View device details

There are two ways to find device details in the Admin Console:

  • Go to Directory > Devices, and then click the device name.
  • Go to Directory > People, and then click the user's name. On the Devices tab, select the Device name.

Device Visibility

Early Access release

When you enable the Device Visibility feature, the device detail pages for macOS and Windows use a four-tab layout: Accounts, Configurations, Signals, and Identifiers.

If you don't have the Device Visibility feature enabled, then macOS and Windows devices show the standard single-page view.

iOS and Android devices always use the standard single-page view, regardless of whether the Device Visibility feature is enabled.

Device Visibility: macOS and Windows

The main header for this page shows the Device display name and the device's operating system (OS). Also shown are the device's current state and the action buttons to change the device state.

You can click View logs to open the System Log filtered to show only the events for this device.

Accounts tab

The Accounts tab shows the OS user accounts and Okta user enrollments on the device. Accounts are organized into two sections:

  • Users with a known OS account: These are the OS-level user accounts detected on the device.

    On macOS, all detected OS accounts appear here if they are enrolled in Okta Device Access (either through PSSO 1.0, PSSO 2.0, or Desktop MFA).

    However, for accounts without a PSSO 2.0 enrollment, the Okta user column shows a dash and there is no PSSO card, even if the account is enrolled through PSSO 1.0 or Desktop MFA.

  • Users without a known OS account: These are Okta FastPass and Okta Desktop MFA enrollments on the device that aren't linked with a detected OS account.

    On Windows devices, all enrolled users appear in this section because OS account detection isn't available for Windows.

Each row in the Accounts table shows the following:

Column Description
Operating system user The name of the OS user account as it appears on the device.
Okta user The Okta user linked to this OS account through Platform SSO 2.0.

If the OS account has no PSSO 2.0 enrollment, this column shows a dash.

Management Managed or Not managed. This indicates whether a device management solution manages the user profile associated with this device enrollment.
Last seen The date when Okta last received OS account data from this device.

The table is sorted by this column by default.

Recovery PIN For managed accounts, you can click this to generate a recovery PIN for Okta Device Access.

Select a row to view the following account details and authenticator enrollment cards.

Detail Description
Account universally unique identifier (UUID) The unique identifier for this OS account on this device (macOS).

This value is specific to the account-device combination and differs from the Okta Device ID.

Security Identifier (SID) The unique identifier for this OS account on this device (Windows).
Lock screen The method that the user most recently used to unlock this device.

On macOS, possible values include Password with Touch ID. On Windows, possible values include Password with Windows Hello.

Platform SSO enrollment card

If the OS account has a Platform SSO (PSSO) 2.0 enrollment, a PSSO card appears in the expanded row. PSSO 1.0 enrollments aren't shown.

Field Description
Authenticated on The date and time of the most recent PSSO authentication for this account.
Enrolled on The date and time the PSSO enrollment was created.
Authentication method The authentication method configured for this PSSO enrollment.

For example, Password or Secure Enclave.

Linked Okta user The Okta user associated with this PSSO enrollment. Selecting the value opens the user profile in the Admin Console.

Okta FastPass enrollment card

If an OS account row has a linked Okta user, an Okta FastPass enrollment card appears for each Okta FastPass enrollment associated with that user on this device.

Field Description
User The Okta user's name and email address.
Enrollment date The date the Okta Verify enrollment was created on this device for this user.
Management status Indicates whether a device management solution manages the user profile associated with this device enrollment.
  • Managed: A device management solution manages the user profile, and the device is configured for device management in Security > Device Integrations.

  • Not managed: A device management solution doesn't manage the user profile, or the device isn't configured for device management.

Configurations tab

The Configurations tab shows the Okta Verify installation details reported from this device. Each installed component appears as a separate card.

Card Description
Version The version of Okta Verify installed on the device.

Select Download latest version to open the download page.

Okta Verify authenticator Indicates that the Okta Verify authenticator is installed.

Select Authenticator settings to open the authenticator configuration in the Admin Console.

Signals tab

The Signals tab shows the device security attributes that Okta Verify collects. Some signals are platform-specific and appear only for the relevant OS.

Signal Platform Description
OS version macOS, Windows

The operating system version installed on the device.

