# Configure Okta Device Trust for managed devices with Mobile Device Manager Plus [Okta Device Trust](https://help.okta.com/en-us/content/topics/device-trust/device-trust-landing.htm) is Okta's [conditional access](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_conditional_access.html) policy which evaluates whether a user who is seeking access to the Okta portal is authorized to access it. Using Okta Device Trust with Mobile Device Manager Plus you can ensure only managed devices get access to your organization's work apps and other resources. Raise your workspace standards by ensuring a password less authentication policy for your users while enhancing corporate device security in a hybrid work environment. ## Pre-requisite: - The device should be enrolled in MDM. [Learn more](https://www.manageengine.com/mobile-device-management/help/enrollment/device_enrollment.html) about the different enrollment methods available in Mobile Device Manager Plus. - The devices should have **Okta Device attestation**. This can be achieved through App Configurations for [Android](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-for-android-devices.html) and [iOS](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-ios.html), and SCEP profile for [macOS](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-macos-devices.html) and [Windows](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-windows-devices.html) respectively. ## Steps Follow the steps below to provision Okta Device Trust with Mobile Device Manager Plus: 1. [Adding CA Policy](#adding-ca-policy) 2. [Disabling Catch All Rule](#disabling-catch-all-rule) 3. [Adding Apps](#adding-apps) ### Adding CA Policy ![Okta Device Trust Step 1](https://www.manageengine.com/mobile-device-management/help/profile_management/_drupal/mobile-device-management/images/Okta-DT-1.png) 1. Login to the **Okta portal**, and under **Security**, go to **Authentication Policies** and click on **Add Policy**. ![Okta Device Trust Step 2](https://www.manageengine.com/mobile-device-management/images/Okta-DT-2.png) 2. Provide a **name** for the policy and click **Save** to proceed. ![Okta Device Trust Step 3](https://www.manageengine.com/mobile-device-management/images/Okta-DT-3.png) 3. Next click on **Add Rule** and give a name for the **Rule**. Then configure the rules as per your organization policies. To learn more about the authentication policy rules, [click here](https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/add-app-sign-on-policy-rule.htm). ![Okta Device Trust Step 4](https://www.manageengine.com/mobile-device-management/images/Okta-DT-4.png) 4. Ensure that the **Device state** is set as **Registered**, and correspondingly the **Device Management** state is set to **Managed** in the rule. Then click **Save**. **Note:** Confirm that the devices have **Okta Device attestation** before configuring the above rule. ### Disabling Catch All Rule The **Catch All Rule** is the last set of conditions which Okta will check before allowing or denying access to a device. This rule should be disabled to prevent the possibility of a device getting access thanks to complying with any of the pre-configured conditions under the **Catch All Rule**. ![Okta Device Trust Step 5](https://www.manageengine.com/mobile-device-management/images/Okta-DT-5.png) 1. Scroll down and click on **Actions** and choose **Edit**. ![Okta Device Trust Step 6](https://www.manageengine.com/mobile-device-management/images/Okta-DT-6.png) 2. After that under the **THEN** conditions, opt **Denied**, and click **Save**. ### Adding Apps ![Okta Device Trust Step 7](https://www.manageengine.com/mobile-device-management/images/Okta-DT-7.png) Next add the apps which should be provisioned with Device Trust. To do that, go to **Applications** and click on **Add app**. Then search and add the apps. With this you can provision Okta Device Trust to the devices in your organization using Mobile Device Manager Plus.