Okta Verify - TOTP authenticator settings

Review the Okta Verify - TOTP authenticator settings to understand how different options affect the end-user experience.

Early Access release. See Enable self-service features.

Setting Details
Enrollment
  • Preferred: Allow users to enable device passcode or biometric confirmation during enrollment or later. They can enroll devices that don't support biometrics.
  • Required: Okta Verify prompts new users to set up a device passcode or biometrics when they enroll. If the device doesn't support biometrics, users can enable a device passcode instead. For enrolled users who skipped this step, Okta Verify prompts the user to enable a device passcode or biometrics the next time they attempt to sign in on the enrolled device. During authentication with Okta FastPass, users can confirm their identity with biometrics or a device passcode.
  • Required with biometrics only: Prompt new users to set up biometrics when they enroll in Okta Verify. If the device doesn't support biometrics, users can't enroll in or authenticate with Okta Verify. If enrolled users skip this step, Okta Verify prompts them to enable biometrics the next time they attempt to sign in on the enrolled device.