Okta: Bypassing Multifactor Authentication

Jamf Connect Documentation

Solution
Application
Jamf Connect
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

You can configure your base Okta Sign On policy to bypass multifactor authentication (MFA) requirements for all devices that are using Jamf Connect's Zero Trust Network Access.

This configuration effectively replaces app or SMS-based factors with "Zero Trust Network Access as a Factor"; meaning that the presence of the Zero Trust Network Access app on a device with Zero Trust Network Access running is considered to be an authentication factor when logging in.

Other devices that do not use Zero Trust Network Access for routing will continue to use your existing MFA policies.
Note:

This feature is not a replacement for end-user authentication. Users must still authenticate with their credentials as defined in Okta.

This configuration also does not impact the users or groups authorized to use any given application.

Steps include:

  1. Configuring Jamf Security Cloud

  2. Configuring Okta

  3. Testing Okta Login with Jamf Trust as a Factor

  4. Testing SSO App Login with Jamf Trust as a Factor