Okta Verify on shared devices and VDI environments

Okta Verify supports up to five concurrent users on shared workstations and virtual desktop infrastructure (VDI) environments when each user has an individual operating system (OS) account.

Okta Verify supports multiple user enrollments on a single device. Before you deploy Okta Verify to a device that more than one person uses, determine which of the following configurations applies.

Shared workstations

Okta Verify supports up to five concurrent users on a single device, provided each user has an individual operating system account. This limit exists because Okta FastPass relies on a loopback port for local authentication, and each device has a limited number of loopback ports available.

Okta FastPass enrollment doesn't support a single OS profile shared by multiple users. To register and monitor devices that use a shared OS profile, see Kiosk devices.

Kiosk devices

A kiosk device is a shared computer that many different users access through a single OS account, rather than through individual OS accounts. Examples include retail point-of-sale terminals, hospital workstations, and shared lab or classroom computers. As these devices don't provide an individual OS account per user, they don't meet the shared workstation requirements for individual user Okta FastPass enrollments.

On macOS and Windows, Device Posture Sensor Mode lets you register and monitor kiosk devices without needing to support individual user enrollments. Instead of enrolling in Okta Verify, admins can use a device-level certificate deployed through an MDM solution to register the device with Okta. Okta can then evaluate the device's security posture and enforce Device Assurance policies during authentication, regardless of whether any individual user has enrolled in Okta FastPass on that device. See Get started.

Virtual desktop infrastructure environments

The same five-concurrent-user limit applies in VDI environments. Roaming profiles and layered image configurations can introduce other restrictions.

For Windows VDI configuration options, see Configure Okta Verify for physical or virtual Windows environments.