Review the Okta Verify - Push authenticator settings to understand how different options affect the
end-user experience.
Early Access release. See Enable self-service features.
| Setting |
Details |
| Number challenge for Okta Verify Push notification |
Choose whether to include a number challenge with an Okta Verify Push notification.
- Never: Users never receive a number challenge regardless of the risk
level of the authentication attempt.
- Only for high risk sign-in attempts: Users receive a number challenge
only if the sign-in attempt is considered risky. Configure your sign-on policy rules.
See About Okta Risk Scoring.
- All push challenges: Users receive a number challenge with all Okta
Verify push notifications regardless of risk level.
The number challenge verifies that a
sign-in attempt to an app protected by Okta came from the intended user and not from an
unauthorized person. It presents a number in the Sign-In Widget and pushes a notification
to Okta Verify on the user's mobile device. The user selects the number that matches what
they see in the Sign-In Widget. If the selection is correct, the user can access the
protected app. The number challenge helps prevent phishing attacks by ensuring that
the user possesses both Okta Verify and the device that initiated the sign-in
attempt.
|
| Enrollment |
- Preferred: Allow users to enable device passcode or biometric
confirmation during enrollment or later. They can enroll devices that don't support
biometrics.
- Required: Okta Verify prompts new users to set up a device passcode
or biometrics when they enroll. If the device doesn't support biometrics, users can enable a
device passcode instead. For enrolled users who skipped this step, Okta Verify prompts the
user to enable a device passcode or biometrics the next time they attempt to sign in on the
enrolled device. During authentication with Okta FastPass, users can confirm their identity
with biometrics or a device passcode.
- Required with biometrics only: Prompt new users to set up biometrics
when they enroll in Okta Verify. If the device doesn't support biometrics, users can't enroll
in or authenticate with Okta Verify. If enrolled users skip this step, Okta Verify prompts
them to enable biometrics the next time they attempt to sign in on the enrolled device.
|