← Course Home
Okta Certified Administrator · Part I

Security

20% of the exam — the third-largest domain.

Security

Module 1: Okta Security Policy & Enforcement Framework

7 sub-topics · this deck covers sub-topic 1 of 7

↑ Module 1 Overview

The Exam Bullet

"Manage authenticators and profiles"

MFA isn't one thing in Okta — it's a whole catalog of interchangeable factors, each with its own security properties. This sub-topic is about knowing that catalog and how to configure it.

The Mechanism — Factor Categories

Every authenticator falls into one of three categories:

Possession — something the user owns (phone, email account)
Knowledge — something the user knows (password, security question)
Biometric — a physical attribute a device can scan (fingerprint, face)

Method Properties

Authenticators are also described by security properties, independent of category:

Device-bound · Hardware-protected · Phishing-resistant · User presence · User verifying

Okta offers 15+ authenticator options: passwords, security questions, email, phone, Smart Cards, YubiKey OTP, Okta Verify, Passkeys (FIDO2 WebAuthn), Duo Security, Google Authenticator, and temporary access codes, among others.

Okta Verify Specifics

Admin setup: Security > Authenticators > add the Okta Verify tile > set an enrollment policy marking it Optional or Required.

Desktop support (macOS/Windows) is Identity Engine-only. Okta Verify is incompatible with Windows Autopilot's out-of-box experience (OOBE).

Admins also control release management (automatic app updates) and risk scoring (triggering extra authentication based on sign-in risk).

The Exam Angle

Watch for scenario questions built around this trap:

→ "Okta Verify needs to run during a Windows Autopilot device provisioning flow." = not compatible — known limitation.

One Line To Remember

Authenticators split into 3 factor categories (possession/knowledge/biometric) with 5 method properties (device-bound, hardware-protected, phishing-resistant, user presence, user verifying). 15+ options exist. Okta Verify: Optional/Required enrollment policy, OIE-only desktop support, incompatible with Windows Autopilot OOBE.

Sources: help.okta.com — about-authenticators.htm · configure-okta-verify.htm