thiagowfx's avatar

¬ just serendipity 🍀 (not just serendipity)

Okta: enroll into 2FA

• 153 words • 1 min • updated

⚠️ This post is over one year old. It may no longer be up to date or relevant. Opinions may have changed.

More specifically, enroll into 2FA other than OTP.

  • Log into https://{company}.okta.com/
  • Go to Settings (https://{company}.okta.com/enduser/settings)
  • Under “Security Key or Biometric Authenticator”, click “Set up another”
  • From this point, you could add either: — a hardware security key (e.g. YubiCo) — a passkey, which will be stored in your password manager, iCloud Keychain (Apple devices) or web browser profile

A hardware security key needs to be plugged in during authentication, when it needs to be gently tapped.

A passkey does not require external hardware, but it requires you to be logged into wherever it is stored (e.g. your password manager or your Apple ID).

What is the motivation to do this?

Previously, I would need to open up my laptop lid to touch ID, which is quite inconvenient in clamshell mode (i.e. with the laptop lid closed).

Now, touching the security key or signing in with the passkey eliminates the need to do so.