Category Filter
 
 

Last updated: August 14, 2026

Configure Okta Device Trust for managed devices with Mobile Device Manager Plus

This guide walks administrators through configuring Okta Device Trust with Mobile Device Manager Plus to enforce conditional access across managed devices. By integrating Okta Device Trust with MDM, organizations can restrict access to work apps and Okta portal resources to only enrolled, attested devices on Android, iOS, macOS, and Windows. The page covers prerequisites such as device enrollment and Okta Device attestation, then details the three configuration steps: adding a CA policy, disabling the Catch All Rule, and adding applications.

Okta Device Trust is Okta's conditional access policy which evaluates whether a user who is seeking access to the Okta portal is authorized to access it.
Using Okta Device Trust with Mobile Device Manager Plus you can ensure only managed devices get access to your organization's work apps and other resources. Raise your workspace standards by ensuring a password less authentication policy for your users while enhancing corporate device security in a hybrid work environment.

Pre-requisite:

  • The device should be enrolled in MDM. Learn more about the different enrollment methods available in Mobile Device Manager Plus.
  • The devices should have Okta Device attestation. This can be achieved through App Configurations for Android and iOS, and SCEP profile for macOS and Windows respectively.

Steps

Follow the steps below to provision Okta Device Trust with Mobile Device Manager Plus:

  1. Adding CA Policy
  2. Disabling Catch All Rule
  3. Adding Apps

Adding CA Policy

Okta Dt 1 - ManageEngine MDM

  1. Login to the Okta portal , and under Security, go to Authentication Policies and click on Add Policy.

Okta Dt 2 - ManageEngine MDM

  1. Provide a name for the policy and click Save to proceed.

Okta Dt 3 - ManageEngine MDM

  1. Next click on Add Rule and give a name for the Rule.Then configure the rules as per your organization policies. To learn more about the authentication policy rules, click here.

Okta Dt 4 - ManageEngine MDM

  1. Ensure that the Device state is set as Registered, and correspondingly the Device Management state is set to Managed in the rule. Then click Save.

    Note:

    Confirm that the devices have Okta Device attestation before configuring the above rule.

Disabling Catch All Rule

The Catch All Rule is the last set of conditions which Okta will check before allowing or denying access to a device. This rule should be disabled to prevent the possibility of a device getting access thanks to complying with any of the pre-configured conditions under the Catch All Rule.


 

Okta Dt 5 - ManageEngine MDM

  1. Scroll down and click on Actions and choose Edit.

Okta Dt 6 - ManageEngine MDM

  1. After that under the THEN conditions, opt Denied, and click Save

Adding Apps

Okta Dt 7 - ManageEngine MDM

Next add the apps which should be provisioned with Device Trust. To do that, go to Applications and click on Add app. Then search and add the apps.

With this you can provision Okta Device Trust to the devices in your organization using Mobile Device Manager Plus.

Frequently Asked Questions

1. What is Okta Device Trust?

Okta Device Trust is Okta's conditional access policy that evaluates whether a user seeking access to the Okta portal is doing so from an authorized, compliant device before granting access.

2. What are the prerequisites for enabling Okta Device Trust with MDM?

The device must be enrolled in Mobile Device Manager Plus and must have Okta Device attestation configured, through App Configurations for Android and iOS, or an SCEP profile for macOS and Windows.

3. Why should I disable the Catch All Rule?

The Catch All Rule is the last set of conditions Okta checks before allowing or denying access. Disabling it prevents a device from getting access simply by falling through to this rule instead of meeting your configured device trust conditions.

4. Which platforms support Okta Device attestation through MDM?

Okta Device attestation is supported on Android and iOS through App Configurations, and on macOS and Windows through an SCEP profile.

Jump To