Audience:
IT (John, Collin). Companion to "Mac and Okta Login Troubleshooting (Consolidated)" and "Emergency Recovery: Mac Locked Out at Login by Okta Desktop MFA."
All commands below are READ-ONLY. Run them in Terminal on the Mac, signed in as a user with admin rights. The sudo lines will ask for that user's Mac password.
WARNING: Do not read the whole Desktop MFA profile at once (defaults read with only the domain and no key name). The profile contains DMFAClientSecret and it will print. Always read keys one at a time, as below.
1. WHAT IS THE DESKTOP MFA POLICY SET TO?
Shows each policy key. "Does not exist" means the key is not set and Okta's default applies.
p="/Library/Managed Preferences/com.okta.deviceaccess.servicedaemon" for k in DMFAOrgURL LoginPeriodWithOfflineFactor LoginPeriodWithoutEnrolledFactor DeviceRecoveryValidityInDays DeviceRecoveryPINDuration OfflineLoginAllowed AllowedFactors MFARequiredList MFANotRequiredList; do print -- "== $k" defaults read "$p" "$k" 2>&1 done
Units (no key name carries its unit):
LoginPeriodWithOfflineFactor: hours. How long after the last online login the Device Access Code keeps working. Set to 4320 (180 days) on 2026-09-28.
LoginPeriodWithoutEnrolledFactor: hours. Grace period to skip Desktop MFA enrollment.
DeviceRecoveryValidityInDays: days. A recovery PIN can only be issued if the user had an online login within this many days. Default 90 when not set.
DeviceRecoveryPINDuration: minutes. How long access lasts after a recovery PIN is used. The PIN itself must be entered within 2 minutes of being generated.
MFANotRequiredList: accounts exempt from Desktop MFA (currently tadmin).
DMFAOrgURL: must match the Okta domain the user's security key was enrolled on (currently https://tamman.okta.com).
2. WHEN DID EACH LOGIN HAPPEN, AND WITH WHICH FACTOR?
Shows the 15 most recent Mac logins, newest first.
sudo sqlite3 -readonly -header "/Library/Application Support/com.okta.deviceaccess.servicedaemon/OktaDMFA" "select username, factorUsed, factorScope, datetime(loginTimestamp,'unixepoch','localtime') as login from LoginHistory order by loginTimestamp desc limit 15;"
How to read it:
push / online: Okta Verify push at the login window. Resets the offline window and the recovery PIN window.
onlineFIDO / online: security key (YubiKey) at the login window. Resets both windows.
offlineTOTP / offline: Device Access Code. Does NOT reset either window.
none / none: recovery PIN login. Does NOT reset either window.
The newest row with scope online is the one that matters.
3. WHICH OFFLINE FACTORS ARE ENROLLED ON THIS MAC?
The Factors table holds no secret material; it is safe to read all rows.
sudo sqlite3 -readonly -header "/Library/Application Support/com.okta.deviceaccess.servicedaemon/OktaDMFA" "select username, factorType, displayName, issuer, datetime(createTimestamp,'unixepoch','localtime') as created, guid from Factors;"
Expect one offlineTOTP row per user (the Device Access Code). As of 2026-09-28, security keys are an online factor only on macOS; Okta documents an offline security key for Windows only.
4. HOW MANY HOURS ARE LEFT IN THE OFFLINE WINDOW?
Fleet view: Jamf extension attribute DMFA_Offline_Hours_Remaining on each computer record. Negative = lapsed. -99999 = no online login on record. Blank = no Desktop MFA on the Mac.
One Mac, per-user detail: run the attached script DMFA_Offline_Window_Check.sh in detail mode:
sudo bash /path/to/DMFA_Offline_Window_Check.sh "" "" "" detail
Note: the script counts from the newest online login and rounds down to whole hours. To see which factor that login used, use command 2.
5. IS THE LOGIN PLUGIN INSTALLED?
ls -ld /Library/Security/SecurityAgentPlugins/OktaDAAuthPlugin.bundle
"No such file or directory" means Desktop MFA is not active at the login window (for example, after the Emergency Recovery procedure). Reinstall Okta Verify from Jamf to restore it.
REFERENCES
Okta: Configure and deploy Desktop MFA policies for macOS: https://help.okta.com/oie/en-us/content/topics/oda/macos-mfa/configure-and-deploy-macos-mfa-policies.htm
Okta: Enable Desktop MFA recovery for macOS: https://help.okta.com/oie/en-us/content/topics/oda/macos-mfa/desktop-mfa-recovery-macos.htm
Okta: Troubleshoot Desktop MFA for macOS: https://help.okta.com/oie/en-us/content/topics/oda/macos-mfa/troubleshoot-macos-mfa.htm
Commands 1 to 5 verified 2026-09-28 on TAM10310-MBP-jciesla.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article