Enable Desktop MFA Factor Discovery for Windows
Enable Desktop MFA Factor Discovery so that the Windows sign-in screen shows users only the MFA factors that they have enrolled, instead of every factor allowed by your org policy.
About this task
Early Access release. See Enable self-service features.
Showing only enrolled factors prevents failed sign-in attempts that result from users selecting factors they haven't set up. When the feature is active, the Desktop MFA client requests the user's enrolled online factors from the server and presents only those factors at the Windows sign-in screen:
- Existing users who have an enrolled online factor see only those factors, and the Skip option is removed. They must authenticate with an enrolled factor, even on a new device, so a stolen password alone doesn't provide access.
- New users who don't have an enrolled online factor can still sign in during the grace period to set up MFA. The
MaxLoginsWithoutEnrolledFactorspolicy controls the duration of the grace period. - When a user signs in for the first time, the device must be connected to the internet and registered with Okta.
Factor Discovery exposes which factors a user has enrolled, so you must exclude Desktop MFA clients from User Enumeration Prevention (UEP) when UEP is enabled. This exclusion allows trusted Desktop MFA clients to read enrolled factors, while UEP continues to protect all other clients from user-enumeration attacks.
If you have enabled UEP for authentication but you haven't excluded Desktop MFA clients, then all allowed factors still appear when you activate Desktop MFA Factor Discovery.
Before you begin
- Deploy Device Access certificates to your Windows devices using SCEP.
- Deploy Desktop MFA for Windows and enable the
UseDirectAuthpolicy. See Configure and deploy Desktop MFA policies for Windows. - In the Admin Console, go to , and then enable Desktop MFA Factor Discovery.
Exclude Desktop MFA from User Enumeration Prevention.
Set the client policy on your Windows devices.
Verify the configuration.
Tell your users what to expect at the Windows sign-in screen. See Desktop MFA user experience for Windows.