---
source_url: "https://support.kandji.io/kb/okta-device-trust-integration-setup"
title: "Okta Device Trust: Integration Setup"
mirrored_at: 2026-08-06T03:40:07.378Z
host: support.kandji.io
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/support.kandji.io/kb/okta-device-trust-integration-setup"
---

> **Original source:** https://support.kandji.io/kb/okta-device-trust-integration-setup

### Overview

Okta Device Trust allows admins to ensure that Kandji manages their Apple devices before end users can access Okta-protected apps from their devices. This, in part, enables Okta FastPass for a passwordless authentication experience for end users, enabling them to sign in to Okta and their Okta resources without needing a password. For iOS, iPadOS, and macOS devices specifically, FastPass allows users to leverage Face ID and Touch ID to access resources. Okta FastPass is a feature of Okta Identity Engine.

### Prerequisites

During the integration setup process, Kandji will check for the presence of the following items. These items must be configured in the Okta tenant before setting up the ODT integration with Kandji. A warning modal will be displayed if Kandji finds one or more of these items missing.

-   The Okta tenant must be migrated from Okta Classic Engine to [Okta Identity Engine](https://help.okta.com/oie/en-us/content/topics/identity-engine/oie-index.htm)
    
-   [Okta FastPass](https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/fp/fp-main.htm) must be enabled in the Okta tenant
    
-   The Okta Verify Apple App Store app must be assigned to Kandji via [Apps and Books in Apple Business Manager](https://support.kandji.io/v1/docs/add-apps-from-apps-and-books-to-kandji).
    
-   The Okta user setting ODT should have the [super admin](https://help.okta.com/oie/en-us/content/topics/security/administrators-super-admin.htm) in Okta. The super admin credentials are only needed for the initial authentication and adding if the API Service Integration.
    
-   [Okta Adaptive MFA](https://www.okta.com/products/adaptive-multi-factor-authentication/) is required in order to add Device integrations in Okta.
    

### Integration setup

1.  Login to your Kandji tenant.
    
2.  Navigate to **Integrations**
    
3.  Click **Discover Integrations**.
    
4.  In the Security section, find **Okta Device Trust**.
    
5.  Click **Add and configure**. ![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/Kandji-Support-KB-0349PM@2x.png)
    
6.  In the **Welcome to Okta Device Trust** modal, click **GetStarted**. ![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/-h2ipzfta5op__b4skp6h1g29ocrgg8apw.png)
    
7.  In the **Specify your Okta Domain** modal, enter your Okta tenant URL and click **Next**.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/Aa7o9tg22ia2oOZcbA71uMsLDAzDcNChpg.png)
    
8.  In the **Sign in with Okta** modal, click **Sign in with Okta**. This will open a new browser window and navigate you to your Okta tenant, where you will create an **API Service Integration**. Once that is done, you will return to Kandji to continue the ODT integration setup.
    
    > The Okta user used to configure ODT must have the [super admin](https://help.okta.com/oie/en-us/content/topics/security/administrators-super-admin.htm) role in Okta.
    
      
    ![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/hnghnbab7fydb9lil0vjk0fv4ghgkt1aha.png)
    
9.  Once signed into Okta, you should be on the **Authorize Kandji Device Trust** integration page. On this page, click **Install & Authorize**. The Kandji API Service integration uses the following scopes:
    
    -   okta.devices.manage
        
    -   okta.devices.read
        
    -   okta.authenticators.read![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/8NgL3wV64G57n0soqWfVDM4SDzydIGOSZw.png)
        
10.  On the **Copy your client secret** modal, copy the client secret to a safe place for use later in Kandji. This is the only time you will be able to view it.
     
11.  Click **Done**.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/SImdJH3ljR1vAZ3s26939tnuxLUm7ogtVA.png)
     
12.  On the **Kandji Device Trust** overview page, copy the **Client ID** to a safe place for use later in Kandji.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/5__C7v7U75qoRisC_x98G0PveJIOZKsShw.png)
     
13.  Head back to Kandji to continue the ODT integration setup.
     
14.  In the **Complete the following tasks in Okta** modal, click **Next**.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/xgjl5qa-cr05jh4xpajmbvtg97-uxlby0g.png)
     
15.  In the **API Service Integration Credentials** modal, enter the Client ID and Client Secret copied from earlier.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/-nVlePSwFCl9XqYmpVEsWEh_BcturelE9Q.png)
     
16.  Click **Connect to Okta**. Kandji will check in the background to ensure the Okta tenant is on Okta Identity Engine and Okta FastPass is enabled.
     

