Device lifecycle

The lifecycle of a device refers to the possible states for a device within the context of Okta Verify. A device can be in one of the following states: active, suspended, or deactivated.

The image shows a device lifecycle flow chart.

Lifecycle states

You can change the lifecycle state of a device through the Okta Admin Console. The current state of a device affects the available options.

State Description

Active

From an Active device, a user can access protected resources if permitted by the app sign-in policies.

You can change an Active device to Suspended or Deactivated.

Suspended

Suspended is intended to be a temporary state. It's useful if you need to pause, and later resume, device access for users such as contractors or employees who take a leave of absence.

You can Unsuspend a Suspended device, which returns it to the Active state. Or you can Deactivate the device.

Deactivated

A device in the Deactivated state can't access any resources and can only be activated again or deleted.

When a device is deactivated, all active sessions using Okta Verify are terminated, and new sessions can't be established until the device is reactivated.

You can Activate a Deactivated device, which returns it to the Active state. Or you can click the trash icon to Delete the device.

Device state buttons

You can find the state change buttons on the Devices page or on the Device Attributes page of the device. The buttons shown depend on the current device state.

Button

Description

Activate

When a device is activated, all Okta Verify factors associated with the device are supported. Also, users can access protected resources from the device, if permitted by the app sign-in policies applied to the resources.

Only Deactivated devices can be activated.

Suspend

When a device is suspended:

  • All active sessions that were established on that device using Okta Verify are terminated.
  • Active sessions established without Okta Verify are unaffected until the session ends.
  • New sessions using Okta Verify can't be established.
  • Okta Verify authentication factors, for example, Okta FastPass, Okta FastPass with biometrics, temporary one-time passcode, and Push can't be used from the device. However, users can continue to use password, email, or WebAuthn authentication factors from the device.
  • Users can't add or remove accounts from Okta Verify on the device.
  • Device certificates are unaffected (applies to desktop devices).
  • The user trying to enroll in Okta Verify can't unsuspend the device.

Only Active devices can be suspended.

Unsuspend

When you Unsuspend a device:

  • The device becomes Active.
  • All Okta Verify factors associated with the device are unsuspended.
  • Users can access protected resources from the device, if permitted by the app sign-in policies applied to the resources.

Only Suspended devices can be unsuspended.

Deactivate

When a device is deactivated:

  • All active sessions that were established on that device using Okta Verify are terminated.
  • Active sessions established without Okta Verify are unaffected until the session ends.
  • New sessions using Okta Verify can't be established.
  • Okta Verify authentication factors, for example, Okta FastPass, Okta FastPass with biometrics, temporary one-time passcode, and Push can't be used from the device. However, users can continue to use password, email, or WebAuthn authentication factors from the device.
  • Users can't add or remove accounts from Okta Verify on the device.
  • Enrolled factors on the device are deactivated and users must re-enroll them when the device is activated.
  • Device certificates are revoked (applies to desktop devices).
  • If all the rules in an app sign-in policy protecting a resource do require registered devices, then a user on a deactivated device can't access that resource, regardless of which factors they have enrolled.

    If the policy includes rules that allow access from unregistered devices, an end user on a deactivated device might be able to access the resource, but not through Okta FastPass.

Only Active devices can be deactivated.

Delete

When a device is deleted:

  • It's deleted from the Universal Directory. A message appears asking you to confirm the delete decision.
  • It no longer appears in the Admin Console.
  • The device can appear again in the Devices page if a user uses it to add an account in Okta Verify.

Only Deactivated devices can be deleted.