# https://blog.iamarki.ai ## Posts - [Step-by-Step: Deploying Platform SSO with Secure Enclave Support](https://blog.iamarki.ai/step-by-step-deploying-platform-sso-with-secure-enclave-support/): May 2026: This is an Early Access release Table of Contents Introduction Requirements Okta Requirements  MDM & Profile Requirements Required Configuration Profiles Seeing is Believing: Okta Device Access in Action Demo – Manual Secure Enclave Registration for Already Enrolled Devices Demo – Simplified Setup for Platform SSO with Secure Enclave Seamless Migration – From Password Sync to Secure Enclave Platform SSO MDM Deployment Strategy Vendor Guide: Configuring Payloads in Jamf Pro Jamf Configuration Profile Conclusion Introduction Apple’s Platform Single Sign-On (Platform SSO) framework fundamentally changes how identity works on macOS. For a while, the primary focus across the industry has […] - [Deploying the Okta PSSO Application](https://blog.iamarki.ai/deploying-the-okta-psso-application/): Introduction Configuring the Okta PSSO App in the Admin Console Introduction Implementing Okta Platform Single Sign-On (PSSO) is a critical step toward unifying endpoint security and cloud identity management for your macOS fleet. By leveraging Apple’s Extensible Enterprise SSO framework, the Okta PSSO Application establishes a secure, native bridge between the local macOS login window and the Okta Identity Cloud, drastically reducing authentication friction while enforcing robust identity policies. In this short technicall guide, we will provide a comprehensive overview of how to configure and add the Okta PSSO Application within the Okta Admin Console. We will walk through the required application […] - [How to Configure Okta Device Access Certificates Across Different MDMs](https://blog.iamarki.ai/how-to-configure-okta-device-access-certificates-across-different-mdms/): Table of Contents Introduction Jamf Pro – Dynamic SCEP Configuration Okta – Dynamic Device Access SCEP Certificate Configuration Jamf Pro SCEP Profile Configuration Create a dynamic SCEP profile in Jamf Pro Introduction Because every IT environment relies on a different device management stack, certificate delivery looks slightly different depending on your tooling. This post is the first installment of a multi-part series dedicated to configuring these certificates across various platforms. Today, we are focusing entirely on setting up the architecture using Jamf Pro, utilizing a dynamic SCEP configuration to automate deployment. If your organization utilizes a different management platform, stay tuned. […] - [Reinforcing the Perimeter: The Power of Device-Bound Single Sign-On](https://blog.iamarki.ai/reinforcing-the-perimeter-the-power-of-device-bound-single-sign-on/): Introduction Demos macOS Demo – The Device-Bound SSO Experience Windows Demo: TPM-Backed Productivity Early Access Feature Activation Creating the DBSSO Authentication Rule Implementing Device-Bound Single Sign-On on macOS macOS Prerequisites Implementing the Configuration in Jamf Pro Implementing the Configuration in Microsoft Intune Implementing Device-Bound Single Sign-On on Windows Windows Prerequisites Desktop MFA policies for Windows Enabling the “Okta-Joined” State Activating Direct Authentication Final thoughts Introduction In the modern cybersecurity landscape, the traditional perimeter has evaporated, replaced by a complex ecosystem of remote identities and distributed endpoints. As session hijacking and sophisticated phishing campaigns become the primary weapons of choice for […] - [Configure Okta Desktop MFA](https://blog.iamarki.ai/configure-okta-desktop-mfa/): Okta Desktop MFA Configuration In the Admin Console, go to Settings, Account, Embedded widget sign-in support.And ensure that the Interaction Code checkbox is selected. Now navigate to Applications –> Applications, click Browse App Catalog and search for Desktop MFA. Click Add integration Retrieve the Client ID and Client secret, these will be required during deployment. Set the Application username format to match your organization’s requirements (e.g., user principal name for Azure AD environments or SAM account name for AD joined or Hybrid environments). Assign the application to relevant users or groups under the Assignments tab. - [Configure Desktop Password Sync for macOS](https://blog.iamarki.ai/configure-desktop-password-sync-for-macos/): Table of Contents Okta PSSO Setup and Integration Setting Up the Okta PSSO Application Okta PSSO Setup and Integration In this section, we will cover the initial steps for configuring the Okta PSSO application and establish the necessary SCEP (Simple Certificate Enrollment Protocol) configuration.  Setting Up the Okta PSSO Application Navigate to Applications > Applications. In the application catalog, search for Platform. From the results, select the Platform Single Sign-On for macOSapplication tile to begin the integration process. Click Add Integration to instantiate the Platform Single Sign-On for macOS application template within your Okta environment. Choose a suitable Application Label and click Done Navigate to the Assignments pane and assign the relevant users or groups to the Platform Single Sign-On for macOSapplication […] - [Okta Device Integration with Workspace ONE](https://blog.iamarki.ai/okta-device-integration-with-workspace-one/): Table of Contents Introduction Prerequisites Configure management attestation Download x509 certificate Create CA in Workspace ONE Add Certificate Template in Workspace ONE Create device profile for Okta Intermediate CA Create user profile to deploy the Okta CA-issued client certificate Verify the certificate installation (Windows) Verify the managed flag in Okta Introduction You can ensure that devices are managed by an endpoint management (in my example Workspace ONE) tool before end users can access apps from the device. Devices are managed if they meet these conditions: For desktop (Windows, macOS), management attestation certificates are deployed to the device with VMware Workspace ONE UEM. Prerequisites Configure management attestation […] - [Okta Device Access Windows- number challenge](https://blog.iamarki.ai/okta-device-access-windows-number-challenge/): Table of Contents Introduction Requirements Configure Okta Verify Number Challenge Sign in overview Demo Introduction In the latest Early Access Okta Verify Release for  (4.8.1) Okta now supports Push notification (number challenge) for Okta Device Access Desktop MFA. Users can choose whether to include a number challenge with an Okta Verify push notification.The number challenge verifies that a sign-in attempt to an app protected by Okta came from the intended user and not from an unauthorized person. It presents a number in the Sign-In Widget and pushes a notification to Okta Verify on the user’s mobile device.  