# Configure Persona with Okta Device Access (ODA)

> Integrate Persona Identity Verification with Okta Device Access to verify employee identity during laptop provisioning and zero-touch onboarding.

Source: https://help.withpersona.com/articles/yRpqxoMHSLC3AVlwyN2LgX/
Section: Marketplace and 3rd-Party Integrations > Authentication > Okta

## What is Okta Device Access?

[Okta Device Access](https://www.okta.com/products/device-access/) (ODA) extends Okta Workforce Identity Cloud to endpoint operating systems across macOS and Windows.

Organizations can require identity verification during initial device enrollment or zero-touch provisioning, before the user is permitted to bind the device, establish local account credentials, or access enterprise resources. Common enrollment paths include Jamf Pro, Jamf Connect, Microsoft Intune, Windows Autopilot, and Apple Automated Device Enrollment (macOS Setup Assistant).

ODA handles enrollment using Okta's standard web-based sign-in flow directly on the endpoint, which evaluates whatever Account Management Policy already governs that user's sign-in. Thus, [Persona's standard Okta integration with OAMP](https://help.withpersona.com/articles/x7vPGY4te68wp1T0Ce5eFi/) works out of the box with Okta Device Access enrollment, without requiring custom desktop plugins or external agents.

### Use cases

- **Remote employee onboarding:** Prevent high-value corporate hardware shipped directly to a remote hire from being intercepted, set up, or compromised by an unauthorized actor.
- **Privileged endpoint issuance:** Enforce step-up biometric verification when provisioning devices for administrators or high-security roles.
- **Contractor and BYOD access:** Gate corporate desktop access or management profile enrollment behind a verified government ID.
- **Endpoint account recovery and Desktop MFA:** Re-verify employee identity for account recovery workflows or elevated lock-screen re-authentication on existing workstations.

### How it works

1. **Enrollment trigger:** A user powers on an unprovisioned laptop. On macOS, Platform Single Sign-On hands the setup session to Okta; on Windows, Autopilot delegates initial sign-in to Okta.
2. **Sign-in widget:** Okta's standard web-based Sign-In Widget appears directly in the endpoint setup flow and evaluates the Account Management Policy that already governs that user's sign-in.
3. **Embedded verification:** Because Persona is configured as an Identity Provider (IDV) authenticator on that policy, the user is routed to Persona to verify their government ID and take a selfie before local credentials or device profiles are created.
4. **Provisioning completion:** Once Persona validates the user and passes the verification claim back to Okta, Okta allows the enrollment agent to complete device binding and issue desktop tokens.

---

## Prerequisites

Before configuring Okta Device Access with Persona:

- Ensure your Okta tenant runs on Okta Identity Engine (OIE) with Okta Device Access enabled.
- Configure Persona as an Identity Verification Provider in Okta. For setup instructions, see [Configure Persona for the Okta Account Management Policy](https://help.withpersona.com/articles/x7vPGY4te68wp1T0Ce5eFi/).
- Create an Inquiry Template configured for employee onboarding that collects a government ID and a live selfie.

---

## Configure your Persona Inquiry Template

When configuring the Inquiry Template used for Okta Device Access, we recommend enabling **Use native mobile app flow** so users complete verification on their mobile device.

During out-of-the-box machine setup, the operating system runs Okta inside a locked-down, embedded system webview rather than a full browser. These captive environments cause issues for desktop-based verification:

- **No camera permissions:** Locked-down provisioning webviews may block hardware camera access, preventing users from capturing an ID or taking a selfie on the laptop webcam.
- **Biometric degradation:** Laptop webcams lack the resolution, focus control, and dynamic range of smartphone cameras, increasing verification friction and drop-off.
- **Sandbox constraints:** Provisioning webviews often restrict file uploads and local session storage.

Enabling **Use native mobile app flow** avoids these limitations by directing the user to complete verification on their mobile device.

1. In the Persona Dashboard, navigate to **Inquiries** > **Templates** and open your employee verification template.
2. In the upper corner of the Flow Editor, click **Configure**.
3. Under the **Device handoff** tab, enable **Use native mobile app flow**.
4. Save and publish your template changes.

---

## Connect your MDM to Okta Device Access

Okta Device Access doesn't add a separate identity-verification rule to Authentication Policies. Instead, connect your device enrollment tool to Okta so it hands off to the Account Management Policy you already configured with the Persona IDV authenticator.

1. In your MDM (such as Jamf Pro or Jamf Connect on macOS, or Microsoft Intune on Windows), configure the device enrollment profile to use Platform Single Sign-On or Okta Device Access, pointing to your Okta org.
2. Assign your new-hire or device-provisioning user groups to the Account Management Policy that requires the Persona IDV authenticator (see [Configure Persona for the Okta Account Management Policy](https://help.withpersona.com/articles/x7vPGY4te68wp1T0Ce5eFi/)).
3. Deploy the enrollment profile to your device-provisioning device groups.

---

## End-user enrollment flow

1. **Power on machine:** The employee turns on their new laptop and connects to Wi-Fi.
2. **Setup prompt:** The operating system launches Apple Automated Device Enrollment, Jamf Connect, or Windows Autopilot and prompts the employee to sign in with Okta.
3. **Identity verification:** Okta prompts the employee to verify their identity with Persona.
4. **Mobile handoff:** Persona displays a QR code on the laptop screen. The employee scans the code to open the verification flow on their smartphone (on iOS via App Clip with no install; on Android via the Persona Wallet app).
5. **ID and selfie capture:** The employee captures their government ID and takes a live selfie on mobile.
6. **Machine unlocks:** Persona confirms the verification with Okta. The laptop screen advances automatically, allowing the enrollment agent to create the local account and complete device provisioning.

---

## Troubleshooting

### Webcam or camera does not launch on the laptop screen

The locked-down provisioning environment (Windows OOBE or macOS Setup Assistant) may have blocked hardware camera permissions. Enable **Use native mobile app flow** under the **Device handoff** tab in your Persona Inquiry Template so employees verify via a mobile device instead of the laptop webcam.

### Session times out during laptop setup

Okta applies a standard 10-minute window to complete the identity verification step once it starts. If an employee takes too long to locate their ID or complete the mobile flow, the session expires. Instruct the employee to restart the enrollment step to generate a fresh session and QR code.

---

## Plans Explained

### Okta Integration by plan

|                  | Startup Program | Essential Plan | Growth Plan | Enterprise Plan |
| ---------------- | --------------- | -------------- | ----------- | --------------- |
| Okta Integration | Not Available   | Not Available  | Limited     | Available       |

[Learn more about pricing and plans](https://withpersona.com/pricing?utm_source=product&utm_medium=referral&utm_audience=a&utm_campaign=cm_gen_ds_hc-plan-table).
