Multi-Factor Authentication Enhances Security
Multi-factor Authentication (MFA) adds an extra layer of protection to the State by requiring more than one form of verification. Instead of relying solely on a password, MFA combines multiple types of identification:
- Something you know (such as a password)
- Something You have (such as a mobile device or security key)
- Something you are (such as a fingerprint)
Requiring MFA provides extra security because even if someone obtains your password, they are unable to access your account without the second verification step. MFA ensures a stronger, more reliable way to confirm your identity and keep state information secure.
State of Indiana Supported Methods for Employee MFA
- Okta Verify App (recommended)
- Easy-to-follow Set up Instructions are included on this Okta Quick Reference Guide.
- The Okta Verify App is a FREE, secure MFA application for mobile devices.
- Works on both personal devices and state-issued mobile devices.
- When used on a personal mobile device, the Okta Verify App does not make your device managed by the State and does not provide IOT any access to your personal data (photos, messages, emails, etc.) It also does not require the installation of the State's mobile device management (Ivanti) on your personal device.
- Available in the Apple App Store, Google Play Store, or Apps@Work (on State-managed devices)
- Check out the Okta Verify App FAQs for more information about the app permissions.
- How to Access the Okta Setup from your computer: https://signin.in.gov/
- FIDO Security Key (also referred to as a Yubikey)
- A Security Key is a hardware authentication option for users who cannot access a smartphone. It is a small physical device similar to a USB stick.
- Ideal for users in restricted environments where mobile devices are not permitted.
- Available through IOT. Managers may request for employees by submitting a Hardware Request Form through ServiceNow (select Yubikey). There is a cost associated with this hardware.
Note: As part of IOT's ongoing efforts to strengthen security and modernize authentication across State of Indiana systems, we are retiring the Voice/Phone Call method currently used for Multi‑Factor Authentication (MFA) in Okta at the end of 2026.
Beginning January 1, 2027, users who have not transitioned to one of the approved MFA methods (listed above) will be unable to log in to required State systems until an updated MFA option is configured. To avoid service disruption, all agencies and users must begin transitioning as soon as possible.
If you need assistance, please contact IOT Customer Service at 317‑234‑4357 or 1‑800‑382‑1095.
Microsoft MFA Instructions
Register for the Microsoft (Entra/Azure) Multi-Factor Authentication (MFA): https://on.in.gov/MFA
You complete the sign-up process using the existing credentials (username and password) that you use to login today. If you have multiple accounts, such as an elevated or admin account, you will need to complete this process for each account.
After you register, you will be able to add a safe and secure two-step verification method for your online credentials using either a phone call or a mobile authenticator app on your smart phone.
Additional MS Instructions:
Multi-factor Authentication with Mobile Authenticator app
Multi-factor Authentication with Phone
Elevated or Admin account? Click here.