Okta Overview

Summary

A few commonly-asked questions about Okta, security, and single sign-on functionality.

Body

Phone call and text message (SMS) options were removed from Okta on March 12.
If you are locked out of your SLU account, please call the ITS service desk at
314-977-4000 for assistance. The service desk’s hours are 7am-8pm Monday-Friday.

 

What is Okta?

Okta is SLU's tool for single sign-on (SSO) password maintenance and multi-factor authentication (MFA).
Okta enables you to log into your computer securely and access online resources including:

  • Email
  • Workday
  • Canvas
  • Zoom
  • Panopto
  • and other university tools
     

How Do I Set It Up?

SLU's Preferred Authentication Method is Okta Verify:

Use the links below to install Okta Verify on:

 

What If I Can't Use An Available MFA Method?

If you don't have a smart phone on which to install Okta Verify or one of the other options offered, please contact the Service Desk by phone (314-977-4000) or through the chat function at ask.slu.edu.
 

What Is Multi-Factor Authentication (MFA)?

MFA is an additional step to verify your identity when you sign in to an application. Using MFA adds an additional layer of protection to your SLU account. It means that even if a hacker figures out your password, they still won't be able to impersonate you to access your account.

The ‘factor’ in MFA refers to a method of verifying your identity. The most basic type of factor is your password. SLU requires you to use a second method to log into your account.
 

Why Do I Keep Seeing MFA Prompts?

If you have selected the Do not challenge me on this device for the next 12 hours option, but keep seeing MFA prompts, it could be for a few different reasons: 

  1. Cookie management: The 'do not challenge me' choice is captured in a browser cookie. If you’ve recently cleared your cookies, or you've switched to another browser, it won’t remember the choice.
  2. Policy configuration: SLU set the expiration for this exception at 12 hours. It's possible that the time expired.
  3. Exempted action: Certain actions, like editing your account profile, will always trigger an MFA prompt as an additional layer of security.

     

What Is Single Sign-On (SSO)?

SSO ensures that your username and password are synchronized across multiple platforms. With Single Sign-On you can use a single username and password to access all your tools and online resources. As long as a SLU system is managed with our through Okta, you don't need to memorize a different password for it.
 

Can I Opt Out of MFA or SSO?

No. SLU has enabled MFA and SSO campus-wide through Okta. Making exceptions would create a vulnerability that could leave everyone’s data open to attack.
 

How Secure Is Okta?

Okta secures and verifies all communications and handshaking within the system. Passwords are encrypted and Okta ensures that only authorized individuals have administrative access. These controls are audited regularly. As for the additional factors, Okta encrypts access using two different software locks called keys. It stores data and the keys used to unlock that data in separate databases. For extra security, it then encrypts the keys in three different ways for even stronger protection. No one person at Okta can access the encrypted master key, and Okta maintains an audit trail to show how it manages the keys.
 

Details

Details

Article ID: 208
Created
Wed 5/5/21 5:25 PM
Modified
Wed 4/2/25 9:04 PM