I have stubbed out most of my embedded code. The customized plist contains the clientID,URIs etc Ive setup for my authenticator.
During OIN testing, the “Confirm User” steps never completes. System logs show the 2 auth factors setup for my policy showing MFA SUCCESS. Immediately followed by an MFA UNANSWERED response. Network logs show no errors. Standalone tests (outside OIN Testing ie) also show similar erros.
One (speculative) theory offered by perplexity says I am missing okta.authn.manage scope on server (only devsupport can assign that to my org apparently). And this seems necessary for updating the state from CHALLENGE to SUCCESS at /idp/idx/challenge/answer. I have no proof for this.
Admin Yella Okta (User)
75.218.146.121
Verify user identity
SUCCESS
Custom App Authenticator (AuthenticatorMethod)
Security Key or Biometric (AuthenticatorMethod)
1 more targets
Nov 07 16:48:38
Admin Yella Okta (User)
75.218.146.121
Authentication of user via MFA
UNANSWERED
Admin Yella Okta (User)
Passkey + TruKYC (AuthenticatorEnrollment)
Nov 07 16:48:38
Admin Yella Okta (User)
75.218.146.121
Authentication of user via MFA
SUCCESS
Admin Yella Okta (User)
Security Key or Biometric (AuthenticatorEnrollment)
Nov 07 16:48:32
Admin Yella Okta (User)
75.218.146.121
User login to Okta
SUCCESS
Passkey + TruKYC (AuthenticatorEnrollment)
Okta Dashboard (AppInstance)
Nov 07 16:48:28
Admin Yella Okta (User)
75.218.146.121
Authentication of user via MFA
SUCCESS
Admin Yella Okta (User)
Passkey + TruKYC (AuthenticatorEnrollment)
Nov 07 16:48:28