Configure the NFC authenticator

Configure the Near Field Communication (NFC) authenticator to allow end users to sign in to managed devices by tapping an NFC-enabled badge and entering a PIN.

About this task

Early Access release. See Enable self-service features.

The NFC authenticator provides a fast, tap-and-go sign-in experience for frontline and deskless workers on managed devices. Instead of entering a username and password, an end user taps their NFC-enabled badge or sticker against a hardware reader. Okta Verify reads the badge's unique ID, and the Sign-In Widget prompts the user for their personal PIN.

Before you begin

  • Reinstall Okta Verify (an update alone isn't sufficient). Okta Verify for Windows version 7.0.1 or later must be reinstalled and configured with Device Posture Sensor Mode enabled on all target devices.
  • Ensure that the target device is marked as managed in Okta. To get a device to a managed state, see Configure management attestation for desktop devices.
  • On all target devices, set the Windows configuration flag AuthenticatorOperationMode to Shared. See Okta Verify configurations for Windows devices.
  • The NFC authenticator doesn't support Okta Org2Org integration. Okta Verify on a managed device can be registered only to a single Okta org for userless authentication.
  • The NFC authenticator doesn't support an embedded Sign-In Widget. NFC is available only with the Okta-hosted Sign-In Widget.
  • Review the supported NFC card types. See Supported NFC card types.
  • Enable the NFC authenticator feature from the Admin Console, Settings > Features.

Procedure

  1. In the Admin Console, go to Security > Authenticators.
  2. On the Setup tab, click Add Authenticator.
  3. Click Add on the NFC tile.
  4. On the General tab, configure the following settings to customize the end-user experience:
    • Sign in with NFC button: Select this checkbox to allow end users to authenticate with NFC from the Sign-In Widget.
    • PIN length: Set the number of digits required for the PIN.
  5. Create NFC authenticator groups. See Configure the NFC authenticator groups.
  6. Add the NFC authenticator to an enrollment policy. See Create an authenticator enrollment policy.
  7. Configure rules for the NFC authenticator that you added to an enrollment policy. See Configure rules for authenticator enrollment policies.