Guides / Okta Verify push not arriving or stuck in an MFA loop
Last reviewed 5 Oct 2026
Okta Verify push not arriving or stuck in an MFA loop
Okta Verify push not showing up, or Okta keeps asking for MFA? How to get the user in, fix the phone, and what Okta admins check in the System Log.
"Okta is down" is the ticket. What it usually means is "I pressed Send Push and nothing happened", or "I approve it and Okta asks me again". Both are fixable at the desk in a few minutes, and neither is a reason to email the whole company.
Is it Okta?
Okta publishes by cell, so find which one your org lives in before reading status.okta.com. As we explain on our Okta page, Okta's public machine-readable feeds have been unreliable, so we will not show you a green light we cannot verify. If many users in different places cannot push at the same time and the cell shows an incident, it is Okta. If one user cannot, keep reading.
Get the user in right now
- Open Okta Verify directly. A pending push often shows inside the app even when the notification banner did not appear.
- Use the code. On the sign-in screen, choose to enter a code instead of a push. The six-digit code in Okta Verify works without a notification, provided your sign-on policy allows it and the phone clock is correct.
- Number challenge. If Okta shows a number, the user must pick the matching number in the app. People miss this on a small screen and assume the push failed.
Fix the phone
- Notifications on for Okta Verify, including banners and lock screen.
- Focus / Do Not Disturb off, or Okta Verify allowed through it.
- Android battery optimisation set to unrestricted for Okta Verify; aggressive power saving kills background pushes.
- iPhone Background App Refresh on, and Low Data Mode off while testing.
- Time set automatically. Wrong time breaks codes.
- Network. Pushes need data. Hotel and guest Wi-Fi with a sign-in page will block them silently; switch to mobile data.
- Update Okta Verify. Old versions can stop working when the org enables newer features.
The MFA loop
If the user approves and is asked again, it is usually one of three things:
- Cookies blocked for the Okta domain, so the session is never kept. Test in a private window with extensions off.
- Policy working as designed. An app sign-on policy that requires MFA every time, or a short session lifetime, feels like a loop. Check the global session policy and the app's authentication policy.
- Two identity providers. Okta federated to Microsoft 365, plus Entra Conditional Access that also requires MFA, gives you two prompts from two vendors. Decide which one owns MFA.
Admin checks (Okta Admin Console)
- System Log. Reports → System Log, filtered to the user. You can see whether a push was sent, whether it was denied, and which policy asked for MFA. If no push was sent, the problem is before the phone.
- Reset the authenticator. On the user's profile, reset Okta Verify (labelled Reset Authenticators or Reset Multifactor, depending on your admin console version). The user re-enrols at next sign-in. Do this for any new phone.
- Policies. Confirm which authenticators the user's group may use and whether the code option is permitted as a fallback.
- Okta FastPass. If the org uses Okta Verify on the desktop, loops can come from a device that is no longer registered. Check the device in the admin console.
Unexpected pushes
A user who gets pushes they did not trigger has a compromised password. Tell them to deny every one. Reset the password, clear sessions, and look at the System Log for the source IP. Pressing approve to make it stop is how MFA fatigue attacks succeed.
When to escalate
Open a case with Okta support when the System Log shows pushes being sent but users across devices and networks do not receive them, or the status page for your cell names Okta Verify or authentication. Include your org URL, cell, timestamps with time zone, and example System Log event IDs.
Related status pages
Related guides
- Okta SSO not working: outage, MFA, or account lockout?
- Microsoft Authenticator not getting notifications: fixes
- Microsoft 365 sign-in loop or 'More information required'
FAQ
- Why is my Okta Verify push not showing up?
- Usually phone settings: notifications off, Focus mode, Android battery optimisation, or no data connection. Open Okta Verify directly to see pending pushes, or enter the six-digit code instead.
- Why does Okta keep asking me to verify?
- Blocked cookies, a sign-on policy that requires MFA every time, or two identity providers (Okta and Microsoft Entra) both asking for MFA. Test in a private window, then ask your admin to review the policies.
- How do I move Okta Verify to a new phone?
- Treat it as a new enrolment. If you can still sign in, add the new phone from your Okta settings. If not, ask your Okta admin to reset Okta Verify on your account so you can enrol again.
- Is Okta down if my push fails?
- Not necessarily. Check status.okta.com for your cell. If colleagues can sign in, the problem is your phone or your enrolment.