okta verify push notification not working
Fixes Okta Verify push notifications that never arrive so the user can complete MFA. Covers device registration, notification permissions, app version, and re-enrollment. Use when a user taps login and no push appears on their phone. Not for SMS or hardware-key MFA issues.
TL;DR
Open Okta Verify on the phone and confirm the account shows as enrolled. If enrolled, check the phone's notification permission for Okta Verify, update the app, and test with "Send push" from the Okta sign-in page. If it still fails, remove the enrollment in Okta Admin and re-enroll the device.
The error
We couldn't send a push notification to your device. Try again or choose another verification method.Steps
- On the phone, open Okta Verify and confirm the user's account is listed. Expected: the account appears with a green check. If missing, the enrollment is gone; skip to step 5.
- Check notification permission: Settings > Notifications > Okta Verify > Allow Notifications must be ON. Expected: toggles on. Pushes silently fail when this is off, the most common cause.
- Update Okta Verify to the latest version from the app store. Expected: version matches the current release. Stale versions lose push registration.
- On the Okta sign-in page, click "Send push" again and keep Okta Verify in the foreground. Expected: the approve/deny prompt appears within 10 seconds. Backgrounded apps on iOS can delay pushes.
- If still failing: in Okta Admin, go to Directory > People > the user > Security Methods, remove Okta Verify, then have the user re-enroll by scanning the QR code. Expected: the new enrollment sends a test push immediately.
When to use
- Push option selected but no notification arrives on the phone
- "We couldn't send a push notification" on the Okta sign-in page
- Pushes work on Wi-Fi but not on cellular (or vice versa)
When not to use
- The user never enrolled Okta Verify (use enrollment steps instead)
- SMS or voice-call MFA is failing (different delivery path)
- Pushes arrive but approval does nothing (likely a clock-skew issue)
Compatibility
- Okta Identity Engine; Okta Verify 9.x+ (iOS and Android)
- Applies to workforce Okta tenants, not Customer Identity Cloud
Variants
Push arrives late, after the code expired
Usually Do Not Disturb or battery optimization delaying the notification. Whitelist Okta Verify in battery settings.
"Device not recognized" after phone upgrade
The enrollment is bound to the old device. Remove the old security method and re-enroll on the new phone.
Why it happens
Push delivery depends on three links: Okta's push service, the Apple/Google push gateway, and the phone's notification permission. Any broken link produces the same silent failure, so the checklist works through them in order.
Edge cases
- Corporate MDM that blocks notification permissions: the MDM profile must allow them.
- Users with two phones: pushes go to the enrolled device only; check which device holds the enrollment.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_nHvm0ZsjG8bXlzQYnShB-g
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.