Last updated: July 24, 2026
This guide explains how to enable Okta Device Attestation for iOS devices managed through Mobile Device Manager Plus, needed for Okta SSO extension provisioning and Okta Device Trust. Administrators add an iOS device platform in Okta to obtain a secret hint and org URL, insert these values into a provided XML configuration template, then upload that XML as a Managed App Configuration for the Okta Verify app in App Repository before distributing it to devices. Users complete attestation by adding their account to Okta Verify and signing in with their organization credentials.
Managed devices should be attested by Okta for provisioning SSO extension with Okta and Okta Device Trust. Attestation can be achieved for iOS devices by configuring a managed app with a management hint (shared secret) that is sent to the device through Mobile Device Manager Plus .
To ensure an iOS device is managed, Okta checks if it has a secret hint. To obtain the secret hint, the administrator or technician must first add Mobile Device Manager Plus to Okta and get the secret hint. Then this secret hint should be added to the MDM App configuration, and the app should be distributed to the managed device(s). Learn more about secret hint by visiting Okta's documentation on Managed app configurations for iOS devices.

Follow the detailed steps specified below to configure Okta Device Trust for iOS devices




The next step is to distribute the Okta Verify app to the devices. For iOS, the app can be added using ABM server tokens or using the App Store in the MDM App repository. For adding configuration to the app follow the steps below:

It's needed for provisioning the SSO extension with Okta and for Okta Device Trust — Okta checks that a managed app on the device carries a management hint (shared secret) sent through Mobile Device Manager Plus.
In Okta, go to Security > Device Integrations > Add Platform and choose iOS, then copy the Secret key and organization URL from the Okta dashboard.
Paste them into the provided XML configuration template in place of the Paste_your_org_url_here and Paste_your_secret_hint_here placeholders, save the file, then upload it as the Managed App Configuration for the Okta Verify app in App Repository.
They add their account to Okta Verify and sign in at least once with their organization credentials after the app and its configuration are distributed.