Requirements Configure Okta Verify Number Challenge In the Okta Admin Console navigate to Security –> Authenticators On the Okta […] - [Okta Device Access self-service password reset](https://blog.iamarki.ai/okta-device-access-self-service-password-reset/): Table of Contents Introduction Prerequisites Create/Adjust Desktop MFA Policies Configuration steps Self-service password reset overview Demo (AD Users) Introduction Self-service password reset allows your users to initiate a password reset if they’re locked out of the computer. Self-service password reset requires users to be online.Users can’t initiate a password reset without an internet connection. The self-service password reset function is designed for the following users: Prerequisites Before enabling the self-service password reset, ensure your Okta password policyand your AD Agent password policies match. A step-by-step guide how to implement Okta Device Access Desktop MFA here.You need to have at least the Okta Verify Version 4.8.1 deployed. Create/Adjust […] - [Okta Device Access macOS Number challenge](https://blog.iamarki.ai/okta-device-access-macos-number-challenge/): Table of Contents Introduction Requirements Configure Okta Verify Number Challenge Sign in overview Demo – macOS Number Challenge Introduction In the latest Early Access Release (9.8.0) of Okta Verify for macOS Okta now also supportsPush notification (Number challenge) for macOS Okta Device Access Desktop MFA.Check here the full release notes. Users can choose whether to include a number challenge with an Okta Verify push notification.The number challenge verifies that a sign-in attempt to an app protected by Okta came from the intended user and not from an unauthorized person.It presents a number in the Sign-In Widget and pushes a notification to Okta Verify on the user’s mobile device. Requirements Configure Okta Verify Number Challenge In the Okta Admin […] - [Okta mobile devices Integration with Workspace ONE](https://blog.iamarki.ai/okta-mobile-devices-integration-with-workspace-one/): Table of Contents Introduction Prerequisites Configure management attestation Integrate Okta with Workspace ONE Create an SSO extension Profile Verify the managed flag in Okta Introduction You can ensure that devices are managed by an endpoint management(in my example Workspace ONE) tool before end users can access apps from the device. Devices are managed if they meet these conditions: For mobile (Android, iOS), a management hint (shared secret) is deployed to the device through a managed app configuration (in this example, with Workspace ONE UEM. Prerequisites Configure management attestation In the Okta Admin Console, go to Security –> Device integrations. Click the Endpoint management tab and then click Add platform. In […] - [Okta Integration with Apple Business Manager and Apple School Manager](https://blog.iamarki.ai/okta-integration-with-apple-business-manager-and-apple-school-manager/): Table of Contents Introduction Requirements Enable Early Access Feature Apple – Set up Federated Authentication Set up Directory Sync between Okta & Apple Overview Demos Introduction Apple Business Manager is a web-based portal that helps you deploy iPhone, iPad, Mac, and Apple TV. And you can easily provide employees with access to Apple services, set up device enrollment, and distribute apps, books, and software — all from one place. In Apple Business Manager, you can now link Okta (your Identity Provider) to allow users to sign in to Apple devices with their Okta username and password. As a result, your users can leverage their Okta usernames […] - [Okta Device Access with Jamf a step-by step guide](https://blog.iamarki.ai/okta-device-access-with-jamf-a-step-by-step-guide/): Table of Contents Introduction Requirements Okta Desktop MFA Configuration Okta Password Sync configuration Enroll your macOS into Jamf Configure the MDM profile for  Desktop MFA for macOS Deploy Okta Verify to your Jamf enrolled device Configure the MDM profile for macOS password sync Introduction In this Blog Post, I’ll take you on a journey how to configure Okta Device Access Desktop MFA and Desktop Password Sync if you use Jamf Pro as your MDM solution for your device fleet.We start with the configuration on Okta, show how to create the necessary configuration profiles on Jamf side and of course we have recorded some demos.Have fun reading the blog and then, […] - [Okta FastPass for Windows Virtual Desktop Infrastructure (VDI)](https://blog.iamarki.ai/okta-fastpass-for-windows-virtual-desktop-infrastructure-vdi/): Table of Contents Introduction Requirements Okta Verify configurations for Windows devices Deploy Okta Verify for virtual Windows environments Setup User verification with an Okta Verify passcode User verification with an Okta Verify passcode Good to know Introduction Okta Verify/FastPass and Device Assurance are now going to be supported in Windows VDI (Virtual Desktop Infrastructure) environments for easy access to resources. Extend passwordless, phishing resistant authentication with device context to resources in VDI environments (AWS, Citrix, etc.).  With this we can bypassing the need of Windows Hello via the the new Passcode Verification feature. Requirements Okta Verify configurations for Windows devices You have the ability to alter Okta Verify functionality by utilizing […] - [FIDO2 for Desktop MFA for macOS](https://blog.iamarki.ai/fido2-for-desktop-mfa-for-macos/): Table of Contents Requirements Set up the FIDO2 (WebAuthn) authenticator Use Case – User verification “disabled” User registers a YubiKey using the Okta End-User Dashboard Demos user registers a YubiKey User Experience – Desktop MFA FIDO2 YubiKey Demo – Desktop MFA FIDO2 YubiKey Use Case – User Verification “enabled” Register a YubiKey on behalf of user in the Admin Console Demo – Register a YubiKey on behalf of user User Experience – Desktop MFA FIDO2 YubiKey Demo – Desktop MFA FIDO2 YubiKey C Bio Demo – Desktop MFA FIDO2 YubiKey 5ci Good to know USB Restriction Mode on Apple silicon devices YubiKey Enrollment Reset a YubiKey […] - [Okta Desktop MFA for macOS with Microsoft Intune](https://blog.iamarki.ai/okta-desktop-mfa-for-macos-with-microsoft-intune/): Table of Contents Introduction Okta Requirements Microsoft Intune Requirements Okta Desktop MFA Configuration Enroll your macOS into Microsoft Intune Install Microsoft Company Portal app Enroll your Mac Demo macOS