# Configure Okta Device Trust for managed devices with Mobile Device Manager Plus Last updated: August 14, 2026 This guide walks administrators through configuring Okta Device Trust with Mobile Device Manager Plus to enforce conditional access across managed devices. By integrating Okta Device Trust with MDM, organizations can restrict access to work apps and Okta portal resources to only enrolled, attested devices on Android, iOS, macOS, and Windows. The page covers prerequisites such as device enrollment and Okta Device attestation, then details the three configuration steps: adding a CA policy, disabling the Catch All Rule, and adding applications. [Okta Device Trust](https://help.okta.com/en-us/content/topics/device-trust/device-trust-landing.htm) is Okta's [conditional access](https://www.manageengine.com/mobile-device-management/help/profile_management/mdm_conditional_access.html) policy which evaluates whether a user who is seeking access to the Okta portal is authorized to access it. Using Okta Device Trust with Mobile Device Manager Plus you can ensure only managed devices get access to your organization's work apps and other resources. Raise your workspace standards by ensuring a password less authentication policy for your users while enhancing corporate device security in a hybrid work environment. ## Pre-requisite: - The device should be enrolled in MDM. [Learn more](https://www.manageengine.com/mobile-device-management/help/enrollment/device_enrollment.html) about the different enrollment methods available in Mobile Device Manager Plus. - The devices should have **Okta Device attestation**. This can be achieved through App Configurations for [Android](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-for-android-devices.html) and [iOS](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-ios.html), and SCEP profile for [macOS](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-macos-devices.html) and [Windows](https://www.manageengine.com/in/mobile-device-management/how-to/okta-device-attestation-windows-devices.html) respectively. ## Steps Follow the steps below to provision Okta Device Trust with Mobile Device Manager Plus: 1. [Adding CA Policy](https://www.manageengine.com/mobile-device-management/help/profile_management/okta_device_trust.html#adding_ca_policy) 2. [Disabling Catch All Rule](https://www.manageengine.com/mobile-device-management/help/profile_management/okta_device_trust.html#disabling_catch_all_rule) 3. [Adding Apps](https://www.manageengine.com/mobile-device-management/help/profile_management/okta_device_trust.html#adding_apps) ### Adding CA Policy ![Okta Dt 1 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/profile_management/_drupal/mobile-device-management/images/Okta-DT-1.png) 1. Login to the **Okta portal**, and under **Security**, go to **Authentication Policies** and click on **Add Policy**. ![Okta Dt 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/images/Okta-DT-2.png) 1. Provide a **name** for the policy and click **Save** to proceed. ![Okta Dt 3 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/images/Okta-DT-3.png) 1. Next click on **Add Rule** and give a name for the **Rule**. Then configure the rules as per your organization policies. To learn more about the authentication policy rules, [click here](https://help.okta.com/oie/en-us/content/topics/identity-engine/policies/add-app-sign-on-policy-rule.htm). ![Okta Dt 4 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/images/Okta-DT-4.png) 1. Ensure that the **Device state** is set as **Registered**, and correspondingly the **Device Management** state is set to **Managed** in the rule. Then click **Save**. **Note:** Confirm that the devices have **Okta Device attestation** before configuring the above rule. ### Disabling Catch All Rule The **Catch All Rule** is the last set of conditions which Okta will check before allowing or denying access to a device. This rule should be disabled to prevent the possibility of a device getting access thanks to complying with any of the pre-configured conditions under the **Catch All Rule**. ![Okta Dt 5 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/images/Okta-DT-5.png) 1. Scroll down and click on **Actions** and choose **Edit**. ![Okta Dt 6 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/images/Okta-DT-6.png) 1. After that under the **THEN** conditions, opt **Denied**, and click **Save** ### Adding Apps ![Okta Dt 7 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/images/Okta-DT-7.png) Next add the apps which should be provisioned with Device Trust. To do that, go to **Applications** and click on **Add app**. Then search and add the apps. With this you can provision Okta Device Trust to the devices in your organization using Mobile Device Manager Plus. ## Frequently Asked Questions ### 1. What is Okta Device Trust? Okta Device Trust is Okta's conditional access policy that evaluates whether a user seeking access to the Okta portal is doing so from an authorized, compliant device before granting access. ### 2. What are the prerequisites for enabling Okta Device Trust with MDM? The device must be enrolled in Mobile Device Manager Plus and must have Okta Device attestation configured, through App Configurations for Android and iOS, or an SCEP profile for macOS and Windows. ### 3. Why should I disable the Catch All Rule? The Catch All Rule is the last set of conditions Okta checks before allowing or denying access. Disabling it prevents a device from getting access simply by falling through to this rule instead of meeting your configured device trust conditions. ### 4. Which platforms support Okta Device attestation through MDM? Okta Device attestation is supported on Android and iOS through App Configurations, and on macOS and Windows through an SCEP profile.