Last updated: July 24, 2026
Mobile Device Manager Plus attests Windows devices for Okta by deploying management attestation certificates over SCEP. Admins generate an SCEP URL, secret key, and CA certificate in Okta, then create a matching CA server, template, and SCEP profile in the MDM console before associating it with target devices. After the Okta Verify MSI is distributed, the user signs in once to complete attestation.
Managed devices should be attested by Okta for provisioning SSO extension with Okta and Okta Device Trust. In the case of Windows devices ,attestation is achieved by Mobile Device Manager Plus by distributing management attestation certificates to the device through SCEP.
Device attestation is achieved for Windows devices by deploying Management attestation certificates. The administrator or technician must first generate an SCEP URL and Secret key in Okta, and then using it create a Certificate Authority (CA) server and Template in the MDM console. The devices should then be associated to this Certificate Server and Template using an SCEP profile. After that, the devices must be distributed to the Okta Verify app, and the user must setup the Okta Verify app and log in once to achieve attested status. Follow the detailed steps specified below to configure Okta Device Trust :

First, generate an SCEP URL and Secret key in the Okta portal by following the steps provided below :



After generating an SCEP URL and Secret key Okta, a Certificate Server and Template should be created in the MDM console .For this follow the steps provided below :



Next we need to create an SCEP profile to distribute to your managed devices.For that:

For associating SCEP profile with the devices follow the steps given below:

Once the SCEP profile has been associated to the devices, the Okta Verify app should be distributed to the devices. For Windows, the app can be added as an MSI package.
Finally for the device(s) to achieve the attested status, the User should Setup Okta Verify with your organisation allotted credential and sign up at least once.
It deploys a management attestation certificate over SCEP — generate an SCEP URL, secret key, and CA certificate in Okta, then use them to create a matching CA server, template, and SCEP profile in the MDM console before associating it with target devices.
Yes — besides the SCEP URL and secret key, download the CA certificate from Actions under Certificate authority in Okta, since it's required when creating the CA server in the MDM console.
It's added as an MSI package in Mobile Device Manager Plus and distributed to the devices once the SCEP profile has been associated.
They set up Okta Verify using their organization-allotted credentials and sign in at least once.