Enrollment Intune Configure the MDM profile for Desktop MFA for macOS Deploy Okta Verify to your Intune enrolled device Introduction In this blog post, I’ll take you on a journey how to configure Okta Device Access Desktop MFA if you use Microsoft Intune as your Mobile Device Management (MDM) solution for your macOS device fleet.We start with the configuration on Okta and show how to create the necessary configuration profile on Intune side.Have fun reading the blog and then, of course, integrating […] - [Okta Device Access Desktop Password Sync with Microsoft Intune](https://blog.iamarki.ai/okta-device-access-desktop-password-sync-with-microsoft-intune/): Table of Contents Introduction Okta Requirements Microsoft Intune Requirements Okta Desktop Password Sync Configuration Enroll your macOS into Microsoft Intune Install Company Portal app Enroll your Mac Deploy Okta Verify to your Intune enrolled device Configure the MDM profiles for macOS password sync Configure single sign-on extension profile for Desktop Password Sync in Intune Configure Associated Domains settings Configure Extensible Single Sign On (SSO) settings Create device management profiles for Password Sync  in Intune Demo Desktop Password Sync Introduction In this blog post, I’ll take you on a journey how to configure Okta Device Access Desktop Password Sync if you use Microsoft Intune as […] - [Okta Device Access with Kandji a step-by step guide](https://blog.iamarki.ai/okta-device-access-with-kandji-a-step-by-step-guide/): Table of Contents Introduction Requirements Okta Desktop MFA Configuration Okta Password Sync (Platform -SSO) configuration Prepare your Kandji environment Enroll your macOS into Kandji Create the profile for Desktop MFA  Deploy Okta Verify App to your Kandji enrolled device Demo Desktop MFA Create the MDM profiles for macOS password sync Create the Platform SSO configuration profile Create the Okta Verify configuration profile Demo Okta Desktop Password Sync Introduction In this Blog Post, I’ll take you on a journey how to configure Okta Device Access Desktop MFA and Desktop Password Sync if you use Kandji as your Mobile Device Management (MDM) solution for your device fleet.We start […] - [Better together: Okta Device Access and Okta FastPass](https://blog.iamarki.ai/better-together-okta-device-access-and-okta-fastpass/): Table of Contents Introduction macOS Okta Device Access and FastPass experience Enable Okta FastPass Enroll Okta FastPass on macOS Configure authentication policies Okta Dashboard Application Policy Additional configurations on macOS Devices Configure SSO extension for managed macOS devices Configure auto-launch Okta Verify on macOS devices Windows Okta Device Access and FastPass experience Enroll Okta FastPass on Windows Skip the Open Okta Verify prompt Introduction Combining security and user experience sometimes seems to be a challenging endeavour.In the last few weeks I have been asked by colleagues but also customers, hey I have now successfully implemented Okta Device Access, where I log on to my end device with a strong […] - [Desktop Password Sync meets Platform SSO 2.0 and Jamf Pro](https://blog.iamarki.ai/desktop-password-sync-meets-platform-sso-2-0-and-jamf-pro/): Table of Contents Introduction Prerequisites Set up Device Access SCEP certificates Configure Okta as a CA for Device Access Create a dynamic SCEP profile in Jamf Pro Verify that the Okta CA was installed on your devices Update your MDM profiles Update your device management profile  Update your single sign-on extension profile Demo Password Sync on macOS lock screen Demo Password Sync on macOS login screen Introduction Support for Platform SSO 2.0 is available for macOS computers using Sonoma (14.0) and later. Platform SSO 2.0 allows Desktop Password Sync to be used directly from the macOS login window.In this blog, I will briefly describe the configuration steps required […] - [Desktop Password Sync meets Platform SSO 2.0 and Workspace ONE](https://blog.iamarki.ai/desktop-password-sync-meets-platform-sso-2-0-and-workspace-one/): Table of Contents Introduction Prerequisites Set up Device Access SCEP certificates Configure Okta as a CA for Device Access Download the x509 certificate from Okta Workspace ONE SCEP configuration Create a Certificate Authority Add a Certificate Template  Create a device profile to deploy the Okta CA  Create a user profile to deploy the Okta CA-issued client certificate Verify the certificate on the macOS device Workspace ONE Profiles configuration Update your device management profile Update your single sign-on extension profile Demo Password Sync on macOS lock screen Demo Password Sync on macOS login screen Workspace ONE custom profiles Okta Verify Custom Profile […] - [Desktop Password Sync meets Platform SSO 2.0 and Kandji](https://blog.iamarki.ai/desktop-password-sync-meets-platform-sso-2-0-and-kandji/): Table of Contents Introduction Prerequisites Set up Device Access SCEP certificates Configure Okta as a CA for Device Access Kandji SCEP configuration Verify that certificate was installed on device Update your Kandji Library profiles Platform SSO configuration profile Okta Verify configuration profile Introduction Support for Platform SSO 2.0 is available for macOS computers using Sonoma (14.0) and later.Platform SSO 2.0 allows Desktop Password Sync to be used directly from themacOS login window.In this blog, I will briefly describe the configuration steps required to use Okta Device Access with Platform SSO 2.0 with Kandji as your MDM solution. Prerequisites Before you start ensure that you meet these requirements: Set up […] - [Okta Device Access macOS TOTP account link](https://blog.iamarki.ai/okta-device-access-macos-totp-account-link/): Table of Contents Introduction Prerequisites Create / Adjust MDM Profiles Workspace ONE UEM Profile Jamf PRO Profile Kandji Profile Microsoft Intune Profile Introduction In Desktop MFA for macOS, admins can now choose between Okta Verify push notification and Okta Verify Time-based One-Time Password as the user verification method used to link an Okta account to the local macOS account.In this blog I will show you how to implement Okta Verify Time-based One-Time Password as the user verification method to link an Okta account to the local macOS account. Prerequisites Before you start ensure that you meet these requirements: Create / Adjust MDM Profiles The […] - [Desktop Password Sync meets Platform SSO 2.0 and Microsoft Intune](https://blog.iamarki.ai/desktop-password-sync-meets-platform-sso-2-0-and-microsoft-intune/): Introduction Support for Platform SSO 2.0 is available for macOS computers using