

As a security precaution, Okta will not issue more than five unbound certificates to a given device. Okta can issue up to five unbound certificates to the device, one each time you perform the enrollment procedure. Per-device unbound certificate limit: A certificate becomes bound to a given user the first time that user accesses a device trust-secured application from a device trust-secured macOS device.To prevent end users from being prompted for consent when the certificate is used in the authentication flow, Okta allows the following apps. The webview in which authentication is performed must have access to the Okta Keychain on the device. Webview must have access to the device keychain: Device Trust for managed macOS computers works with any SAML/WS-Fed-enabled app that supports authentication through a webview.
#Jamf pro mdm registration
(Note: Be aware that disabling syncing blocks all keychain transfers.) See the Add the modified Okta Device Registration Task to Jamf Pro and distribute it to macOS devices.
#Jamf pro mdm upgrade
If you have macOS 10.14.xx (Mojave) and are currently using registration script 1.2.1 or earlier, continue to use it as-is, or upgrade to Catalina, Big Sur, or Monterey before using Python 3.ĭevice Trust deployment is not renewed on devices that are not used to access secure applications.If you have macOS 10.15.xx (Catalina), 11.xx (Big Sur), or 12.xx (Monterey), use registration version 1.3.3 or later, which is based on Python 3.Depending on your OS, complete one of the following, to make sure you use the appropriate version of this script: The Okta Device Registration Task is a Python script that completes various tasks (for example, enrollment, and registration).The following browsers and native apps capable of accessing the Okta Keychain on the managed computer when performing the federated authentication flow to Okta:.Apple computers running Supported platforms, browsers, and operating systems of macOS.Okta Device Trust ensures that only known and secured devices can access your Okta-managed applications. Okta Device Trust for Jamf Pro managed macOS devices allows you to prevent unmanaged macOS devices from accessing corporate SAML and WS-Fed cloud apps. If you require the Python 2.x script, see Device Registration Task v1.2.1. Okta Device Registration Task v1.3.1 was released to support Python 3. Enforce Okta Device Trust for Jamf Pro managed macOS devices
