Flexible Okta Verify authenticator configuration

The flexible Okta Verify authenticator configuration separates the bundled Okta Verify methods into distinct authenticators that you can configure, assign, and manage independently.

Early Access release. See Enable self-service features.

The Okta Verify authenticator supports the following authentication methods:
  • Okta FastPass (phishing-resistant, device-bound)
  • Push notification
  • Time-based one-time passcode (TOTP)
Previously, these methods were bundled as a single authenticator, and you couldn't assign them independently to different groups of users. When you enable this feature, you replace the bundled Okta Verify authenticator with separately configurable authenticators:
  • Okta Verify - Okta FastPass
  • Okta Verify - Push
  • Okta Verify - TOTP
This allows you to assign and configure each authentication method independently for a user group.

Before you begin

Before you enable this feature, review the following:
  • Update all devices in your org to a supported version of Okta Verify (9.68.0 or later for iOS or 9.0.0 or later for Android).
  • Each of the three individual authenticators (Okta Verify - Okta FastPass, Okta Verify - Push, and Okta Verify - TOTP) has a grace period setting. However, Okta enforces a single grace period across all Okta Verify authenticators within the same authenticator enrollment policy. You can't set different grace periods for individual authenticators inside the same policy.

Enable the flexible Okta Verify authenticator configuration

To enable the flexible Okta Verify authenticator configuration feature in the Admin Console, go to Settings > Features.

After you enable the feature, the bundled Okta Verify authenticator is no longer available and can't be reactivated, modified, or referenced in newly created policy rules after the replacement.

Okta Verify per-method authenticator settings

After you enable the flexible Okta Verify authenticator configuration, Okta Verify - TOTP, Okta Verify - Push, and Okta Verify - Okta FastPass each have their own settings, plus two settings shared across all three.

How existing authenticator enrollment policies are affected

When you enable the flexible Okta Verify authenticator configuration, the authentication policies with Okta Verify set to Optional or Disabled aren't affected.

The authentication policies with Okta Verify set to Required are automatically translated to the three new authenticators, as detailed in the following table:
Previous Okta Verify methods Current Okta Verify methods
Okta Verify - Okta FastPass Okta Verify - Push Okta Verify - TOTP
Okta FastPass, Push, and TOTP Required Optional Optional
Push and TOTP Disabled Required Optional
Okta FastPass and TOTP Required Disabled Optional
TOTP only Disabled Disabled Required

After you enable the flexible Okta Verify authenticator configuration, you can set each Okta Verify authenticator independently in your authenticator enrollment policy.

Recommended Okta Verify enrollment configurations

To encourage phishing-resistant authentication, Okta recommends setting Okta Verify - Okta FastPass to Required, configuring same-device enrollment, and setting Okta Verify - TOTP and Okta Verify - Push to Optional in your authenticator enrollment policy.

Setting Okta Verify - Push to Optional is recommended because Okta Verify on desktop doesn't support Push notifications, and so desktop users would need to enroll on a mobile device.

The following table shows the enrollment behavior based on how the authenticators are set:
Okta Verify - Okta FastPass Okta Verify - Push Okta Verify - TOTP Enrollment behavior
Required Optional or Disabled Optional Users enroll on a desktop or mobile device using same-device enrollment.
Required Required Optional or Required Users enroll on a mobile device.
Disabled Required Optional Users enroll on a mobile device. Same-device enrollment on desktop isn't available.
Disabled Disabled Required Users enroll on a mobile device. Same-device enrollment on desktop isn't available.

How Okta determines the enrollment flow

Okta determines the enrollment flow based on the following:

  • The Okta Verify authenticators (TOTP, Push, or Okta FastPass) that the end user is allowed to enroll in, based on their authenticator enrollment policy.
  • The device (desktop or mobile) that the user attempts to enroll from.
  • Whether Okta FastPass is the only required authenticator, which determines same-device enrollment.
Authenticators allowed by policy User's device Enrollment flow
Okta FastPass, and one of TOTP or Push, or both Desktop The user is prompted to enroll from a mobile device.

After Okta FastPass is enrolled, other allowed authenticators become optional.

Okta FastPass, and one of TOTP or Push, or both Mobile Same-device enrollment starts.

After Okta FastPass is enrolled, other allowed authenticators become optional.

Okta FastPass only Desktop or mobile Same-device enrollment starts, regardless of the device.

How Okta determines the user verification requirement

Each of the three authenticators can have their own Enrollment setting (Required or Preferred). Since the end user performs just one verification step for all their eligible authenticators, Okta consolidates these into a single user verification requirement:

  • Okta considers only the authenticators that are Active and not Disabled for that user under their authenticator enrollment policy.
  • Okta applies the strictest setting, for example, Required overrides Preferred.
The following table shows some examples:
Policy settings Enrollment requirement
  • Push and TOTP are set to Required.
  • Enrollment is set to Preferred.
  • Okta FastPass is Active but Disabled.
Preferred
  • Push and TOTP are set to Required.
  • Enrollment is set to Required.
  • Okta FastPass is Active but Disabled.
Required