Sonoma (14.0) and later.Platform SSO 2.0 allows Desktop Password Sync to be used directly from themacOS login window.In this blog, I will briefly describe the configuration steps required to use Okta Device Access with Platform SSO 2.0 and Microsoft Intune as your MDM solution. Prerequisites Before you start ensure that you meet these requirements: Set up Device Access SCEP certificates Device Access SCEP certificates are required to use Desktop Password Sync on devices running macOS Sonoma (14.0) and later.These certificates deploy with yourMicrosoft Intune environment. Configure Okta as a CA with delegated SCEP challenge for Microsoft Intune In this blog I […] - [Okta secure devices Videos on IAMSE.blog](https://blog.iamarki.ai/okta-secure-devices-videos-on-iamse-blog/): Introduction Remote and hybrid work is here to stay, so are all your devices secured? In recent weeks and months, I’ve written various blogs on the topic endpoint integration and security.In this blog post, I would like to briefly demonstrate once again with some demos how Okta can help with this from enrollment to logging on to the device and accessing the applications.So I hope you enjoy the demos! Streamlined Device Enrollment and Workspace ONE login for endpoints using Okta In the first demo we will se a streamlined Device Enrollment with Okta and Workspace ONE.After the brand new macOS device boots up the very first time, Zero-Touch Enrollment automatically enrolls it into Workspace ONE […] - [Okta and VMware Horizon True SSO](https://blog.iamarki.ai/okta-and-vmware-horizon-true-sso/): Introduction This blogs covers a basic guide how to configure Okta and VMware Horizon to provide an end-to-end single sign on experience to the end-user .We need to have TrueSSO configured on our Horizon environment as this enable users are not required to also enter Active Directory credentials in order to use a remote desktop or applications. Prerequisites Configuring SAML Integration with Okta In the Okta Admin Console navigate to Applications –> Applications Create a new App Integration Select SAML 2.0 and press Next Enter your App name as the App name, upload an App Logo(optional) and Click Next No we need to configure the SAML Settings.Here we need to replace <YOUR-UAG_FQDN> with the respective FQDN from your environment. Complete your […] - [Okta Device Access - Desktop MFA for macOS](https://blog.iamarki.ai/okta-device-access-desktop-mfa-for-macos/): Okta Desktop MFA for macOS adds an extra layer of security to the macOS sign-in process by asking users for additional authentication before allowing computer access. In this blog we show you how to configure Desktop MFA in the Okta Admin Console, and then deploy it through VMware Workspace ONE.  Technical Prerequisites Create and configure the Desktop MFA app integration In the Admin Console, go to Settings, Account, Embedded widget sign-in support. and ensure that the Interaction Code checkbox is selected. Now we need to enable Direct Authentication, to do so go to Settings, Features and enable Direct Authentication. In the Admin Console, navigate now to  Applications –> Applications. Click Browse App Catalog and search for Desktop MFA Click Add […] - [Okta Device Access - Desktop Password Sync for macOS](https://blog.iamarki.ai/okta-device-access-desktop-password-sync-for-macos/): October 2024: The Okta application name from “Desktop Password Sync” to“Platform Single Sign-On for macOS” April 2025: Additional app identifier required for the associated domain entry on macOS 15 Sequoia (mobileconfig template was updated) Introduction With macOS Ventura, Apple introduced Platform SSO, which enables developers to create a single sign-on (SSO) extension that interacts directly with the macOS login window. This extension enables users to link their local macOS account with their Identity provider through a simple, Mac-native workflow. Okta has led the way in adopting this with the Desktop Password Sync feature under the Okta Device Access offering,allowing users to authenticate themselves using their Okta credentials directly from the […] - [Okta Desktop MFA for Windows](https://blog.iamarki.ai/okta-desktop-mfa-for-windows/): The use ofOkta’s Desktop MFA for Windows strengthens the security of a user’sauthentication of Windows computers.This customizable solution is designed to configure the sign- in flow into a Windows workstation.This secured sign-in flow will prompt a user for multi-factor authentication after the username and password are entered and includes offline sign-in methods that can be used in cases where an internet connection is not available.The use of Desktop MFA adds a layer of security to company-provided desktopand laptop computers using Okta MFA factors already used by your employees. Technical Prerequisites Create and configure the Desktop MFA app integration In the Admin Console, go […] - [Enable Okta for VMware vCenter Server](https://blog.iamarki.ai/enable-okta-for-vmware-vcenter-server/): In today’s security landscape, identity management and multifactor authentication (MFA) are crucial components. The latest release of vSphere, vSphere 8 Update 1, introduces support for cloud-based identity providers in vCenter, including the widely used Okta service. With this new capability, vSphere administrators can leverage modern identity management features for enhanced security and streamlined operations. Prerequisites Okta requirements: Okta connectivity requirements: vCenter Server requirements: Networking requirements: Step 1: Create the Okta OpenID Connect Application First we need to create the OIDC – OpenID Connect on Okta side. Select OIDC – OpenID Connect as the Sign in method and Native Application as the Application type We need to enter a name for the OpenID Connection application and in the General Settings section– […] - [Secure your VMware Web Proxy access with Okta](https://blog.iamarki.ai/secure-your-vmware-web-proxy-access-with-okta/): Overview / Prerequisites In this blog I want to guide you through the process how we can integrate Okta as the IdP with VMware Web Proxy and how the User Experience looks .I will not cover how to create a Security Policy on the VMware side, but you can read this basic steps in my personal blog. The VMware Cloud Web Security (CWS) Web Proxy is designed to enable the standalone consumption of CWS without the need for VMware SD-WAN or VMware Secure Access (SA). Any device with a modern browser that can support a network proxy configuration, either manually or automatically through a proxy auto-config (PAC) file, can have its […] - [VMware SD-WAN Orchestrator Single Sign-On