Autopush for RADIUS
Okta's Autopush for RADIUS allows you to use the high assurance, low friction Okta Verify with Push feature when it is not possible for an end user to opt-in. The Okta Verify with Push experience has been popular with Admins for its high security implementation. The option for an end user to opt in for an automatic push has also increased end-user satisfaction by removing additional friction; specifically, the extra click to request the push. However, in some use cases, the end user cannot opt in, as this behavior is stored in a browser cookie. To bridge this gap, Okta's Autopush for RADIUS feature permits an admin to configure the behavior without requiring an enduser opt in.
Autopush for RADIUS is compatible with the following:
- Okta VPN integrations supported by RADIUS
- Okta's Generic RADIUS app
Step-by-step Configuration Guide
There are seven parts to the configuration, including prerequisites and testing. Answers to frequently asked questions are also provided.
Before you begin, you must complete the following four steps.
Implement either an Okta VPN (using RADIUS) or the Okta Generic RADIUS App in your Okta Preview test environment.
- Configure an app-based sign on policy for the application to require MFA on authentication.
- Enable Okta Verify with Push for your Okta preview test environment.
- Assign a test user to the configured app and enroll the test user in Okta Verify.
Complete the following steps to enable RADIUS Autopush,
In the Sign on tab for the app you created, scroll down to Advanced RADIUS Settings and click Edit.
- Check the boxes for both of the following items, as shown below.
- Accept password and security token in the same login request
- Permit Automatic Push for Okta Verify Enrolled Users
Note: The first setting is required for autopush. It permits access with alternate MFA if a user has misplaced their device or otherwise lacks access to acknowledge the push.
- Click Save.
Test the integration by performing an authentication with your test user against the configured RADIUS App or RADIUS enabled VPN. No other testing is necessary.