As of July 28th, 2025, Mass General Brigham will be requiring the use of the Okta Verify app for multi-factor authentication and disabling text message authentication.
Please note: You will need an iOS or Android mobile device for these instructions, which you probably already have if you are getting SMS authentication prompts.
Download Okta Verify from the iOS App Store or Google Play Store.
If you are searching for it, be sure you install the correct app and not a sponsored / advertised top result! The icon should look like the one pictured on the right with the ✅ next to it.
You do not have to open the app just yet, but let it finish installing.
Login to MyProfile: https://myprofile.partners.org/oktaverify
Note: A QR code displays on the screen once you sign into this page -- you will need the QR code for the activation once you reach step 6 below.
If you have previously enrolled in Okta Verify, clicking continue will invalidate your device enrollment and will require you to delete your existing token in the Okta Verify App to re-enroll your device.
Using the steps below to connect your Okta Verify app with your MGB account.
Find and open the Okta Verify app on your mobile device and select Allow Notifications.
Click Add Account -> Organization -> Skip → Your camera will appear within the Okta Verify app.
Use your mobile device to scan the QR code displayed on your computer screen from step 4 above on the myprofile page.
Once scanned, your computer screen will refresh, and setup is complete.
Upon your next login to the VPN or any DFCI site requiring multi-factor authentication, you should be able to select "Send me a push" as a verification method (see image below).
When you are not connected to the MGB network and log in to an MGB application, use Okta Verify to verify your identity.
Once prompted for multi-factor authentication (when accessing VPN, UKG, PeopleSoft, or Citrix, for example), perform the following steps.
At the Secure Log In screen, enter you MGB username and password.
Choose Get a Push Notification: Click Send Push
Open the Okta Verify app on your mobile device or tap the push notification on your phone to go directly to the confirmation prompt.
Tap Yes, It’s Me on your mobile device.
Done! If you encounter issues, don't hesitate to contact the IS Service Desk using this link or call 857-282-4357.
Q: Is Okta Verify easy to use?
A: Yes! Once installed and enrolled, you’ll receive a simple push notification when signing in. Just tap "Yes" to verify – no need to enter a 6-digit code. It’s faster and easier than text messages or phone calls.
Q: Is my personal phone number still required?
A: No. Okta Verify does not rely on your phone number. It works securely through the app itself and doesn’t require your phone number or text data.
Q: Who needs to make this change?
A: All workforce members currently using Text Message or Voice MFA will need to switch to Okta Verify by Monday, July 28th. This especially includes remote workers, clinicians, administrative staff, and contractors, who regularly access MGB applications when not onsite.
Q: Is Okta Verify tracking my phone or collecting personal data?
A: No. Okta Verify does not collect personal information or actively track your location. Okta Verify does collect some basic location related data for security purposes, and only as part of verifying your identity when you log in.
Q: Who should I contact if I need help setting up Okta Verify?
A: Need help with enrollment? Contact the Service Desk using this link or call 857-282-4357.
Q: What if I don’t have a smartphone or can't install apps?
A: If you are unable to use a smartphone for multifactor authentication, you will be required to come onsite to a MGB hospital, facility, or office to access MGB applications.
Q: Does my phone need to be enrolled in InTune to download, install, or use Okta Verify?
A: No. Okta Verify can be downloaded, installed, and used without the mobile device being enrolled in MGB InTune.
Q: What if I don’t want to install Okta Verify on my phone?
A: If you are unwilling to install Okta Verify as an authenticator on your phone, you will be unable to pass multifactor authentication when logging into MGB applications remotely, and you will be required to be onsite at an MGB hospital, facility or office to access MGB applications.
Q: What if I lose my phone or get a new one?
A: If you change or lose your device:
When you come back onsite to an MGB facility, you can re-enroll your new device by logging into MyProfile.
If you cannot come onsite, contact the Service Desk to reset your Okta MFA enrollment. You’ll be required to go through an identity verification process and will be guided through re-enrollment of your new device.
Q: When do I need to make the switch?
A: All users must transition to Okta Verify by Monday, July 28th.
After this date, Text Messages and Voice MFA will no longer be supported for sign-in.
Q: Why does this matter in healthcare?
A: Protecting patient data isn’t just a best practice — it’s a responsibility. Using Okta Verify helps:
Keep electronic health records (EHRs) secure
Prevent unauthorized access to systems
Maintain compliance with healthcare regulatory requirements