### Configuring device platforms in Okta

This section outlines creating device integration in Okta. This information is used when adding device platforms in Kandji.

> Okta [Adaptive MFA](https://www.okta.com/products/adaptive-multi-factor-authentication/) is required in order to add Device integrations in Okta.

#### Adding device integrations in Okta

1.  Log in to the Okta admin portal
    
2.  In the left-hand navigation, click **Security > Device Integrations**
    
3.  Click **Add platform![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/0po_qpbj4vgvgxyqh1cpo6pz5eqyntlcnq.png)**
    

#### Add macOS as a device integration

1.  On the **Select platform** step, select **Desktop (Windows and macOS only)**.
    
2.  Click **Next**. ![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/yoazks_5exutjs7to8ejfnxubukecoqk7w.png)
    
3.  On the **Configure management attestation** step, select **Use Okta as certificate authority**
    
4.  For **SCEP URL challenge type**, select **Dynamic SCEP URL** and **Generic**.
    
5.  Next to **SCEP URL**, click **Generate**.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/vbot3xcup6yaqmjsw76dfbw5_7frmgzsya.png)
    
6.  Copy the SCEP URL, Challenge URL, Username, and Password to a safe place.  Later, in Kandji, this information will be used to set up MacOS as a device platform.
    
    -   This will be the only time you can view the password. If needed, you can rotate it later in the menu from the main Device integrations page in Okta
        
7.  Click **Save**.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/6xubce93gnicjj0jc3pyx_kajbz-e5nmpa.png)
    

#### Add iOS as a device integration

1.  On the **Select platform** step, select **iOS**.
    
2.  Click **Next**.**![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/rxev3zsshhbpvdqsu3cbpp7v1rcdj3fpvw.png)**
    
3.  On the **Configure management attestation** step, copy the **Secret key** to a safe place for use later in Kandji when adding iOS as a device platform in Kandji.
    
    -   This will be the only time you can view the secret key. If needed, you can rotate the key later in the menu from the main Device integrations page in Okta.
        
4.  For **Device management provider**, enter a descriptive, user-friendly value.
    
5.  For **Enrollment link**, enter your Kandji tenant’s device enrollment link. (Example: `https://accuhive.kandji.io/enroll` where `accuhive` should be your tenant subdomain.)
    
6.  Click **Save**![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/oakHzdQE3VX_-ko8Z_FP5D2AeIZfnfNFCg.png)
    

### Modifying a device integration in Okta

#### Rotate a macOS challenge password or iOS Secret

1.  Go to the Device Integrations page
    
2.  Next to the integration that you want to change, click the **Actions** menu
    
3.  Click the reset option for that platform
    
4.  Click the **Reset** button in the modal that appears
    

#### Delete a macOS challenge password or iOS Secret

1.  Go to the Device Integrations page
    
2.  Next to the integration that you want to change, click the **Actions** menu
    
3.  Click **Delete**
    
4.  Click the **Delete** button in the modal that appears
    

### Configuring device platforms in Kandji

1.  In the **Configure device platforms** modal, select the platforms to configure. You can configure macOS, iOS, or both.
    
2.  Click **Next**. ![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/lq0onohu6episkot9pkpo3beomyvj7zhya.png)
    
3.  If selecting macOS, enter the required information in the **Add macOS as a device platform** modal and click **Next**.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/GvTUUqtDftYVTsCP63tmsLPIv8mh-PXTmQ.png)
    
4.  If selecting iOS, enter the required information in the **Add iOS as a device platform** modal and click **Finish setup**.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/M6ByI5w2nl9T-QZ_mFfqJ8Ip2f2KDy4QtA.png)
    
5.  In the **Okta Device Trust setup complete** modal, you can choose **View integration settings** to see additional information about the ODT integration in Kandji or choose **Go to Library item** to configure the Okta Verify app for ODT deployment.![](https://cdn.document360.io/0844b095-d720-4a7b-bb17-ec97d9bc6e41/Images/Documentation/XCY7qYJ8vSaJWQmSMGOrgnn90Hm0fkDHJA.png)
    

### Up next

Deploy ODT to your Apple devices using the [Okta Device Trust: Configuring the Okta Verify Library item](https://support.kandji.io/v1/docs/okta-device-trust-configuring-the-okta-verify-library-item) support article.