Enabling Multifactor Authentication for Okta Classic Engine

Jamf Connect Documentation

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

If you want to enable multifactor authentication (MFA) while using Okta Classic Engine as your identity provider, you must enable MFA at the organization level rather than the app level. Enabling MFA at the app level may cause errors in Jamf Connect.

Requirements

Access to your organization's Okta Classic Engine admin console.

  1. Log in to the Okta Admin console.
  2. Navigate to Security and click Authentication.
  3. Click the Sign on tab.
  4. Click Add New Okta Sign-On Policy.
  5. Create a name and description for the policy.
  6. Assign the policy to a group of users you want to enable MFA for.
  7. Create a new rule.
    1. Create a name for the rule.
    2. Select the options for Policy settings that correspond with your organization's needs.
    3. In the Authentication section, set Users will authenticate with to Password / Any IdP + Any Authenticator and Users will be prompted for MFA to At every sign in or When signing in with a new device cookie.
    4. Select the options for Session Lifetime that correspond with your organization's needs.
    5. Click Create rule.

The group selected in your sign-on policy will have MFA applied corresponding to the rule's guidelines. Repeat these steps as needed to create additional policies and rules for additional groups of users.