Configure Okta org
Before installing the Okta credential provider for Windows, you must :
- Define a group for the end users who will authenticate RDP sign ins.
- Specify MFA factors that include the factor to use for RDP sign in.
- Add and configure the Microsoft RDP (MFA) app.
- Define groups the will be used to authenticate:
- Sign in to your Okta tenant as an administrator.
- In the Admin Console, go to .
- Click Add Group.
- Complete the fields in the Add group dialog and click Save.
- Add people to the group. See Users, groups, and profiles.
- Specify authentication:
- In the Admin Console, go to .
- Select the Factor Types tab.
- Activate a factor by selecting it and clicking .
See also MFA.
- Add and configure the Microsoft RDP (MFA) app:
- Sign in to your Okta tenant as an administrator.
- In the Admin console, go to Applications > Applications.
- Click Add Application and enter Microsoft RDP (MFA) in the search box.
- On the General tab, assign any desired application label and then add the application.
- Select the Assignments tab.
- Assign the application to groups or individuals as required.
- Save your changes.
- Select the Sign On tab.
- Click Add Rule and add any required sign on rules.
- Click Done when complete.
RDP can fail with the error message Multifactor Authentication Failed if a user attempts to RDP into a server with the RDP agent installed that does not match an Microsoft RDP (MFA) App username.