Flexible Okta Verify authenticator configuration
The flexible Okta Verify authenticator configuration separates the bundled Okta Verify methods into distinct authenticators that you can configure, assign, and manage independently.
Early Access release. See Enable self-service features.
- Okta FastPass (phishing-resistant, device-bound)
- Push notification
- Time-based one-time passcode (TOTP)
- Okta Verify - Okta FastPass
- Okta Verify - Push
- Okta Verify - TOTP
Before you begin
- Update all devices in your org to a supported version of Okta Verify (9.68.0 or later for iOS or 9.0.0 or later for Android).
- Each of the three individual authenticators (Okta Verify - Okta FastPass, Okta Verify - Push, and Okta Verify - TOTP) has a grace period setting. However, Okta enforces a single grace period across all Okta Verify authenticators within the same authenticator enrollment policy. You can't set different grace periods for individual authenticators inside the same policy.
Enable the flexible Okta Verify authenticator configuration
To enable the flexible Okta Verify authenticator configuration feature in the Admin Console, go to .
After you enable the feature, the bundled Okta Verify authenticator is no longer available and can't be reactivated, modified, or referenced in newly created policy rules after the replacement.
Okta Verify per-method authenticator settings
How existing authenticator enrollment policies are affected
When you enable the flexible Okta Verify authenticator configuration, the authentication policies with Okta Verify set to Optional or Disabled aren't affected.
| Previous Okta Verify methods | Current Okta Verify methods | ||
|---|---|---|---|
| Okta Verify - Okta FastPass | Okta Verify - Push | Okta Verify - TOTP | |
| Okta FastPass, Push, and TOTP | Required | Optional | Optional |
| Push and TOTP | Disabled | Required | Optional |
| Okta FastPass and TOTP | Required | Disabled | Optional |
| TOTP only | Disabled | Disabled | Required |
After you enable the flexible Okta Verify authenticator configuration, you can set each Okta Verify authenticator independently in your authenticator enrollment policy.
Recommended Okta Verify enrollment configurations
To encourage phishing-resistant authentication, Okta recommends setting Okta Verify - Okta FastPass to Required, configuring same-device enrollment, and setting Okta Verify - TOTP and Okta Verify - Push to Optional in your authenticator enrollment policy.
Setting Okta Verify - Push to Optional is recommended because Okta Verify on desktop doesn't support Push notifications, and so desktop users would need to enroll on a mobile device.
| Okta Verify - Okta FastPass | Okta Verify - Push | Okta Verify - TOTP | Enrollment behavior |
|---|---|---|---|
| Required | Optional or Disabled | Optional | Users enroll on a desktop or mobile device using same-device enrollment. |
| Required | Required | Optional or Required | Users enroll on a mobile device. |
| Disabled | Required | Optional | Users enroll on a mobile device. Same-device enrollment on desktop isn't available. |
| Disabled | Disabled | Required | Users enroll on a mobile device. Same-device enrollment on desktop isn't available. |
How Okta determines the enrollment flow
Okta determines the enrollment flow based on the following:
- The Okta Verify authenticators (TOTP, Push, or Okta FastPass) that the end user is allowed to enroll in, based on their authenticator enrollment policy.
- The device (desktop or mobile) that the user attempts to enroll from.
- Whether Okta FastPass is the only required authenticator, which determines same-device enrollment.
| Authenticators allowed by policy | User's device | Enrollment flow |
|---|---|---|
| Okta FastPass, and one of TOTP or Push, or both | Desktop | The user is prompted to enroll from a mobile device. After Okta FastPass is enrolled, other allowed authenticators become optional. |
| Okta FastPass, and one of TOTP or Push, or both | Mobile | Same-device enrollment starts. After Okta FastPass is enrolled, other allowed authenticators become optional. |
| Okta FastPass only | Desktop or mobile | Same-device enrollment starts, regardless of the device. |
How Okta determines the user verification requirement
Each of the three authenticators can have their own Enrollment setting (Required or Preferred). Since the end user performs just one verification step for all their eligible authenticators, Okta consolidates these into a single user verification requirement:
- Okta considers only the authenticators that are Active and not Disabled for that user under their authenticator enrollment policy.
- Okta applies the strictest setting, for example, Required overrides Preferred.
| Policy settings | Enrollment requirement |
|---|---|
|
Preferred |
|
Required |