Assign users/groups to the Microsoft RDP (MFA) app

You must assign the Microsoft RDP (MFA) app to all users who log in to machines that have the Credential Provider installed. By default, the App Sign-On policy for this app prompts for MFA every login.

  1. In the Admin Console, go to ApplicationsApplications.
  2. Locate the Microsoft RDP (MFA) app.
  3. Click the app name.
  4. Select the Sign On tab.
  5. In the Settings section, select Edit.
  6. Select the Application username format to assign to users of this app. The default is Okta username.

    The username that you enter must match the format that you selected in the preceding step. Suppose a user's full UPN is in the format name@yourorg.com. If you're using the AD SAM account name as the Application username format, enter only the name portion of the UPN for the username. The AD SAM account name includes the @yourorg.com portion of the UPN.

  7. Click Save.
  8. Select the Assignments tab.
  9. Assign people or groups to the app. To assign the app to users:
    1. Select AssignAssign to People.
    2. Click Assign beside a user to assign to the app.
    3. Click Save and Go back.
    4. Repeat the previous two steps to add other users to the app.
    5. Click Done.
    Okta recommends assigning applications to groups rather than individual users for ease of management. To assign the app to groups:
    1. Click Assign and select Assign to Groups.
    2. Click Assign beside each group to which to assign the app.
    3. Click Done.

  10. Select the Sign On tab to configure sign on rules for this app.
  11. Scroll to the Sign On Policy section.
  12. The default setting for User assigned this policy for this app is Require Multifactor every sign on. Create another sign on rule if you don't want to prompt some or all of your users for MFA. Assign users to the new rule and clear the Prompt for factor checkbox. Click Save when finished. Your system configuration is complete.

    Okta sign on policy doesn't apply to Microsoft RDP (MFA). Okta only evaluates the app sign on policy defined in this step.