About Passport with Okta
Passport with Okta enables users to log into Mac computers using their Okta credentials instead of separate local passwords. This integration streamlines authentication by connecting your Okta identity provider directly to macOS login.How It Works
Passport integrates with your Okta organization to authenticate users at the macOS login screen. When users enter their Okta credentials, Passport verifies them against your Okta tenant and creates or updates the local Mac user account accordingly.- Okta
- Iru Endpoint
Okta Application Configuration
When configuring the Passport Library Item, you need the Client ID and Identity provider URL. In Okta, the client identifier may be labeled Application ID. Use these steps to configure the OIDC app and collect the required information.Access Applications
Create App Integration
Select Sign-in method
Select Application Type
Continue to next step
Enter app name
Configure Grant type
Access Advanced options when using OIE
Select Resource Owner Password
Add redirect URI
Enter redirect URI

Configure assignments
Save configuration

Collecting Configuration Details
Prepare secure document
Copy Client ID

Store Client ID
Copy Identity provider URL formula
Store Identity provider URL
Replace domain placeholder
Enable Multi-Factor Authentication
When you use MFA with Passport, update Okta and the Passport Library Item. For more on how they can differ, see Okta’s Differences Between Okta Classic and OIE article. Expand the section for your Okta engine, or use the Okta Identity Engine or Classic Engine links.Okta Identity Engine, OIE
Okta Identity Engine, OIE
Access Security section
Open Authenticators
Verify MFA methods
Add authenticator when needed

Select authenticator

Complete setup
Confirm addition
Access Security section
Open Global Session Policy
Create or edit policy
Edit existing Default Policy

Set MFA requirement
Set MFA prompt frequency

Save policy
Access Security section
Open Authentication Policies
Access Applications
Switch policy for Passport
Select Password only policy
Save policy

Classic Engine
Classic Engine
Access Security section
Open Authentication
Access Sign On
Add new policy

Configure policy details
Add policy description
Select groups
Create policy

Enter rule name
Set MFA requirement
Set MFA frequency

Create rule

Configure the Group Claim Filter in Okta
In your Passport OIDC application, configure the Groups claim filter so Okta sends the group claims Passport expects. This article uses names starting with Mac- as an example.Access Applications
Select Passport application
Open Sign On tab
Edit ID Token

Configure Groups claim filter
Set filter condition
Enter group prefix
Save configuration



