Okta Verify - Push authenticator settings

Review the Okta Verify - Push authenticator settings to understand how different options affect the end-user experience.

Early Access release. See Enable self-service features.

Setting Details
Number challenge for Okta Verify Push notification Choose whether to include a number challenge with an Okta Verify Push notification.
  • Never: Users never receive a number challenge regardless of the risk level of the authentication attempt.
  • Only for high risk sign-in attempts: Users receive a number challenge only if the sign-in attempt is considered risky. Configure your sign-on policy rules. See About Okta Risk Scoring.
  • All push challenges: Users receive a number challenge with all Okta Verify push notifications regardless of risk level.

    The number challenge verifies that a sign-in attempt to an app protected by Okta came from the intended user and not from an unauthorized person. It presents a number in the Sign-In Widget and pushes a notification to Okta Verify on the user's mobile device. The user selects the number that matches what they see in the Sign-In Widget. If the selection is correct, the user can access the protected app.

    The number challenge helps prevent phishing attacks by ensuring that the user possesses both Okta Verify and the device that initiated the sign-in attempt.

Enrollment
  • Preferred: Allow users to enable device passcode or biometric confirmation during enrollment or later. They can enroll devices that don't support biometrics.
  • Required: Okta Verify prompts new users to set up a device passcode or biometrics when they enroll. If the device doesn't support biometrics, users can enable a device passcode instead. For enrolled users who skipped this step, Okta Verify prompts the user to enable a device passcode or biometrics the next time they attempt to sign in on the enrolled device. During authentication with Okta FastPass, users can confirm their identity with biometrics or a device passcode.
  • Required with biometrics only: Prompt new users to set up biometrics when they enroll in Okta Verify. If the device doesn't support biometrics, users can't enroll in or authenticate with Okta Verify. If enrolled users skip this step, Okta Verify prompts them to enable biometrics the next time they attempt to sign in on the enrolled device.