20% of the exam — the third-largest domain.
7 sub-topics · this deck covers sub-topic 1 of 7
↑ Module 1 OverviewMFA isn't one thing in Okta — it's a whole catalog of interchangeable factors, each with its own security properties. This sub-topic is about knowing that catalog and how to configure it.
Every authenticator falls into one of three categories:
Authenticators are also described by security properties, independent of category:
Okta offers 15+ authenticator options: passwords, security questions, email, phone, Smart Cards, YubiKey OTP, Okta Verify, Passkeys (FIDO2 WebAuthn), Duo Security, Google Authenticator, and temporary access codes, among others.
Admin setup: Security > Authenticators > add the Okta Verify tile > set an enrollment policy marking it Optional or Required.
Desktop support (macOS/Windows) is Identity Engine-only. Okta Verify is incompatible with Windows Autopilot's out-of-box experience (OOBE).
Admins also control release management (automatic app updates) and risk scoring (triggering extra authentication based on sign-in risk).
Watch for scenario questions built around this trap:
→ "Okta Verify needs to run during a Windows Autopilot device provisioning flow." = not compatible — known limitation.
Sources: help.okta.com — about-authenticators.htm · configure-okta-verify.htm
Next: Sub 2 →