powered by Okta](https://blog.iamarki.ai/vmware-sd-wan-orchestrator-single-sign-on-powered-by-okta/): Table of Contents Prerequisites Configure Okta for Single Sign On How to configure Single Sign On for Operator User Single Sign On Demo(s) In this article I would like to describe how to integrate the Okta into the SD-WAN Orchestrator and using Single Sign On (SSO) with different user types. VMware SD-WAN Orchestrator provides centralized, enterprise-wide installation, configuration, and real time monitoring, in addition to orchestrating the data flow through the cloud network. Prerequisites Configure Okta for Single Sign On Let us first create a new Application in Okta. Select OIDC – OpenID Connect as the Sign-in method, Web Application as the Application type click Next to continue. In the General Settings section enter a name […] - [Desktop MFA Recovery for macOS](https://blog.iamarki.ai/desktop-mfa-recovery-for-macos/): August 2024: This is an Early Access Feature Table of Contents Introduction Prerequisites Enable Device Recovery Configure Device Recovery Omnissa Workspace ONE UEM Jamf Pro Kandji Microsoft Intune Request a Device Recovery PIN Demo Request a Device Recovery PIN Create Device Recovery PIN Demo Create Device Recovery PIN Demo Desktop MFA Admin Recovery Conclusion Introduction In today’s security-focused environment, Multi-Factor Authentication (MFA) is crucial for protecting user accounts and data. However, challenges arise when users lose access to their registered MFA device and cannot sign in to their machines. This situation necessitates administrative intervention to restore user access securely and efficiently. This blog […] - [Okta Device Access - Allowed Factors on macOS](https://blog.iamarki.ai/okta-device-access-allowed-factors-on-macos/): Table of Contents Introduction Prerequisites Configure Allowed Factors MDM policy Omnissa Workspace ONE UEM Jamf Pro Kandji Microsoft Intune Demo Introduction Admins can now control which verification methods users are permitted to authenticate with by configuring a new registry value called AllowedFactors.This provides greater flexibility in managing authentication options within the system. Prerequisites Configure Allowed Factors MDM policy Deploy the configuration to your devices using your Mobile Device Management (MDM) solution.Ensure that you apply the following settings in your Desktop MFA MDM profile for proper configuration: Value name Description Default value AllowedFactors You can specify a list of authentication factors that users are […] - [Just in Time Account Creation for macOS with Jamf Pro](https://blog.iamarki.ai/just-in-time-account-creation-for-macos-with-jamf-pro/): April 2025: Additional app identifier required for the associated domain entry on macOS 15 Sequoia Table of Contents Introduction to Just-in-Time Local Account Creation on macOS with Okta Requirements for Implementing Just-in-Time Local Account Creation with Okta on macOS Enable JIT provisioning in the Admin Console Add custom attributes to Platform SSO app Set up Device Access SCEP certificates Configure Okta as a CA for Device Access Create a dynamic SCEP profile in Jamf Pro Verify that the Okta CA was installed on your devices Configure PlatformSSO MDM profile in  Jamf Pro Preparing the macOS Device for User Enrollment Demo Just-in-Time Local Account Creation Conclusion […] - [Okta Devices Access - Just in Time Account Creation for macOS with Microsoft Intune](https://blog.iamarki.ai/okta-devices-access-just-in-time-account-creation-for-macos-with-microsoft-intune/): April 2025: Additional app identifier required for the associated domain entry on macOS 15 Sequoia Table of Contents Introduction to Just-in-Time Local Account Creation on macOS with Okta Requirements for Implementing Just-in-Time Local Account Creation with Okta on macOS Enable JIT provisioning in the Admin Console Add custom attributes to Platform SSO app Set up Device Access SCEP certificates Set up Device Access SCEP certificates Configure Okta as a CA with delegated SCEP challenge for Microsoft Intune Register the AAD app credentials for Okta in Microsoft Entra Set the Intune scep_challenge_provider permissions Set the Microsoft Graph Application.Read.All permissions Generate a SCEP URL in Okta Download the x509 […] - [Okta Device Access with mosyle a step-by-step guide](https://blog.iamarki.ai/okta-device-access-with-mosyle-a-step-by-step-guide/): April 2025: Additional app identifier required for the associated domain entry on macOS 15 Sequoia (mobileconfig template was updated) Introduction In this blog post, I’ll guide you through the process of configuring Okta Device Access Desktop MFA and Platform SSO for macOS devices managed with mosyle MDM. We’ll begin by setting up the required configurations within Okta, followed by creating and deploying the necessary configuration profiles in mosyle. By the end, you’ll have a clear understanding of how to implement and test this integration seamlessly. Enjoy the read, and happy integrating! Requirements Here’s how you can set up Okta Device Access Desktop MFA and Platform SSO for macOS devices using mosyle as your Mobile Device Management […] - [Enhancing Security with Okta Identity Threat Protection and Omnissa](https://blog.iamarki.ai/enhancing-security-with-okta-identity-threat-protection-and-omnissa/): Table of Contents Introduction Prerequisites Okta Omnissa Omnissa configuration Configure Security Events in Omnissa Workspace ONE UEM Compliance policies Okta Identity Threat Protection Configuration Configure the shared signal receiver Entity Risk Policy Policy Structure and Evaluation Actions Based on Matching Rules Add an entity risk policy rule for Universal Logout Add an entity risk policy rule to run a Workflow Demos ITP Universal Logout – Omnissa Workspace ONE enrolled Device Observability & Insights Review logs – Identity Threat Protection Universal Logout ITP Workflows – Omnissa Workspace ONE enrolled Device Review logs – Identity Threat Protection Workflows Omnissa events Conclusion Introduction […] - [Okta Device Access Out-of-the-box enrollment with Jamf Pro](https://blog.iamarki.ai/okta-device-access-out-of-the-box-enrollment-with-jamf-pro/): April 2025: Additional app identifier required for the associated domain entry on macOS 15 Sequoia Table of Contents Introduction Requirements Okta Apple Business Manager (ABM) Account Jamf Pro MDM Configuration Demos Secure macOS onboarding and Platform SSO enrollment Just-in-Time (JIT) local account creation and Desktop MFA enrollment Configure Single-Sign-On Okta Configuration Jamf Pro Configuration Configure Okta LDAP with