<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Force Okta Device Assurance Policy to Reprocess for Unmanaged Apple Devices

Okta Identity Engine
FastPass

Overview

Unmanaged Apple macOS, iOS, and iPadOS devices do not automatically send FastPass device signals during the normal device assurance sequence due to Apple's operating system design. To resolve this, administrators must configure specific authentication policy rules to manually trigger a device signal evaluation using Okta Verify FastPass. Without a Single Sign-On (SSO) extension installed, Apple devices do not perform the loopback checks that Okta Verify uses to trigger device signal gathering, causing the device assurance check to be skipped.

Applies To

  • Okta Identity Engine (OIE)
  • Device Assurance
  • Apple macOS
  • Apple iOS
  • Apple iPadOS

Cause

Apple designs its operating systems to skip automatic device signal checks. Without an SSO extension installed, Apple devices do not perform loopback checks. Okta Verify relies on these loopback checks to trigger device signal gathering.

Solution

How is an unmanaged Apple device evaluated for device assurance?

 

To manually trigger a device signal evaluation, the user must invoke Okta Verify FastPass after Okta denies the device. Configure the authentication policy rules to force a manual evaluation by establishing the following rule sequence.

  • Create an allow policy rule with device assurance enforced for the specific device.
  • Create a deny policy rule for the same device directly following the device assurance rule.
  • Create an allow policy rule immediately following the deny rule that includes the device if it is not registered.

 

NOTE: Authentication chaining is not required.

 

Review the following example of the required authentication policy rules.

Device assurance

 

What occurs during the login process?

 

During the login process, Okta evaluates the authentication policy rules and triggers a fresh evaluation when the user selects FastPass.

  1. Okta evaluates the login and polls for device assurance.
  2. Unmanaged Apple devices do not automatically present device signals, causing Okta to skip the device assurance rule and the deny rule.
  3. Okta presents the user with sign-in options, including FastPass.
  4. The user selects FastPass, which manually invokes the application, sends device signals, and triggers a fresh evaluation of the authentication policy rules.
Loading
Okta Support - Force Okta Device Assurance Policy to Reprocess for Unmanaged Apple Devices