
MonteD.49528 (Customer) asked a question.
Passwordless Offline Biometrics for Desktop MFA
We are using Okta Verify for Windows v6.11.1.0 for Desktop MFA. We have been frustrated that the offline login has required a password because we want to be fully passwordless. We are excited about the new offline biometrics for desktop MFA feature that's in EA and we're trying to make it work. According to the documentation, enabling one or both and using the correct registry keys will actually make the offline login fully passwordless and users can login using only their face or fingerprint if they're offline.
We can't get it to skip the password prompt while offline though. Everything else works great. We believe we have all the right registry keys. Has anybody been able to make this work yet, or do we just need to wait for the next round of bug fixes since this feature is EA?
At HKLM\SOFTWARE\Policies\Okta\Okta Device Access we have the following keys:
- AllowedFactors = OV_Push Offline_TOTP Offline_Fingerprint Offline_FaceBio
- CredProvidersToExclude = {D6886603-9D2F-4EB2-B667-1971041FA96B} {BEC09223-B018-416D-A0AC-523971B639F5} {8AF662BF-65A0-4D0A-A540-A338A999D36F}
- OktaJoinEnabled = 1
- PasswordlessAccessEnabled = 1
- PrioritizeBiometrics = 1
- OfflineLoginAllowed = 1
At HKLM\SOFTWARE\Okta\Okta Device Access we have:
- UseDirectAuth = 1
- OrgURL, and obscured client ID and secret

Hi @MonteD.49528 (Customer) , Thank you for reaching out to the Okta Community!
Your configuration looks correct and I haven't seen any similar reports.
The only thing I can think of is the "PasswordlessAccessEnabled" registry key description mentioning that
"Password autofill supports Okta Verify Push, FIDO2 keys and Windows Hello biometrics when you specify these as AllowedFactors. Desktop MFA always attempts to enforce user verification through the FIDO2 key PIN. If the key doesn't have a PIN, then Desktop MFA falls back to password authentication."
If you continue experiencing issues with the implementation, please open a case to work with our colleagues from the Okta Support team. They can set up a meeting go over the configuration with you.
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Securing AI agents across your org? Join our upcoming Ask Me Anything on 8/5 about Okta for AI Agents. Ask our expert questions.