Okta Device Trust: Add Device Platforms

By Jonathan Connor

Learn how to add, configure, and manage device integrations in Okta for macOS and iOS

This article is used in conjunction with the Okta Device Trust: Integration Setup support article.

Adding device integrations in Okta

  1. Log in to the Okta admin portal
  2. In the left-hand navigation, click Security > Device Integrations
  3. Click Add platform

Add macOS as a device integration

  1. On the Select platform step, select Desktop (Windows and macOS only), click Next
  2. On the Configure management attestation step, for Certificate authority, select Use Okta as certificate authority
  3. For SCEP URL challenge type, select Dynamic SCEP URL and Generic
  4. Next to SCEP URL, click the Generate button

    Copy the SCEP URL, Challenge URL, Username, and Password to a safe place. This info will be used later in Kandji when setting up macOS as a device platform

    Please copy the password, as it will be the only time you can view it. You can rotate the password later in the  menu from the main Device integrations page in Okta if needed.

  5. Click Save.

Add iOS as a device integration

  1. On the Select platform step, select iOS, click Next
  2. On the Configure management attestation step, copy the Secret key to a safe place for use later in Kandji when adding iOS as a device platform in Kandji

    Please copy the Secret key, as it will be the only time you can view it. You can rotate the password later in the  menu from the main Device integrations page in Okta if needed.

  3. For Device management provider, enter some like Kandji MDM
  4. For Enrollment link, enter your Kandji tenant’s device enrollment link (https://subdomain.kandji.io)
  5. Click Save

Modifying a device integration in Okta

Rotate a macOS challenge password or iOS Secret

  1. Go to the Device Integrations page
  2. Next to the integration that you want to change, click the Actions menu
  3. Click the reset option for that platform
  4. Click the Reset button in the modal that appears

Delete a macOS challenge password or iOS Secret

  1. Go to the Device Integrations page
  2. Next to the integration that you want to change, click the Actions menu
  3. Click Delete
  4. Click the Delete button in the modal that appears