Flexible Okta Verify authenticator configuration
The Flexible Okta Verify authenticator configuration separates the bundled Okta Verify methods into distinct authenticators that you can configure, assign, and manage independently.
Early Access release. See Enable self-service features.
The Okta Verify authenticator supports the following authentication methods:
- Okta FastPass (phishing-resistant, device-bound)
- Push notification
- Time-based one-time passcode (TOTP)
Previously, these methods were bundled as a single authenticator, and you couldn't assign them independently to different groups of users.
By enabling this feature, you can replace the bundled Okta Verify authenticator with separately configurable
authenticators:
- Okta Verify - Okta FastPass
- Okta Verify - Push
- Okta Verify - TOTP
Before you begin
Before enabling this feature, review the following:
- Update all devices in your org to a supported version of Okta Verify (9.68.0 or later for iOS or 9.0.0 or later for Android).
- Unlike the bundled Okta Verify authenticator, TOTP is no longer enabled by default.
- Grace periods apply per authenticator enrollment policy, not per Okta Verify authenticator. Each separated authenticator supports a grace period. However, Okta enforces a single grace period policy across all Okta Verify authenticators within the same authenticator enrollment policy. You can't set different grace periods for individual authenticators inside a policy.
Enable Flexible Okta Verify authenticator configuration
CAUTION: Enable this feature during a maintenance window or other period of
low user activity. Because it permanently replaces the bundled Okta Verify authenticator configuration,
users who are actively authenticating may experience sign-in flow disruptions. If you enable this feature
and want to disable it later, you can't do so from the Features page. You must
contact Okta
Support for assistance.
To enable the Flexible Okta Verify authenticator configuration feature in the Admin Console, go to .
After you enable the feature, the bundled Okta Verify authenticator is no longer available and can't be reactivated, modified, or referenced in newly created policy rules after the replacement.