Enforcing Multifactor Authentication at the macOS Login Window with Okta Classic Engine

Jamf Connect Documentation

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Once two Jamf Connect applications have been created, it is necessary to make modifications to your Sign On or Authentication policies to properly enforce multifactor authentication (MFA) at the macOS login window.

Requirements
  • Access to your organization's Okta Classic Engine admin console.

  • Two separate Jamf Connect applications, one for password checks and another to support interactive logins at the macOS login window.

  1. Log in to the Okta Admin Console.
  2. Click Applications.
  3. Locate the Jamf Connect application that supports interactive logins at the macOS login window.
  4. Navigate to the Sign On tab.
  5. In the Sign On Policy section, click Add Rule.
  6. Enter a name for the rule in the Rule Name field.
  7. (Optional) Select values for People and Location.
  8. (Optional) Select macOS in the Client section and deselect any other values.
  9. Navigate to the Access section.
  10. Set the value for When all conditions above are met, sign on to this application is: to Allowed.
  11. Click the checkbox for Prompt for factor and the option for Once per session.

Users who have been assigned to your Jamf Connect application should now see a requirement for MFA as part of the login process.