View device details
There are two ways to find device details in the Admin Console:
- Go to , and then click the device name.
- Go to , and then click the user's name. On the Devices tab, select the Device name.
Device Visibility
Early Access release
When you enable the Device Visibility feature, the device detail pages for macOS and Windows use a four-tab layout: Accounts, Configurations, Signals, and Identifiers.
If you don't have the Device Visibility feature enabled, then macOS and Windows devices show the standard single-page view.
iOS and Android devices always use the standard single-page view, regardless of whether the Device Visibility feature is enabled.
Device Visibility: macOS and Windows
The main header for this page shows the Device display name and the device's operating system (OS). Also shown are the device's current state and the action buttons to change the device state.
You can click View logs to open the System Log filtered to show only the events for this device.
Accounts tab
The Accounts tab shows the OS user accounts and Okta user enrollments on the device. Accounts are organized into two sections:
-
Users with a known OS account: These are the OS-level user accounts detected on the device.
On macOS, all detected OS accounts appear here if they are enrolled in Okta Device Access (either through PSSO 1.0, PSSO 2.0, or Desktop MFA).
However, for accounts without a PSSO 2.0 enrollment, the Okta user column shows a dash and there is no PSSO card, even if the account is enrolled through PSSO 1.0 or Desktop MFA.
-
Users without a known OS account: These are Okta FastPass and Okta Desktop MFA enrollments on the device that aren't linked with a detected OS account.
On Windows devices, all enrolled users appear in this section because OS account detection isn't available for Windows.
Each row in the Accounts table shows the following:
| Column | Description |
|---|---|
| Operating system user | The name of the OS user account as it appears on the device. |
| Okta user | The Okta user linked to this OS account through Platform SSO 2.0.
If the OS account has no PSSO 2.0 enrollment, this column shows a dash. |
| Management | Managed or Not managed. This indicates whether a device management solution manages the user profile associated with this device enrollment. |
| Last seen | The date when Okta last received OS account data from this device.
The table is sorted by this column by default. |
| Recovery PIN | For managed accounts, you can click this to generate a recovery PIN for Okta Device Access. |
Select a row to view the following account details and authenticator enrollment cards.
| Detail | Description |
|---|---|
| Account universally unique identifier (UUID) | The unique identifier for this OS account on this device (macOS).
This value is specific to the account-device combination and differs from the Okta Device ID. |
| Security Identifier (SID) | The unique identifier for this OS account on this device (Windows). |
| Lock screen | The method that the user most recently used to unlock this device.
On macOS, possible values include Password with Touch ID. On Windows, possible values include Password with Windows Hello. |
Platform SSO enrollment card
If the OS account has a Platform SSO (PSSO) 2.0 enrollment, a PSSO card appears in the expanded row. PSSO 1.0 enrollments aren't shown.
| Field | Description |
|---|---|
| Authenticated on | The date and time of the most recent PSSO authentication for this account. |
| Enrolled on | The date and time the PSSO enrollment was created. |
| Authentication method | The authentication method configured for this PSSO enrollment.
For example, Password or Secure Enclave. |
| Linked Okta user | The Okta user associated with this PSSO enrollment. Selecting the value opens the user profile in the Admin Console. |
Okta FastPass enrollment card
If an OS account row has a linked Okta user, an Okta FastPass enrollment card appears for each Okta FastPass enrollment associated with that user on this device.
| Field | Description |
|---|---|
| User | The Okta user's name and email address. |
| Enrollment date | The date the Okta Verify enrollment was created on this device for this user. |
| Management status | Indicates whether a device management solution manages the user profile associated with this device enrollment.
|
Configurations tab
The Configurations tab shows the Okta Verify installation details reported from this device. Each installed component appears as a separate card.
If Okta Verify hasn't reported data for this device, an informational notice appears in place of the configuration cards. Okta Verify sends signal data approximately every three hours after Device Visibility is enabled.
| Card | Description |
|---|---|
| Version | The version of Okta Verify installed on the device.
Select Download latest version to open the download page. |
| Okta Verify authenticator | Indicates that the Okta Verify authenticator is installed.
Select Authenticator settings to open the authenticator configuration in the Admin Console. |
Signals tab
The Signals tab shows the device security attributes that Okta Verify collects. Some signals are platform-specific and appear only for the relevant OS.
| Signal | Platform | Description |
|---|---|---|
| OS version | macOS, Windows |
The operating system version installed on the device. |
| Disk encryption | macOS, Windows |
Indicates whether the device storage is encrypted.