Jamf Pro Okta Configuration Jamf Pro LDAP configuration Okta Device Access configuration Set up Device Access SCEP certificates Configure Okta as a CA for Device Access Create a dynamic SCEP profile in Jamf Pro Configure PlatformSSO MDM profile in Jamf Pro Configure Desktop MFA MDM […] - [Okta Device Access - FIDO2 security keys for Windows](https://blog.iamarki.ai/okta-device-access-fido2-security-keys-for-windows/): January 2025: This is an Early Access release Table of Contents Introduction Requirements Activating FIDO2 Support for the Desktop MFA Set up the FIDO2 (WebAuthn) authenticator Setting Up FIDO2 Security Keys User registers YubiKey using the Okta End-User Dashboard Register a YubiKey on behalf of user in the Admin Console Authentication use cases Authentication User verification “Disabled” Demo – Desktop MFA FIDO2 YubiKey Authentication User Verification “enabled” Demo – Desktop MFA FIDO2 YubiKey Reset a YubiKey User has no YubiKey registered Conclusion January 2025: This is an Early Access release January 2025: This is an Early Access release Introduction When integrating Okta Device Access with FIDO2 security keys for […] - [Okta Device Access Allowed Factors on Windows](https://blog.iamarki.ai/okta-device-access-allowed-factors-on-windows/): January 2025: This is an Early Access release Table of Contents Introduction Prerequisites Configure Allowed Factors policy Demo Introduction We now have the capability to define which authentication methods users are allowed to utilize by setting a new registry value called AllowedFactors on Windows devices. This enhancement provides greater control and customization over authentication policies, allowing organizations to fine-tune security measures and align them with specific operational needs. Prerequisites Configure Allowed Factors policy To configure the Allowed Factors policy for Okta Device Access Desktop MFA, it’s necessary to deploy a specific registry key to your endpoints. The registry key must be configured appropriately across all systems where […] - [Mastering Okta Device Access: A Comprehensive Guide to Deploying Desktop MFA with Microsoft Intune](https://blog.iamarki.ai/mastering-okta-device-access-a-comprehensive-guide-to-deploying-desktop-mfa-with-microsoft-intune/): September 2026: Updated policies for offline biometrics settings + added new offline biometrics feature demos. Table of Contents Requirements Okta Requirements Microsoft Intune Requirements Okta Desktop MFA Configuration Okta Verify Deployment Convert Okta Verify into .intunewin Package Deploy the Okta Verify .intunewin Package in Microsoft Intune Configuring Registry Settings for Okta Device Access in Microsoft Intune via a PowerShell Script Configure and deploy Okta Device Access access policies Okta Device Access – Windows Demos Offline biometrics for Windows – Fingerprint Offline biometrics for Windows – Facial Passwordless Login Offline login to Windows – Device Access Code Self-Service Password Reset Configure and Deploy […] - ["Enhancing Zero Trust with Okta Identity Threat Protection and Jamf Security: Continuous Access Evaluation Through Shared Security Signals"](https://blog.iamarki.ai/enhancing-zero-trust-with-okta-identity-threat-protection-and-jamf-security-continuous-access-evaluation-through-shared-security-signals/): Table of Contents Introduction Prerequisites: Setting the Foundation for Okta Identity Threat Protection and Jamf Security Cloud Integration Okta Requirements Jamf Security Cloud Requirements Additional Considerations Demos Demo – Jamf Trust Activation with Okta Demo – Identity Threat Protection with Jamf and Universal Logout – macOS Demo – Identity Threat Protection with Jamf and Universal Logout – Mobile devices Authorizing Jamf Trust in Your Okta Organization Create a Jamf SSO app in Okta Create an Okta IdP connection in Jamf Security Cloud Configuring UEM Connect for Jamf Pro Creating an Activation Profile using Jamf Security Cloud Distribute the activation profile and Jamf Trust […] - [Fortifying the Zero Trust Framework with Okta Advanced Posture Checks](https://blog.iamarki.ai/fortifying-the-zero-trust-framework-with-okta-advanced-posture-checks-for-macos/): May 2026: This is an Early Access releaseApril 2026: Added Windows section Table of Contents Introduction Prerequisites Seeing is Believing: Advanced Posture Checks in Action macOS: Verifying Firewall Status via OSQuery Windows: Verifying Firewall Status via OSQuery Enable Advanced Posture Checks in Okta How to Configure Custom Device Checks How to Configure Custom Device Checks for macOS How to Configure Custom Device Checks for Windows Create custom checks Add the custom check to a device assurance policy Add the device assurance policy to an authentication policy Logs Miscellaneous Conclusion Introduction In today’s increasingly complex and perilous digital landscape, the concept […] - [Cross-Platform Endpoint Security: Integrating Okta and CrowdStrike for Windows and macOS](https://blog.iamarki.ai/cross-platform-endpoint-security-integrating-okta-and-crowdstrike-for-windows-and-macos/): Table of Contents Introduction Requirements Okta Configuration CrowdStrike Configuration Device Management / MDM macOS Device Requirements Windows Device Requirements Network & Connectivity Okta configuration steps Endpoint Security Integration Create an endpoint security integration authentication policy Install the CrowdStrike sensor on macOS Endpoint security integration plugin for macOS Install the CrowdStrike sensor on Windows Review Okta System Logs Conclusion Introduction In today’s dynamic and hybrid work environments, ensuring that only trusted and secure devices can access corporate resources is a fundamental pillar of a Zero Trust strategy. Device posture, including real-time security health and risk state, is critical in enabling secure access […] - [Okta Device Access: FIDO2 Passwordless Windows Login](https://blog.iamarki.ai/okta-device-access-fido2-passwordless-windows-login/): July 2025: This is an Early Access Release Table of Contents Introduction Requirements Okta Requirements Windows Device Requirements User Prerequisites & Enrollment Demo – FIDO2 Passwordless on Windows Configuration steps Activating FIDO2 Support for the Desktop MFA Activating Passwordless policy for Desktop MFA Set up the FIDO2 (WebAuthn) authenticator Configure User Verification Method Configure Authentication Policy Conclusion Introduction This technical blog post offers an exploration of Okta Device Access Desktop MFA with FIDO2 Passwordless for Windows, a transformative solution designed to fundamentally redefine the Windows login