## TL;DR
FastPass lets users sign in with their device plus a biometric or PIN instead of a password plus a push, which kills credential phishing. It only works when Okta trusts the device, so the rollout is: confirm devices are managed with assurance signals flowing, enable FastPass on the Okta Verify authenticator, require it in the authentication policy, and pilot with a test user before going wide.

## Steps
1. Confirm the target devices are managed (MDM-enrolled for mobile, Okta-managed for desktop) and that device assurance signals are flowing to Okta. Expected: devices appear in Okta with a managed trust level.
2. In Okta Admin go to Security > Authenticators > Okta Verify and configure FastPass: enable it and select the platforms in scope. Expected: FastPass shows enabled for the chosen platforms.
3. Set the authentication policy: add a rule for the target users that requires Okta Verify with FastPass, or offers it as the preferred factor. Expected: the policy rule lists Okta Verify with FastPass enabled.
4. Check device assurance policies do not block the fleet: disk encryption, minimum OS version, and jailbreak or root detection must pass for devices in scope. Expected: a test device passes every assurance check.
5. Pilot: have a test user sign in on a managed device. Expected: Okta Verify prompts for a biometric or device PIN and no password is asked for. Expand the policy scope only after the pilot is clean.

## Use this when
- Rolling out passwordless sign-in on company-managed devices
- Phishing-resistant MFA is required by policy or audit
- You want to reduce password-reset ticket volume

## Not for this skill when
- Devices are unmanaged or personal (FastPass assurance does not apply the same way)
- The tenant is on Okta Classic Engine (FastPass needs Identity Engine)
- You only need standard push MFA (that is the regular Okta Verify setup)

## Compatibility
- Okta Identity Engine, Okta Verify 9.x on iOS, Android, Windows, macOS
- Managed devices via your MDM or Okta device management

## Variants
### Rolling out to macOS desktops
Deploy Okta Verify for macOS through your MDM. Enrollment is per device profile, so verify the profile installed before testing sign-in.
### Phased rollout by department
Scope the authentication policy rule to a pilot group first, then widen the group membership once the pilot is clean.

## Why it happens
FastPass moves authentication from "something you know plus a push" to "a trusted device plus your biometrics." Attackers can phish passwords and even push approvals, but they cannot phish a device-bound cryptographic check. The managed-device requirement is what makes the trust meaningful.

## Edge cases
- Users with both managed and unmanaged devices: scope the policy to managed devices so personal devices fall back to standard MFA.
- Shared or kiosk devices: FastPass is per-user enrollment, so shared devices need a different sign-in story.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_KiDrr-39PaNTqa0S1SCAaA