The device is marked as encrypted only when encryption is active and enabled on the system volume. For example: All internal volumes encrypted. |
| Secure Enclave | macOS |
Indicates whether the device has a Secure Enclave processor. For example: Supported. |
| Trusted Platform Module | Windows |
Indicates whether a Trusted Platform Module (TPM) is present and in use on the device. For example: In use. |
Identifiers tab
The Identifiers tab shows hardware and platform identifiers for the device.
The Hardware Universally Unique Identifier (UUID) field replaces the UDID (Unique Device Identifier) field from earlier Admin Console versions. Devices registered before this change may still display UDID.
| Identifier | Platform | Description |
|---|---|---|
| Okta Device ID | macOS, Windows | The unique identifier assigned to this device by Okta. |
| Display name | macOS, Windows | The display name of the device. |
| Manufacturer | macOS, Windows | The vendor that created the physical device. |
| Model | macOS, Windows | The device type or design. |
| Serial number | macOS, Windows | The hardware serial number of the device. |
| Hardware Universally Unique Identifier (UUID) | macOS, Windows | The hardware-level unique identifier for the device.
This field was previously named the device UDID. |
| Security Identifier (SID) | Windows | The Security Identifier (SID) is a unique number for a user, user group, or other security principal.
For example: S-1-83625951649466-0. |
| Dedicated hardware | Windows | The TPM public key hash for the device's Trusted Platform Module. |
Device details: standard view
The following sections describe the device detail page for:
- iOS and Android devices (all releases)
- macOS and Windows devices when Device Visibility isn't enabled
Device users
A user profile represents an identity that uses an enrolled device to sign in to your org. A user can have more than one profile on a device. For example, a single user can have a business profile to access restricted company apps, and a personal profile to access personal files. A single device can also have more than one user who signs in using the same device. The device details page displays a maximum of 20 users associated with the device, even though there may be more than 20 users assigned to the device.
| Details by device user | Description |
|---|---|
| User | A user's name and email address.
For example, Cristina Young c.young@example.com. |
| Enrollment date | Date that the device was enrolled in Okta Verify. |
| Management status |
|
| Lock screen | Indicates whether the user unlocked the lock screen with Password, Password with Windows Hello, or if it's Disabled. |
Device security signals
| Device security signal | Description |
|---|---|
| OS version | The OS version installed on the device. For example, 13.5.1 |
| Disk encryption | Indicates whether the device storage is encrypted.
On macOS, this reflects FileVault status. On Windows, this reflects BitLocker status. The device is marked as encrypted only if encryption is active and enabled on the system volume. For example, Fully encrypted. |
| Secure Enclave | Indicates whether the iOS or macOS device supports Secure Enclave. |
| Jailbreak | Indicates whether the iOS device is jailbroken. |
| Hardware Keystore | Indicates whether the Android device supports a hardware keystore. |
| Rooting | Indicates whether the Android device is rooted. |
| Trusted Platform Module | Indicates whether the Windows Trusted Platform Module is in use. |
Device identifier
| Device identifier | Description |
|---|---|
| Display name | The display name of the device.
For example, Maya's iPhone. |
| Platform | The operating system of the device. |
| Manufacturer | The vendor that created the physical device. For example, APPLE. |
| Model | The device type or design. For example, iPhone. |
| OS Version | The operating system software version of the device. |
| IMEI | International Mobile Equipment Identity (IMEI) is a unique number for identifying a mobile device on a Global System for Mobile communication (GSM) network.
Okta Verify doesn't collect this information, but a custom app can collect it. |
| MEID | Mobile Equipment Identifier (MEID) is a unique number for identifying a mobile device on a network that uses Code-Division Multiple Access (CDMA) protocols for second-generation and third-generation wireless communication.
Okta Verify doesn't collect this information, but a custom app can collect it. |
| UDID | The unique device ID (UDID) that is used to identify Apple devices on an iOS or macOS platform. |
| Security Identifier | The Security Identifier (SID) is a unique number for the user, user group, or other security principal. |
| Dedicated hardware | Indicates if dedicated hardware exists for a Trusted Platform Module (TPM).
The unique identifier hash isn't shown for devices with a TPM. Instead, the placeholder Present - No hash available appears. |