experience. We’ll dissect the technical intricacies of its implementation, delineate the critical requirements for seamless integration, and […] - [Device Logout for macOS](https://blog.iamarki.ai/device-logout-for-macos/): August 2025: This is an Early Access release Table of Contents Introduction Requirements Enable Early Access Feature Desktop MFA – Device Logout System Logs Demo – Device Logout Universal Logout with Identity Threat Protection Enabling the Logout Feature  Entity Risk Policy configuration Demo Introduction In today’s fast-paced enterprise environment, ensuring the security of user sessions across devices is more critical than ever. With employees accessing corporate resources from multiple macOS devices—laptops, desktops, and shared workstations—organizations face increasing risks from unauthorized access, session hijacking, and compromised credentials. The Okta Device Logout for macOS feature provides a powerful solution by allowing IT administrators to remotely sign users out […] - [Streamlining Windows Admin Recovery with Okta Device Access and Intune Integration](https://blog.iamarki.ai/streamlining-windows-admin-recovery-with-okta-device-access-and-intune-integration/): August 2025: This is an Early Access release Table of Contents Introduction Requirements Okta Requirements Microsoft Intune Requirements Demo – Windows Admin Recovery Enable Desktop MFA recovery  Desktop MFA access policies Group Policy-Based Deployment of Desktop MFA for Windows Configure Okta as a CA with delegated SCEP challenge for Microsoft Intune Register the AAD app credentials for Okta in Microsoft Entra Set the Intune permissions for SCEP Set the Microsoft Graph permissions Implement the SCEP configuration in Okta Download the x509 certificate from Okta Create a Trusted Certificate configuration in Microsoft Intune Create a SCEP profile in Intune Confirm Successful Certificate Deployment Verifying the SCEP Certificate […] - [Unifying Your Corporate PKI with Okta Device Access](https://blog.iamarki.ai/unifying-your-corporate-pki-with-okta-device-access/): Introduction Requirements Configuring the ADCS Certificate Template Duplicate and Configure a Certificate Template Add the Okta Application Policy Configure Permissions Publish the New Template Manually Requesting a Certificate from a Microsoft CA via the Certificates Console Verify the Certificate Installation Configuring Okta Device Access Certificate Authority Conclusion Introduction While Okta can act as a Certificate Authority (CA), many enterprises prefer to leverage their existing Public Key Infrastructure (PKI), namely Microsoft Active Directory Certificate Services (ADCS). This technical guide provides a, step-by-step approach to using your own ADCS CA with Okta Device Access. We’ll delve into the process of creating a custom certificate property within an […] - [Farewell, Complexity: Platform SSO Simplified Setup on macOS 26 Powered by Okta and Jamf](https://blog.iamarki.ai/farewell-complexity-platform-sso-simplified-setup-on-macos-26-powered-by-okta-and-jamf/): May 2026 Update: Updated to include support for Secure Enclave capabilities. Table of Contents Introduction Requirements The Technical Leap: Identity at Setup Assistant Requirements Okta Requirements  Jamf Pro Requirements  macOS Device Requirements  Demo – Simplified Setup for Platform SSO with Secure Enclave Demo – Simplified Setup for Platform SSO with Desktop Password Sync Configuring Single Sign-On (SSO) Okta Setup Jamf Pro Single Sign-On (SSO) Configuration Okta PSSO Setup and Integration Setting Up the Okta PSSO Application Device Access SCEP Certificate Configuration Jamf Pro SCEP Profile Configuration Create a dynamic SCEP profile in Jamf Proin Jamf Pro PlatformSSO MDM Profile Configuration in Jamf […] ## Pages - [Subscribe](https://blog.iamarki.ai/21728-2/): Just subscribe! - [Disclaimer](https://blog.iamarki.ai/disclaimer/): All content on this blog, especially technical guides and code examples, is provided “as is” without any warranty of its correctness, security, or suitability for a particular purpose. The author assumes no liability for any damages arising directly or indirectly from the use or inability to use the information provided. The opinions expressed are solely those of the author and do not represent the views of their employer or any other organization. - [Contact me](https://blog.iamarki.ai/contact-2/): Get in Touch. Thank you for your interest. This is the right place for inquiries, feedback on my articles, or suggestions for future topics. I read every message and will do my best to respond as promptly as possible. Please complete the form below to get in touch. - [Articles](https://blog.iamarki.ai/articles-2/): Step-by-Step: Deploying Platform SSO with Secure Enclave Support Arkadiusz Krowczynski·June 4, 2026·0 comments Apple, Jamf, Jamf Pro, macOS, Okta, Okta Device Access May 2026: This is an Early Access release Table of ContentsIntroductionRequirementsOkta Requirements MDM & Profile RequirementsRequired Configuration ProfilesSeeing is Believing: Okta Device Access in ActionDemo – Manual Secure Enclave Registration for Already Enrolled DevicesDemo – Simplified Setup for Platform SSO with Secure EnclaveSeamless Migration – From Password Sync to Secure Enclave Platform SSOMDM Deployment StrategyVendor Guide:… Continue Reading Deploying the Okta PSSO Application Arkadiusz Krowczynski·May 29, 2026·0 comments macOS, Okta, Okta Device Access IntroductionConfiguring the Okta PSSO App in […] - [Resources](https://blog.iamarki.ai/resources/): Our Services In-depth articles breaking down key branding concepts and tactics. Exclusive interviews with branding pros sharing real-world experiences. Detailed case studies illustrating branding successes and lessons. Stay Inspired Dive into fresh branding insights and strategies to elevate your business identity. - [Articles](https://blog.iamarki.ai/articles/): Branding Insights About Us At blog.iamarki.ai, we dive deep into branding to help you build a business identity that truly stands out. - [Contact](https://blog.iamarki.ai/contact/): We are here to help Need some help? Fill out the form below and our staff will be in touch!   - [About Me](https://blog.iamarki.ai/about/): Hello and welcome to my blog My name is Arkadiusz Krowczynski (but everyone calls me Arki), and I’m a Principal Product Acceleration Specialist in the product organization at Okta. With a career spanning nearly 25 years in the IT industry, I’ve had the opportunity to work in a variety of roles and cover many different topics. My journey has taken me from hands-on IT consulting to deep architectural work in the world of End-User Computing at VMware, and now into the heart of identity and access management. The intersection of devices and identity has always been a passion of mine. […] - [Button & Separator](https://blog.iamarki.ai/3029-2/): Faucibus nisl tincidunt eget nullam non. Feugiat sed lectus vestibulum mattis ullamcorper. Egestas purus viverra accumsan in nisl nisi scelerisque eu. Eget nunc lobortis mattis aliquam faucibus purus in massa tempor. Dignissim suspendisse in est ante in nibh mauris cursus. Ipsum faucibus vitae aliquet nec. Filled Style Button Aliquam faucibus purus in massa tempor nec feugiat nisliverra orci sagittis. Outline Style Button Aliquam faucibus purus in massa tempor nec feugiat nisliverra orci sagittis. Filled Rounded Aliquam faucibus purus in massa tempor nec feugiat nisliverra orci sagittis. More Customizations Separator Default Porttitor leo a diam sollicitudin tempor id. Cursus mattis molestie […] - [Image & Gallery Block](https://blog.iamarki.ai/image-gallery-block/): Porttitor leo a diam sollicitudin tempor id. Cursus mattis molestie a iaculis at erat pellentesque. Malesuada proin libero nunc consequat interdum varius sit amet mattis. Sem fringilla ut morbi tincidunt augue interdum. Netus et malesuada fames ac turpis egestas maecenas pharetra convallis. Nulla aliquet porttitor lacus luctus accumsan tortor posuere ac. Nisl suscipit adipiscing bibendum est. Left Aligned Image Has wisi placerat legendos in, eu eos eius lorem consequat. In cum eruditi facilis, qui id facer scripserit. Ne vix nulla eirmod iracundia, vix et accusam officiis. Cum nobis munere partem ei. Nostrud probatus postulant ex mea. An sit iusto maiestatis, […] - [Table Block](https://blog.iamarki.ai/table-block/): Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Rutrum quisque non tellus orci. Luctus accumsan tortor posuere ac ut consequat semper viverra nam. Rhoncus mattis rhoncus urna neque viverra. Tristique risus nec feugiat in fermentum posuere urna nec. Table Wide Width ID First Name Last Name Profession 1 John Doe Entrepreneur 2 Michael Clarck Web Designer 3 Monica Sherif Author 4 Alex McLaren Analytic Tristique magna sit amet purus gravida quis. Netus et malesuada fames ac turpis egestas sed. Id volutpat lacus laoreet non curabitur gravida arcu. Ornare arcu […] - [Quote Block](https://blog.iamarki.ai/quote-block/): Enim sit amet venenatis urna cursus eget nunc scelerisque viverra. A arcu cursus vitae congue. Netus et malesuada fames ac turpis egestas integer eget. Quis commodo odio aenean sed adipiscing diam donec adipiscing. Viverra tellus in hac habitasse. Varius sit amet mattis vulputate enim. Montes nascetur ridiculus mus mauris vitae ultricies leo integer malesuada. Quote Left Aligned Only a quarter of young adults are financially literate. You don’t want to overwhelm them with terrible advice. Micheal Clarck Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Rutrum quisque non tellus […] - [Columns Block](https://blog.iamarki.ai/columns-block/): 1 Column Netus et malesuada fames ac turpis egestas sed. Id volutpat lacus laoreet non curabitur gravida arcu. Ornare arcu odio ut sem nulla pharetra diam sit. Massa tempor nec feugiat nisl. Laoreet id donec ultrices tincidunt arcu non sodales neque. 1/2 Column Netus et malesuada fames ac turpis egestas sed. Id volutpat lacus laoreet non curabitur gravida arcu. Ornare arcu odio ut sem nulla pharetra diam sit. 1/2 Column Netus et malesuada fames ac turpis egestas sed. Id volutpat lacus laoreet non curabitur gravida arcu. Ornare arcu odio ut sem nulla pharetra diam sit. 1/3 Column Netus et malesuada […] - [Legal Notice](https://blog.iamarki.ai/left-sidebar/): # Legal Notice ## Information pursuant to § 5 TMG (German Telemedia Act) Arkadiusz KrowczynskiZum Hofe 158710 MendenGermany ## Contact Email: arki@iamarki.ai ## Responsible for the content Arkadiusz KrowczynskiZum Hofe 158710 MendenGermany ## EU Dispute Resolution The European Commission provides a platform for online dispute resolution (ODR): [https://ec.europa.eu/consumers/odr/](https://ec.europa.eu/consumers/odr/).You can find our email address in the legal notice above. - [Right Sidebar](https://blog.iamarki.ai/right-sidebar/): Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Lobortis feugiat vivamus at augue eget arcu dictum varius. Vestibulum lectus mauris ultrices eros in. Semper eget duis at tellus at urna condimentum mattis pellentesque. Enim neque volutpat ac tincidunt vitae semper quis. Mi eget mauris pharetra et ultrices neque ornare. Mi eget mauris pharetra et ultrices neque ornare aenean euismod. Fringilla est ullamcorper eget nulla facilisi etiam. Varius quam quisque id diam vel quam elementum. Odio morbi quis commodo odio aenean sed adipiscing diam. Mattis molestie a iaculis at. Lectus […] - [Default Width](https://blog.iamarki.ai/default-width/): Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Lobortis feugiat vivamus at augue eget arcu dictum varius. Vestibulum lectus mauris ultrices eros in. Semper eget duis at tellus at urna condimentum mattis pellentesque. Enim neque volutpat ac tincidunt vitae semper quis. Mi eget mauris pharetra et ultrices neque ornare. Mi eget mauris pharetra et ultrices neque ornare aenean euismod. Fringilla est ullamcorper eget nulla facilisi etiam. Varius quam quisque id diam vel quam elementum. Odio morbi quis commodo odio aenean sed adipiscing diam. Mattis molestie a iaculis at. Lectus […] - [Narrow Width](https://blog.iamarki.ai/narrow-width/): Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Laoreet non curabitur gravida arcu ac tortor dignissim convallis aenean. Fermentum odio eu feugiat pretium nibh. Turpis tincidunt id aliquet risus feugiat in ante metus dictum. Vitae purus faucibus ornare suspendisse sed nisi. Aliquam sem fringilla ut morbi tincidunt augue. Diam sollicitudin tempor id eu nisl. Nascetur ridiculus mus mauris vitae ultricies leo integer. Aliquet enim tortor at auctor urna nunc. Praesent tristique magna sit amet purus gravida quis blandit turpis. Ac turpis egestas integer eget aliquet nibh. Mauris sit amet […] - [Privacy Policy](https://blog.iamarki.ai/privacy-policy-2/): ## 1. Privacy at a Glance ### General Information The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text. ### Data Collection on This Website **Who is responsible for data collection on this website?** The data processing on this website is carried out by the website operator. The operator’s contact details can be found in the Legal Notice of this […] ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/blog.iamarki.ai/mcp) [comment]: # (Generated by Hostinger Tools Plugin)