Skip to main content

April 13, 2026

Configure Device Trust and Access Policies for Desktop Devices

To configure device trust and access policies for desktop devices, you configure identity provider routing rules in Okta and conditional access policies in Omnissa Access. The new, simplified Okta device trust solution that is available for iOS and Android devices is not yet available for desktop devices. To configure device trust for desktop devices, you can use the Certificate (Cloud Deployment) and Device Compliance authentication methods in Omnissa Access policies.

Important: Do not use the Device Compliance (with AirWatch) authentication method for apps that are configured with Device Trust in Okta. The Device Compliance authentication method is not compatible with apps using Okta Device Trust.

Important: Okta Device Trust is available only with the Okta Classic Engine. It is not supported with the Okta Identity Engine.

Make sure that you follow the preliminary procedures listed for the Device Trust use case in Main Use Cases before proceeding with the tasks in this section.

Configure Identity Provider Routing Rules in Okta for Desktop Devices

Configure Okta Identity Provider routing rules for desktop devices for the Workspace ONE-Okta integration. These routing rules work with application sign on policies to redirect authentication requests from desktop devices to Workspace ONE.

Procedure

  1. In the Okta Admin console, navigate to Security > Identity Providers.

  2. Click the Routing Rules tab, then click Add Routing Rule.

  3. Configure the routing rule.

    OptionDescription
    Rule NameEnter a name for the rule you are creating.
    IF User's IP isIf appropriate for your implementation, you can specify network zones to which the routing rule applies or does not apply. Network zones must be defined already in Okta.
    AND User's device platform isSelect Any of these devices, then select Windows, macOS, and Other desktop, or some of these options, based on your requirements.
    AND User is accessingSelect Any of the following applications, then enter the applications to which you want to apply the routing rule.
    AND User matchesSelect the appropriate option.
    • Anything
      Specifies any user. This is the default option.
    • Regex on login
      Allows you to enter any valid regular expression based on the user login to use for matching. This is useful when specifying the domain, or if a user attribute is not sufficient for matching. For details, see Identity Provider Discovery.
    • Domain list on login
      Specify a list of the domains to match. For example, example.com. Do not add the @symbol to the domain name. You can add multiple domains. Note that it is not necessary to escape any characters.
    • User attribute
      Select an attribute name in the left list, a type of comparison in the Starts with list, and then enter a value that you want to match in the text field on the right.
    THEN Use this identity providerSelect the Identity Provider you created in Okta for Omnissa Access, as described in "Configure Omnissa Access as an Identity Provider in Okta".

    For example:

    The Add Rule tab has all the desktop devices selected for device platform.

  4. Click Create Rule.

What to do next

Configure Conditional Access Policies in Omnissa Access for Desktop Devices

Configure Conditional Access Policies in Omnissa Access for Desktop Devices

To provide SSO and device trust for desktop devices, additional access policy rules are required in Omnissa Access.

Create the access policy for MacOS and Windows with Certificate (Cloud Deployment) and Device Compliance as the authentication methods.

Important: Do not use the Device Compliance (with AirWatch) authentication method for apps that are configured with Device Trust in Okta. The Device Compliance authentication method is not compatible with apps using Okta Device Trust.

Procedure

  1. In the Omnissa Access console, select Resources > Policies.

  2. Click Add Policy.

  3. In the Definition page of the wizard, enter the following information.

    OptionDescription
    Policy NameA name for the policy
    DescriptionA description for the policy
    Applies toSelect Okta.
    This assigns the access policy set to the Okta Application Source. All requests for Okta apps are evaluated with this policy rule set.
  4. Click Next.

  5. In the Configuration page, click Add Policy Rule and configure the policy rule for Windows.

    1. Select Windows 10+ as the device type in the and user is accessing content from list.

    2. Set the authentication method as follows:

      then perform this action: Authenticate using
      then the user may authenticate using: Certificate (Cloud Deployment)
      and: Device Compliance (with Workspace ONE UEM)

      Note: If Okta Device Trust is configured, do not use the Device Compliance (with Workspace ONE UEM) authentication method. Instead, use Okta authentication as the fallback authentication method:

      then perform this action: Authenticate using
      then the user may authenticate using: Certificate (Cloud Deployment)
      If the preceding method fails or is not applicable, then: Okta Auth Method

    3. Click Save.

  6. Click Add Policy Rule and configure the policy rule for macOS.

    1. Select macOS as the device type in the and user is accessing content from list.

    2. Set the authentication method as follows:

      then perform this action: Authenticate using
      then the user may authenticate using: Certificate (Cloud Deployment)
      and: Device Compliance (with Workspace ONE UEM)

      Note: If Okta Device Trust is configured, do not use the Device Compliance (with Workspace ONE UEM) authentication method. Instead, use Okta authentication as the fallback authentication method:

      then perform this action: Authenticate using
      then the user may authenticate using: Certificate (Cloud Deployment)
      If the preceding method fails or is not applicable, then: Okta Auth Method

    3. Click Save.

  7. Because this new policy overrides the default access policy for Okta applications, also add policy rules for iOS, Android, Apps on Workspace ONE Intelligent Hub, and Web Browser to the new policy, similar to the ones you previously added to the default access policy.

    1. Create a policy rule for iOS devices with Mobile SSO (iOS) as the first authentication method and Okta authentication as the fallback authentication method.

      If a user's network range is: ALL RANGES
      and the user is accessing content from: iOS
      then perform this action: Authenticate using
      then the user may authenticate using: Mobile SSO (iOS)
      If the preceding method fails or is not applicable, then: Okta Auth Method

    2. Create a policy rule for Android devices with Mobile SSO (iOS) as the first authentication method and Okta authentication as the fallback authentication method.

      If a user's network range is: ALL RANGES
      and the user is accessing content from: Android
      then perform this action: Authenticate using
      then the user may authenticate using: Mobile SSO (Android)
      If the preceding method fails or is not applicable, then: Okta Auth Method

    3. Create a policy rule for Apps on Workspace ONE Intelligent Hub.

      If a user's network range is: ALL RANGES
      and the user is accessing content from: Apps on Workspace ONE Intelligent Hub
      then perform this action: Authenticate using
      then the user may authenticate using: Mobile SSO (for iOS)
      If the preceding method fails or is not applicable, then: Mobile SSO (for Android)
      If the preceding method fails or is not applicable, then: Okta Auth Method

    4. Create a policy rule for Web browsers with Okta as the authentication method.

      If a user's network range is: ALL RANGES
      and the user is accessing content from: Web Browser
      then perform this action: Authenticate using
      then the user may authenticate using: Okta Auth Method

  8. Arrange the policy rules in the following order, listed from top to bottom.

    1. Apps on Workspace ONE Intelligent Hub
    2. Windows 10+ or macOS
    3. Windows 10+ or macOS
    4. iOS or Android
    5. iOS or Android
    6. Web browser

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…