Amazon Web Servires user experience
The Amazon Web Services Workspace end user experience should be similar to the oriignal client experience before integrating with RADIUS. However end users will now be prompted for an additional validation factor after the login with their normal credentials.
The following describes the user experience once integration with RADIUS is complete.
Topics
Okta MFA enrollment
-
End user receives an activation link in the inbox.
-
When a user clicks on the activation link they are directed to the onboarding page:
-
When a user clicks on the activation link they are directed to the onboarding page:
-
User can click on Configure factor and select a mobile OS::
-
User downloads Okta Verify app on their mobile device. Opens the app and scans the barcode displayed on the laptop:
-
Okta Verify self-enrollment is complete when user clicks on Finish
User may choose to configure additional factors.
Note: you can fully customize the email template from Okta admin console.
Note: When complete the user is redirected to the Okta dashboard.
AWS Workspace + Okta MFA Challenge
-
Once Okta MFA is enabled within the AWS Workspace, end users will see a MFA field on their workspace sign in page similar to:
-
The MFA code can be used in 2 ways:
-
You can enter the Okta Verify OTP that is displayed on your enrolled mobile phone in Okta Verify App.
Click on your username in the mobile app to display the OTP. If you enter username+password and Okta Verify OTP as MFA code, you'll be signed in automatically. -
You can enter push as value.
If you enter username+password and push as MFA code: you will receive a push notification on your enrolled mobile phone. Once you approve, you'll be signed in automatically in your workspace instance.
-