<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Verify Sign-in Failures on Android 17 - Cross-Profile Loopback Traffic Restriction

Okta Identity Engine
Okta Verify

Overview

Android 17 enforces a network isolation change that blocks cross-profile loopback traffic by default. This affects customers using Okta Verify (OV) in managed Android environments with work profiles, specifically in two scenarios: MDM enrollment flows that require FastPass sign-in as part of work profile creation, and authentication flows from productivity apps installed in a profile different from the Okta Verify application. 

     

This behavior is consistent with Android's long-standing design principle that applications in the personal profile and work profile should not communicate directly across profile boundaries. Android 17 now enforces this at the network level.

 

Applies To

  • Okta Verify for Android on Android 17 and later
  • Customers using MDM (Mobile Device Management) with Android Work Profile
  • Customers with Okta FastPass 
  • Environments where Okta Verify is installed in the personal profile and accessed from the work profile

Cause

Beginning with Android 17, Google blocks cross-profile loopback traffic by default for all apps, regardless of target API level. Okta Verify Fastpass relies on loopback-based invocation, which is no longer permitted across profile boundaries. This results in two distinct failure scenarios:

  

Scenario 1 — MDM Enrollment

When the Identity Provider (IdP) sign-in is required as part of the work profile creation process and Okta policies enforce FastPass, a chicken-and-egg problem occurs: the work profile does not yet exist, so Okta Verify cannot be invoked to satisfy authentication, and enrollment cannot complete.

  

Scenario 2 — Cross Profile Authentication

Customers who have Okta Verify installed in the personal profile and use productivity applications in the work profile will no longer be able to invoke Okta Verify across profiles. Android 17 enforces the profile boundary, and cross-profile invocation of Okta Verify is not supported on Android 17 or later. Okta Verify must be in the same profile as the productivity applications.



Solution

To address this issue, use the following workaround:

  1. Create a dedicated enrollment policy group with a relaxed authentication policy that does not require FastPass and uses factors like push notifications.
  2. Place users undergoing Android work profile enrollment into this group.
  3. Once enrollment is complete and Okta Verify is registered within the work profile, move the user to the standard group that enforces the FastPass factor.
  4. For ongoing use, ensure Okta Verify is installed and registered within the work profile. Relying on Okta Verify in the personal profile to authenticate work profile apps is now blocked as originally intended. 

 

Okta is actively engaging with Google to address this at the OS or platform level and will provide updates as they become available.



Loading
Okta Support - Okta Verify Sign-in Failures on Android 17 - Cross-Profile Loopback Traffic Restriction