MFA for Active Directory Federation Services (ADFS)

Install the Okta Multifactor Authentication (MFA) provider for Active Directory Federation Services (ADFS) v. 3.0 and v 4.0.

This feature allows customers to use ADFS as their Identity Provider (IdP) for applications and Okta for MFA for strong authentication for your applications. See the list of prerequisites and assumptions before you begin installation.

The Sign-In Widget (third generation) doesn’t support multifactor authentication for third-party agents.

Before you begin

Requirements for installing the Okta Credential Provider for Windows:

  • Proxy Configuration: The Okta Credential Provider for Windows doesn't support a discrete proxy configuration but does follow system level proxy configurations.
  • The Windows machine used for installation must have an active internet connection with port 443 open.
  • The installing account must have administrative rights to install the Okta Windows Credential Provider Agent, Visual C++ Redistributable and .NET 4.0+.

Supported operating systems

The Okta Credential Provider for Windows agent can be installed on the following:

  • Windows Server 2019 (v1.3.0 and later)
  • Windows Server 2016
  • Windows Server 2012
  • Windows Server 2012 R2

Typical workflow

Task

Description

Download the agent In the Admin Console, go to SettingsDownloads. Download the Okta MFA provider for ADFS agent from the MFA Plugins and Agents section to the machine on which to install the agent. See Okta ADFS Plugin version history.
Install and configure Microsoft ADFS in Okta Enable and configure:
  • Required MFA factors and a target group
  • The ADFS application
  • Cross-Origin Resource Sharing
Install the Okta ADFS Plugin on your ADFS Server Install and configure the ADFS Plugin on the ADFS server.

See Configure MFA for Active Directory Federation Services (ADFS) for more information on ADFS configuration settings.

Enable the Okta MFA Provider in ADFS Enable Okta as an MFA provider for ADFS.
Add Access Control Policy to a Relying Party Application Add the Access Control Policy to a Relying Party Application.
Assign the Microsoft ADFS (MFA) application Assign Okta application to users or groups.
Verify the Okta MFA prompt when signing in to ADFS Verify that the application behaves as expected.
Troubleshooting Troubleshoot the Okta MFA provider for ADFS agent installation.

Post installation and configuration tasks

Task

Description

Enable Open ID Connect with existing ADFS installations Enable Open ID Connect with existing ADFS installations.
Enable MFA as a service for existing installations configured for OIDC Enable MFA as a service with existing ADFS installations.