Disk encryption macOS, Windows

Indicates whether the device storage is encrypted.

  • On macOS, this reflects FileVault status.
  • On Windows, this reflects BitLocker status.

The device is marked as encrypted only when encryption is active and enabled on the system volume.

For example: All internal volumes encrypted.

Secure Enclave macOS

Indicates whether the device has a Secure Enclave processor.

For example: Supported.

Trusted Platform Module Windows

Indicates whether a Trusted Platform Module (TPM) is present and in use on the device.

For example: In use.

Identifiers tab

The Identifiers tab shows hardware and platform identifiers for the device.

Identifier Platform Description
Okta Device ID macOS, Windows The unique identifier assigned to this device by Okta.
Display name macOS, Windows The display name of the device.
Manufacturer macOS, Windows The vendor that created the physical device.
Model macOS, Windows The device type or design.
Serial number macOS, Windows The hardware serial number of the device.
Hardware Universally Unique Identifier (UUID) macOS, Windows The hardware-level unique identifier for the device.

This field was previously named the device UDID.

Security Identifier (SID) Windows The Security Identifier (SID) is a unique number for a user, user group, or other security principal.

For example: S-1-83625951649466-0.

Dedicated hardware Windows The TPM public key hash for the device's Trusted Platform Module.

Device details: standard view

The following sections describe the device detail page for:

  • iOS and Android devices (all releases)
  • macOS and Windows devices when Device Visibility isn't enabled

Device users

A user profile represents an identity that uses an enrolled device to sign in to your org. A user can have more than one profile on a device. For example, a single user can have a business profile to access restricted company apps, and a personal profile to access personal files. A single device can also have more than one user who signs in using the same device. The device details page displays a maximum of 20 users associated with the device, even though there may be more than 20 users assigned to the device.

Details by device user Description
User A user's name and email address.

For example, Cristina Young c.young@example.com.

Enrollment date Date that the device was enrolled in Okta Verify.
Management status
  • Managed: the device is registered, a device management solution manages the user profile, the device is configured for device management in Security > Device Integrations, and the user authenticated with Okta FastPass from the managed device.
  • Not managed: the device is registered but either a device management solution doesn't manage the user profile, or the device isn't configured for device management.
Lock screen Indicates whether the user unlocked the lock screen with Password, Password with Windows Hello, or if it's Disabled.

Device security signals

Device security signal Description
OS version The OS version installed on the device.

For example, 13.5.1

Disk encryption Indicates whether the device storage is encrypted.

On macOS, this reflects FileVault status. On Windows, this reflects BitLocker status.

The device is marked as encrypted only if encryption is active and enabled on the system volume.

For example, Fully encrypted.

Secure Enclave Indicates whether the iOS or macOS device supports Secure Enclave.
Jailbreak Indicates whether the iOS device is jailbroken.
Hardware Keystore Indicates whether the Android device supports a hardware keystore.
Rooting Indicates whether the Android device is rooted.
Trusted Platform Module Indicates whether the Windows Trusted Platform Module is in use.

Device identifier

Device identifier Description
Display name The display name of the device.

For example, Maya's iPhone.

Platform The operating system of the device.
Manufacturer The vendor that created the physical device.

For example, APPLE.

Model The device type or design.

For example, iPhone.

OS Version The operating system software version of the device.
IMEI International Mobile Equipment Identity (IMEI) is a unique number for identifying a mobile device on a Global System for Mobile communication (GSM) network.

Okta Verify doesn't collect this information, but a custom app can collect it.

MEID Mobile Equipment Identifier (MEID) is a unique number for identifying a mobile device on a network that uses Code-Division Multiple Access (CDMA) protocols for second-generation and third-generation wireless communication.

Okta Verify doesn't collect this information, but a custom app can collect it.

UDID The unique device ID (UDID) that is used to identify Apple devices on an iOS or macOS platform.
Security Identifier The Security Identifier (SID) is a unique number for the user, user group, or other security principal.
Dedicated hardware Indicates if dedicated hardware exists for a Trusted Platform Module (TPM).

The unique identifier hash isn't shown for devices with a TPM. Instead, the placeholder Present - No hash available appears.