View device details
There are two ways to find device details in the Admin Console:
- Go to , and then click the device name.
- Go to , and then click the user's name. On the Devices tab, select the Device name.
Device Visibility
Early Access release
When you enable the Device Visibility feature, the device detail pages for macOS and Windows use a four-tab layout: Accounts, Configurations, Signals, and Identifiers.
If you don't have the Device Visibility feature enabled, then macOS and Windows devices show the standard single-page view.
iOS and Android devices always use the standard single-page view, regardless of whether the Device Visibility feature is enabled.
Device Visibility: macOS and Windows
The main header for this page shows the Device display name and the device's operating system (OS). Also shown are the device's current state and the action buttons to change the device state.
You can click View logs to open the System Log filtered to show only the events for this device.
Accounts tab
The Accounts tab shows the OS user accounts and Okta user enrollments on the device. Accounts are organized into two sections:
Users with a known OS account
These are the OS-level user accounts detected on the device.
For account and Platform SSO (PSSO) information to appear here, macOS devices must be using the Okta Verify app, version 9.69 or later.
On macOS, all detected OS accounts appear here if they are enrolled in Okta Device Access.
This enrollment can be through PSSO 1.0, PSSO 2.0, or Desktop MFA.
However, for accounts without a PSSO 2.0 enrollment, the Okta user column shows a dash and no PSSO card is shown, even if the account is enrolled through PSSO 1.0 or Desktop MFA. Instead the account appears in the Okta Verify accounts section.
Each row in the Accounts table shows the following:
| Column | Description |
|---|---|
| Operating system user | The name of the OS user account as it appears on the device. |
| Okta user | The Okta user linked to this OS account through Platform SSO 2.0. If the OS account has no PSSO 2.0 enrollment, this column shows a dash. |
| Management | Managed or Unmanaged. This indicates whether a device management solution manages the user profile associated with this device enrollment. |
| Last seen | The date when Okta last received OS account data from this device. The table is sorted by this column by default. |
Select a row to view the following account details and authenticator enrollment cards.
| Detail | Description |
|---|---|
| Account universally unique identifier (UUID) | The unique identifier for this OS account on this device (macOS). This value is specific to the account-device combination and differs from the Okta Device ID. |
| Lock screen | The method that the user most recently used to unlock this device. On macOS, possible values include Password with Touch ID. On Windows, possible values include Password with Windows Hello. |
Platform SSO enrollment card
If the OS account has a PSSO 2.0 enrollment, a PSSO card appears in the expanded row.
| Field | Description |
|---|---|
| Authenticated on | The date and time of the most recent PSSO authentication for this account. |
| Enrolled on | The date and time the PSSO enrollment was created. |
| Authentication method | The authentication method configured for this PSSO enrollment. For example, Password or Secure Enclave. |
| User | The Okta user associated with this PSSO enrollment. Select the user to open the user profile in the Admin Console. |
Okta FastPass enrollment card
If an OS account row has a linked Okta user, an Okta FastPass enrollment card appears for each Okta FastPass enrollment associated with that user on this device.
| Field | Description |
|---|---|
| Enrolled on | The date the Okta Verify enrollment was created on this device for this user. |
| User | The Okta user associated with this Okta FastPass enrollment. Select the user to open the user profile in the Admin Console. |
Users without a known OS account
These users have Okta FastPass and Okta Desktop MFA enrollments on the device that aren't linked with a detected OS account.
On Windows devices, all enrolled users appear in this section because OS account detection isn't available for Windows.
| Field | Description |
|---|---|
| Okta user | The Okta user linked to this account. |
| Enrolled on | The enrollment date for this user account on this device. |
| Management | Indicates whether a device management solution manages the user profile associated with this device enrollment.
|
| Lock screen | The method that the user most recently used to unlock this device. |
| Recovery PIN | For managed accounts, you can generate a recovery PIN for Okta Device Access. |
Configurations tab
The Configurations tab shows the Okta Verify installation details reported from this device. Each installed component appears as a separate card.
If Okta Verify hasn't reported data for this device, an informational notice appears in place of the configuration cards. Okta Verify sends signal data approximately every three hours after Device Visibility is enabled.
| Card | Description |
|---|---|
| Version | The version of Okta Verify installed on the device.
Select Download latest version to open the download page. |
| Okta Verify authenticator | Indicates that the Okta Verify authenticator is installed. Select Authenticator settings to open the authenticator configuration in the Admin Console. |
Signals tab
The Signals tab shows the device security attributes that Okta Verify collects. Some signals are platform-specific and appear only for the relevant OS.
| Signal | Platform | Description |
|---|---|---|
| OS version | macOS, Windows |
The operating system version installed on the device. |
| Disk encryption | macOS, Windows |
Indicates whether the device storage is encrypted.
