Okta is the one sign-in for the work apps your organization connects to it — email, chat, payroll, cloud consoles — so a single stolen password would open all of them. That is why organizations require a second step in Okta. Okta Verify is Okta’s own app; the “Google Authenticator” option takes a standard code from any authenticator, so it can live on your work computer instead of your personal phone.
Set up the Google Authenticator option in Okta
Okta is run by your employer or school, and its administrators decide which security methods you see, so your screens may differ — older Okta pages say “Setup security authenticators” instead of “security methods”. If “Google Authenticator” is not offered, your organization has not turned it on: use what it offers, or ask your IT help desk. Okta’s own page on it is written for administrators; the steps follow its section on what users see.
- Open your organization’s Okta sign-in page on your computer and sign in.
- If Okta asks you to set up security methods, it lists them right away. Otherwise click the arrow beside your name on the Okta dashboard, choose “Settings”, and find “Security Methods”.
- Click “Set up” next to “Google Authenticator”.
- If Okta asks for your device type, pick iPhone or Android and click “Next” — it only changes the instructions on the screen.
- Okta shows a QR code — do not click “Next” yet. Leave it on the screen and add it to the extension as described below, then click “Next”, type the code from the extension into “Enter Code” and click “Verify”.
Add Okta to Authenticator
- Install 2FA Authenticator from the Chrome Web Store and pin it to the toolbar, so its icon is one click away.
- Leave the Okta page with the QR code open. Click the Authenticator icon, then “Add Account” → “QR Code” → “Scan QR from screen”.
- The account appears in the list with a six-digit code that changes every 30 seconds. Rename it if you like — the name is only for you.
- Go back to Okta and type the current code into the confirmation field. If it is about to expire, wait for the next one.
- Okta confirms that two-factor authentication is on. From now on it will ask for a code when you sign in — click the extension icon and copy it.
No QR code, or it will not scan? Look for the option to enter a key manually on Okta’s setup screen, copy the key, and add it in the extension with “Add Account” → “Manual” → “Secret Key”.
Get 2FA Authenticator for Chrome — freePlan a way back into Okta
Okta does not give you backup codes for this method. Your way back is your organization’s IT help desk, which can reset your security methods so you can set them up again. Make that unlikely to be needed: keep the extension’s automatic backups on, and if your organization offers a second method, set that up too.
The code is not accepted?
Almost always the computer’s clock. The codes are calculated from the current time, so a clock that is a minute off produces codes that look right and are refused. Turn on automatic date and time in your system settings — step-by-step for Windows, macOS and Linux.
If the clock is right, check the key itself: paste it into the TOTP code generator and compare the code with the one in the extension. If they differ, the key was copied wrong — add the account again.
Questions
- Okta asks for Google Authenticator. Do I have to install it on my phone?
- No. Okta’s help describes the option as a standard time-based one-time password (TOTP), and all Okta checks is the six-digit code. The Authenticator extension generates the same codes in Chrome on your computer and reads the QR code straight off the Okta screen.
- Is Okta Verify the same thing?
- No. Okta Verify is Okta’s own app, with push notifications only it can answer. If your organization offers both, the “Google Authenticator” option is the one that works with the extension; if it offers only Okta Verify, you need Okta Verify.
- What if I lose access to my authenticator?
- Sign in with another security method if you set one up, or ask your IT help desk to reset Google Authenticator for your account, then scan the new QR code. With the extension, restoring one of its automatic backups on a new computer keeps the same codes working.
- Why does Okta say my code is wrong?
- Usually the computer clock: Okta allows up to about two minutes of difference, and a clock further off produces codes it refuses. Turn on automatic date and time before trying again — after five wrong codes Okta stops accepting them for a while, and in some organizations until an administrator unlocks the account.
Your codes, one click from the login page
Authenticator keeps your 2FA codes in the browser, on your device only — free to use, open source, no account and no phone needed. Local backups and optional password protection come built in.
Get 2FA Authenticator for Chrome — free