Expression Language attributes for devices
When you use the Okta Expression Language to create a custom expression for devices, you can reference the following attributes that exist in the Okta Device Profile:
Attribute name and type |
Description |
Platform |
Examples |
|---|---|---|---|
|
Type: String |
Obtains the value of the device's screen lock type. |
All platforms |
|
|
Type: String |
Identifies the app that you allowed to invoke Okta FastPass. |
macOS, Windows |
Examples: The exact binary identifiers for apps can be found in your System Log. |
|
Type: String |
Obtains the binding method that's used for authentication. |
macOS, Windows, Linux |
|
|
Type: String |
Indicates whether the binary is signed. |
macOS, Windows |
Returns |
|
Type: String |
Obtains the unique identifier that Okta assigns to the device. |
All platforms |
Returns the device's Okta-assigned identifier when the user authenticates with Okta FastPass on a device enrolled in Okta FastPass. This attribute doesn't return a value when the user authenticates with a password or any other authenticator, or when the device isn't enrolled in Okta FastPass. |
|
Type: String |
Obtains the value of the device's version of Okta Verify. Use the Use |
All platforms |
CAUTION:
Don't use the For example, |
|
Type: String |
Obtains the value of the device profile's disk encryption type. |
All platforms |
|
|
Type: String |
Obtains the value of the device profile's display name attribute. 4-byte UTF-8 characters aren't supported. |
All platforms |
|
|
Type: Boolean |
Indicates whether a debugger has been detected. |
Android, iOS |
|
|
Type: Boolean |
Indicates whether the device runs as an emulator. |
Android, iOS |
|
|
Type: Boolean |
Indicates whether internal functions or runtime hooks have been detected. |
Android, iOS |
|
|
Type: Boolean |
Indicates if the mobile device has been jailbroken or rooted. |
Android, iOS |
|
|
Type: Boolean |
Indicates if an unknown third party repackaged the mobile device app. |
Android, iOS |
|
|
Type: Boolean |
Obtains the value of the device profile's managed attribute. |
All platforms |
|
|
Type: String |
Obtains the value of the device profile's manufacturer attribute. |
All platforms |
|
|
Type: String |
Obtains the value of the device profile's model attribute. |
All platforms |
|
|
Type: String |
Obtains the value of the device profile's operating system version attribute. Use |
All platforms |
CAUTION:
Don't use the For example, |
|
Type: String |
Obtains the value of the device profile's operating system. |
All platforms, including ChromeOS |
|
|
Type: Boolean |
Obtains the value of the device profile's registered attribute. |
All platforms |
|
|
Type: Boolean |
Obtains the value of the device profile's secure hardware present attribute. This checks for chip presence, in the form of a Trusted Platform Module (TPM) or Secure Enclave. It doesn't check whether there are tokens on the secure hardware. |
All platforms |
|
|
Type: String |
Obtains the value of the device profile's serial number attribute. On Linux, this attribute returns null. |
All platforms (through MDM), except Linux |
|
|
Type: String |
Obtains the value of the device profile's Security Identifier (SID) attribute. This is only available with Windows devices. |
Windows |
|
|
Type: String |
Obtains the value of the device profile's Trusted Platform Module (TPM) public key hash attribute. |
Windows |
|
|
Type: String |
Obtains the value of the device profile's unique device ID (UDID) attribute. On Android, iOS, and macOS, this attribute is only available with certain managed scenarios. On Linux, this attribute is always present because the value is retrieved from |
Android, iOS, macOS, Linux |
|
Device access attributes
The following table lists the device access attributes.
|
Attribute name and type |
Description |
Platform |
Examples |
|---|---|---|---|
|
Type: Boolean |
Indicates whether the device is joined to Okta for use of advanced capabilities like Device-Bound SSO. See Device-Bound Single Sign-On for more information. |
macOS, Windows |
|
Operators
Use operators in your custom expression to handle decisions. Any Okta Expression Language operator can be used in a custom expression. The following table lists commonly used operators:
| Operator | Description |
|---|---|
&&
|
Signifies an AND function. |
||
|
Signifies an OR function. |
!
|
Signifies a NOT function. |
<, >, <=, and >=
|
Signifies relational operators. |
==
|
Checks for equality. |
!=
|
Checks for inequality. |
See Okta Expression Language for a complete list of Okta Expression Language functions.
Important considerations
- Always include
device.profile.registered == trueif you want to include device conditions in your custom expression. - In general, device attributes can only be used if Okta FastPass is enabled.
- Device attributes can only be evaluated if Okta Verify is installed.