Flexible Okta Verify authenticator configuration - General settings

Review the general settings that are common to all Flexible Okta Verify authenticators.

Early Access release. See Enable self-service features.

To edit these settings in the Admin Console, go to Security > Authenticators. On the Setup tab, locate the Okta Verify authenticator and click Actions > Edit.
Setting Details
Enrollment channels
  • Higher security channels: Users can enroll with the following methods only:
    • Same device: Users start and complete the Okta Verify enrollment within the app by providing the org sign-in URL.
    • Device-to-device bootstrap: Users can add an existing Okta Verify account to another mobile or desktop device by using Bluetooth.
  • Any channels: In addition to Same device and Device-to-device bootstrap, users can also enroll with one of the following methods to enroll Okta Verify on a mobile device:
    • QR code in browser: Users scan a QR code in the browser.
    • SMS or email link: Users click a link sent to them through SMS or email.
FIPS compliance Restrict Okta Verify enrollment to FIPS-compliant Android and iOS devices by allowing users to enroll with:
  • FIPS-compliant devices only: Users can enroll only a FIPS-compliant device in Okta Verify.

    Okta Verify uses FIPS 140-2 validation for all security operations and meets FedRAMP FICAM requirements by relying on FIPS-validated vendors.

  • Any device: Users can enroll any device in Okta Verify.