The device is marked as encrypted only when encryption is active and enabled on the system volume. For example: All internal volumes encrypted. |
| Secure Enclave | macOS |
Indicates whether the device has a Secure Enclave processor. For example: Supported. |
| Trusted Platform Module | Windows |
Indicates whether a Trusted Platform Module (TPM) is present and in use on the device. For example: In use. |
Identifiers tab
The Identifiers tab shows hardware and platform identifiers for the device.
The Hardware Universally Unique Identifier (UUID) field replaces the UDID (Unique Device Identifier) field from earlier Admin Console versions. Devices registered before this change may still display UDID.
| Identifier | Platform | Description |
|---|---|---|
| Okta Device ID | macOS, Windows | The unique identifier assigned to this device by Okta. |
| Display name | macOS, Windows | The display name of the device. |
| Manufacturer | macOS, Windows | The vendor that created the physical device. |
| Model | macOS, Windows | The device type or design. |
| Serial number | macOS, Windows | The hardware serial number of the device. |
| Hardware Universally Unique Identifier (UUID) | macOS, Windows | The hardware-level unique identifier for the device.
This field was previously named the device UDID. |
| Security Identifier (SID) | Windows | The Security Identifier (SID) is a unique number for a user, user group, or other security principal.
For example: S-1-83625951649466-0. |
| Dedicated hardware | Windows | The TPM public key hash for the device's Trusted Platform Module. |
Device details: standard view
The following sections describe the device details page for:
- iOS and Android devices
- macOS and Windows devices when Device Visibility isn't enabled
Device users
A user profile represents an identity that uses an enrolled device to sign in to your org. A user can have more than one profile on a device. For example, a single user can have a business profile to access restricted company apps, and a personal profile to access personal files.
A single device can also have more than one user who signs in using the same device. The device details page displays a maximum of 20 users associated with the device, even though there may be more than 20 users assigned to the device.
| Details by device user | Description |
|---|---|
| User | The user's name and email address. For example, Cristina Young c.young@example.com. |
| Enrollment date | Date that the device was enrolled in Okta Verify. |
| Management status |
|
| Lock screen | Indicates whether the user unlocked the lock screen with Password, Password with Windows Hello, or if it's Disabled. |
| Device recovery | Select View recovery PIN to view the existing recovery PIN or to generate a new PIN for Okta Device Access. |
Device security signals
| Device security signal | Description |
|---|---|
| OS version | The OS version installed on the device. For example, 13.5.1 |
| Disk encryption | Indicates whether the device storage is encrypted. On macOS, this reflects FileVault status. On Windows, this reflects BitLocker status. The device is marked as encrypted only if encryption is active and enabled on the system volume. For example, Fully encrypted. |
| Secure Enclave | Indicates whether the iOS or macOS device supports Secure Enclave. |
| Jailbreak | Indicates whether the iOS device is jailbroken. |
| Hardware Keystore | Indicates whether the Android device supports a hardware keystore. |
| Rooting | Indicates whether the Android device is rooted. |
| Trusted Platform Module | Indicates whether the Windows Trusted Platform Module is in use. |
Device identifiers
| Device identifier | Description |
|---|---|
| Display name | The display name of the device.
For example, Maya's iPhone. |
| Platform | The operating system of the device. |
| Manufacturer | The vendor that created the physical device. For example, APPLE. |
| Model | The device type or design. For example, iPhone. |
| Serial number | The serial number for the device. |
| OS Version | The operating system software version of the device. |
| IMEI | International Mobile Equipment Identity (IMEI) is a unique number for identifying a mobile device on a Global System for Mobile communication (GSM) network.
Okta Verify doesn't collect this information, but a custom app can collect it. |
| MEID | Mobile Equipment Identifier (MEID) is a unique number for identifying a mobile device on a network that uses Code-Division Multiple Access (CDMA) protocols for second-generation and third-generation wireless communication.
Okta Verify doesn't collect this information, but a custom app can collect it. |
| UDID | The unique device ID (UDID) that is used to identify Apple devices on an iOS or macOS platform. |
| Security Identifier | The Security Identifier (SID) is a unique number for the user, user group, or other security principal. |
| Authenticator app key | A unique identifier for the specific instance of an authenticator app enrolled on the device. |
| Dedicated hardware | Indicates if dedicated hardware exists for a Trusted Platform Module (TPM).
The unique identifier hash isn't shown for devices with a TPM. Instead, the placeholder Present - No hash available appears. |