how to set up okta fastpass on managed devices
Sets up Okta FastPass for phishing-resistant passwordless sign-in on managed devices. Covers device assurance prerequisites, FastPass policy settings, and enrollment verification. Use when rolling out passwordless login on company-managed laptops or phones. Not for unmanaged or personal devices, which need different assurance handling.
TL;DR
FastPass lets users sign in with their device plus a biometric or PIN instead of a password plus a push, which kills credential phishing. It only works when Okta trusts the device, so the rollout is: confirm devices are managed with assurance signals flowing, enable FastPass on the Okta Verify authenticator, require it in the authentication policy, and pilot with a test user before going wide.
Steps
- Confirm the target devices are managed (MDM-enrolled for mobile, Okta-managed for desktop) and that device assurance signals are flowing to Okta. Expected: devices appear in Okta with a managed trust level.
- In Okta Admin go to Security > Authenticators > Okta Verify and configure FastPass: enable it and select the platforms in scope. Expected: FastPass shows enabled for the chosen platforms.
- Set the authentication policy: add a rule for the target users that requires Okta Verify with FastPass, or offers it as the preferred factor. Expected: the policy rule lists Okta Verify with FastPass enabled.
- Check device assurance policies do not block the fleet: disk encryption, minimum OS version, and jailbreak or root detection must pass for devices in scope. Expected: a test device passes every assurance check.
- Pilot: have a test user sign in on a managed device. Expected: Okta Verify prompts for a biometric or device PIN and no password is asked for. Expand the policy scope only after the pilot is clean.
Use this when
- Rolling out passwordless sign-in on company-managed devices
- Phishing-resistant MFA is required by policy or audit
- You want to reduce password-reset ticket volume
Not for this skill when
- Devices are unmanaged or personal (FastPass assurance does not apply the same way)
- The tenant is on Okta Classic Engine (FastPass needs Identity Engine)
- You only need standard push MFA (that is the regular Okta Verify setup)
Compatibility
- Okta Identity Engine, Okta Verify 9.x on iOS, Android, Windows, macOS
- Managed devices via your MDM or Okta device management
Variants
Rolling out to macOS desktops
Deploy Okta Verify for macOS through your MDM. Enrollment is per device profile, so verify the profile installed before testing sign-in.
Phased rollout by department
Scope the authentication policy rule to a pilot group first, then widen the group membership once the pilot is clean.
Why it happens
FastPass moves authentication from "something you know plus a push" to "a trusted device plus your biometrics." Attackers can phish passwords and even push approvals, but they cannot phish a device-bound cryptographic check. The managed-device requirement is what makes the trust meaningful.
Edge cases
- Users with both managed and unmanaged devices: scope the policy to managed devices so personal devices fall back to standard MFA.
- Shared or kiosk devices: FastPass is per-user enrollment, so shared devices need a different sign-in story.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_KiDrr-39PaNTqa0S1SCAaA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.