Okta Verify for macOS

You can download the Okta Verify package for macOS from these locations:

Current release

Version: 9.63.0

Preview deployment: May 11, 2026

Release summary

Secure Enclave key support for Platform SSO

Platform SSO now supports a Secure Enclave key-based authentication method that integrates with Device-Bound SSO. When a user authenticates at the macOS login window with their password, the authentication unlocks a hardware-bound cryptographic key stored in the Secure Enclave. Okta uses the key to create a device-bound session that satisfies any authentication policy that requires Okta FastPass with user verification, without repeated MFA prompts. See Platform SSO for macOS and Configure device configuration profiles for Secure Enclave using a generic MDM.

Platform SSO password integration with Device-Bound SSO

The Platform SSO password authentication method now integrates with Device-Bound SSO. When a user signs in at the macOS login window, Okta verifies the password factor and creates a device-bound session. Users can then access Okta-protected apps in their browser without additional password prompts. See Platform SSO for macOS and Configure device configuration profiles for PSSO using a generic MDM.

Fixes and enhancements

  • When a user registers their device using Platform SSO, the authentication flow now appears in a dedicated pop-up window, rather than through a default browser window.

  • When users attempted to enroll an iPhone in Okta Verify from another device using Bluetooth, they sometimes received a message on the already enrolled device, saying Something went wrong. Enrollment of the new device succeeded on subsequent attempts, even though the error message continued to appear. (OKTA-1142007)

  • This release also includes internal improvements and usability fixes.


Previous releases

Version: 9.61.1

Production deployment: May 4, 2026

Release summary

New configuration option for Okta Verify user verification

Admins can now configure user verification enrollment through a client setting when deploying Okta Verify for macOS. This provides greater flexibility by allowing client-level settings to take precedence over org-wide configurations. See OktaVerify.UserVerificationEnrollment.

Enhanced security for osquery binary

The osqueryd binary now requires root-level permissions for execution. This enhancement provides OS-level enforcement to ensure that only authorized root users can run the binary, improving overall system security.

UserPrincipalName now available for macOS sign-in flows

Okta Verify for macOS now honors the OktaVerify.UserPrincipalName configuration to populate user names during enrollment. This enhancement simplifies the enrollment experience by automatically filling in the user identity based on the device configuration. See Okta Verify configurations for macOS devices.

Fixes

  • When user verification was set to Preferred, the Platform SSO enrollment flow failed to automatically enroll user verification keys for device passcodes. (OKTA-1131919)

  • The Okta Verify sign-in prompt displayed the enrollment URL instead of the authentication challenge URL during Okta FastPass sign-in prompts. (OKTA-1053919)

  • Okta Verify for macOS didn't immediately reflect enrollment resets performed through end-user settings or the Admin Console. The app now updates the enrollment state when the page loads so users don't have to wait for the change to appear. (OKTA-1119789)

  • This release also includes internal improvements and fixes.

Version: 9.59.0

Production deployment: March 19, 2026

Release summary

  • This release includes usability improvements and internal fixes.

Version: 9.57.3

Production deployment: March 6, 2026

Release summary

Osquery schema update

The binary used to validate osquery schema checks for macOS has been updated to 5.18.1. No additional action is required to use the new schema.

Fixes

  • The Platform SSO registration window sometimes didn't appear in the foreground, preventing users from completing the registration process. (OKTA-1109032)

  • After a new installation of Okta Verify, Desktop MFA failed to trigger on some devices. (OKTA-1125725)

  • This release also includes internal improvements and fixes.

  • The 9.57.3 release is only available as a download from the Okta Admin Console.

Version: 9.57.2

Production deployment: February 26, 2026

Release summary

Osquery schema update

The binary used to validate osquery schema checks for macOS has been updated to 5.18.1. No additional action is required to use the new schema.

Fixes

  • The Platform SSO registration window sometimes didn't appear in the foreground, preventing users from completing the registration process. (OKTA-1109032)

  • This release also includes internal improvements and fixes.

Version: 9.56.1

Production deployment: February 2, 2026

Release summary

Device-Bound Single Sign-On in Early Access

Device-Bound SSO initiates a hardware-protected session for seamless access to apps after users sign in to Okta-joined macOS and Windows devices. This self-service Early Access feature provides session replay protection and a streamlined authentication experience. See Device-Bound Single Sign-On.

This feature isn't supported by Okta Verify clients downloaded from the Apple App Store.

Fixes

  • The copyright date now displays 2026.

  • Some Okta Verify screens didn't update their colors automatically when users switched between light and dark modes. (OKTA-1038205)

  • This release also includes internal improvements and fixes.

Version: 9.55.0

Production deployment: January 7, 2026

Release summary

  • This release includes usability improvements and internal fixes.

  • The 9.55.0 release is only available as a download from the Okta Admin Console.

Version: 9.54.1

Production deployment: December 2, 2025

Release summary

  • Admins can use the new OktaVerify.OSQueryCustomChecksTimeout MDM parameter to customize the default osquery timeout value. This gives orgs the flexibility to fine-tune device posture checks and improve performance in diverse network environments. See Okta Verify configurations for macOS devices.

  • Users can now reset Okta Verify on macOS if the app fails to load. This option deletes all Okta Verify accounts on the device and restores the app to a clean state. See Reset Okta Verify on macOS.

  • This release also includes internal improvements and fixes.

  • The 9.54.1 release is only available as a download from the Okta Admin Console.

Version: 9.52.0

Production deployment: October 21, 2025

Release summary

  • Starting with this release, macOS 13 Ventura is no longer supported.

  • Desktop Password Sync now supports a simplified setup of Apple's Platform Single Sign-on (Platform SSO) during the Automated Device Enrollment process on macOS 26 Tahoe. See Platform SSO for macOS.

  • The OSQueryService binary file used in the advanced posture validation check has been renamed to OktaAuthenticationService. If you have the OSQueryService.xpc file in any automated scripts, update the command with the new name: OktaAuthenticationService.xpc.

    See Configure advanced posture checks for device assurance.

  • This release also includes internal improvements and fixes.

Version: 9.50.0

Production deployment: September 18, 2025

Release summary

  • This release includes internal improvements and fixes.

Version: 9.48.0

Production deployment: August 14, 2025

Release summary

  • This release includes internal improvements and fixes.

Version: 9.46.1

Production deployment: July 21, 2025

Release summary

  • This release includes internal improvements and fixes.

Version: 9.44.0

Production deployment: June 23, 2025

Release summary

  • This release includes internal improvements and fixes.

Version: 9.42.0

Production deployment: May 14, 2025

Release summary

  • This release includes internal improvements and fixes.

Release notes retention policy

Okta maintains release notes online for a period of 12 months following a release.

Contact Okta Support to request archived documentation for releases outside this window.