Flexible Okta Verify authenticator configuration

The Flexible Okta Verify authenticator configuration separates the bundled Okta Verify methods into distinct authenticators that you can configure, assign, and manage independently.

Early Access release. See Enable self-service features.

The Okta Verify authenticator supports the following authentication methods:
  • Okta FastPass (phishing-resistant, device-bound)
  • Push notification
  • Time-based one-time passcode (TOTP)

Previously, these methods were bundled as a single authenticator, and you couldn't assign them independently to different groups of users.

By enabling this feature, you can replace the bundled Okta Verify authenticator with separately configurable authenticators:
  • Okta Verify - Okta FastPass
  • Okta Verify - Push
  • Okta Verify - TOTP
This allows you to assign and configure each authentication method independently per user group.

Before you begin

Before enabling this feature, review the following:
  • Update all devices in your org to a supported version of Okta Verify (9.68.0 or later for iOS or 9.0.0 or later for Android).
  • Unlike the bundled Okta Verify authenticator, TOTP is no longer enabled by default.
  • Grace periods apply per authenticator enrollment policy, not per Okta Verify authenticator. Each separated authenticator supports a grace period. However, Okta enforces a single grace period policy across all Okta Verify authenticators within the same authenticator enrollment policy. You can't set different grace periods for individual authenticators inside a policy.

Enable Flexible Okta Verify authenticator configuration

To enable the Flexible Okta Verify authenticator configuration feature in the Admin Console, go to Settings > Features.

After you enable the feature, the bundled Okta Verify authenticator is no longer available and can't be reactivated, modified, or referenced in newly created policy rules after the replacement.