Create and enforce the registered device policy
Enforce the registered condition and the Device Assurance policy during the sign-in flow with multiple users.
-
Create a Device Assurance policy for macOS or Windows:
- In the Admin Console, go to Security > Device Assurance Policies.
- Select Add a policy.
- Create a macOS or Windows policy with conditions that your devices pass.
-
Create an app sign-in policy that contains a registered condition requirement.
- In the Admin Console, go to Security > Authentication Policies > App sign-in.
- Select Create policy.
- Set the catch-all policy to Denied.
-
Add a rule with the following conditions:
- IF
- Device state is Registered
- Device management is Managed
- Device assurance policy is the policy created in the previous step.
- THEN
- Access is allowed after successful authentication
- User must authenticate with any enrolled authenticator that isn't FastPass
-
Sign in to the app where the authentication policy is assigned.
- Assign the app sign-in policy to the Okta End-User Dashboard app.
- To test the access for a test user, access the Okta End-User Dashboard.
Confirm that you can access the Okta End-User Dashboard without error. -
As a different test user, sign in to the app where the authentication policy is assigned.
- On the same device, switch to a different user account.
- Access the Okta End-User Dashboard app as the different user.
Confirm that you can access the Okta End-User Dashboard without error.