedFactors = OV_Push Offline_TOTP Offline_Fingerprint Offline_FaceBio
- CredProvidersToExclude = {D6886603-9D2F-4EB2-B667-1971041FA96B} {BEC09223-B018-416D-A0AC-523971B639F5} {8AF662BF-65A0-4D0A-A540-A338A999D36F}
- OktaJoinEnabled = 1
- PasswordlessAccessEnabled = 1
- PrioritizeBiometrics = 1
- OfflineLoginAllowed = 1
At HKLM\SOFTWARE\Okta\Okta Device Access we have:
- UseDirectAuth = 1
- OrgURL, and obscured client ID and secret

Updating this response for ease of access and reference:
Okta Verify Desktop Multi-Factor Authentication (MFA) prompts for a password during offline login despite the configuration of offline biometrics. This fallback occurs when the FIDO2 key lacks a Personal Identification Number (PIN). Configuring a PIN for the FIDO2 key resolves the issue.
During an offline login attempt using Okta Verify for Windows version 6.11.1.0 or later, the authentication process skips the biometric prompt and requires a password. This happens even when the PasswordlessAccessEnabled registry key has a value of 1 and AllowedFactors includes Offline_Fingerprint or Offline_FaceBio.
Applies To
Cause
The PasswordlessAccessEnabled
registry key supports Okta Verify Push, FIDO2 keys, and Windows Hello biometrics. Desktop MFA always attempts to enforce user verification through the FIDO2 key PIN. If the FIDO2 key lacks a configured PIN, Desktop MFA falls back to password authentication.
Solution
What steps resolve the offline biometric password fallback?
Configure a PIN for the FIDO2 key and verify the registry settings to ensure passwordless offline access functions correctly.