Enforce number challenge for Desktop MFA for macOS

When Desktop MFA users sign in to their computers, they receive a number challenge with every push notification.

This provides enhanced security for your org by ensuring that users can only verify their identity when they have access to their mobile device and computer.

  • The Desktop MFA number challenge applies only to users who have Desktop MFA. They receive the number challenge in push notifications when they sign in to their computers.

  • The Okta Verify number challenge applies to all org users who authenticate using Okta Verify Push to access their apps. See Configure Okta Verify options.

Procedure

To enable the number challenge for Desktop MFA, follow these steps:

  1. In the Admin Console, go to SecurityGeneral.

  2. Locate the Okta Device Access section.
  3. Click Edit.
  4. Set the Enforce number matching challenge for Desktop MFA option to Enabled.
  5. Click Save.

To disable the number challenge for Desktop MFA, follow the same procedure, but set the Enforce number matching challenge for Desktop MFA option to Disabled.

Next steps

Optional. Configure Desktop MFA for macOS to use FIDO2 keys