Skip to main content

Transfer Okta Verify accounts to a new device using Bluetooth

How to transfer Okta Verify accounts to a new device over Bluetooth, including third-party TOTP and Device Access codes on iOS-to-iOS moves.

Okta Verify can transfer existing accounts directly from one mobile device to another over Bluetooth. The transfer happens locally between the two devices and does not use cloud synchronization, so authentication secrets stay device-bound and never pass through a personal cloud account.

This article covers what can be transferred, the requirements, and the current platform limitations. It's intended for MSP technicians and administrators supporting an end user through a device change, such as a phone upgrade or replacement.

What can be transferred?

Bluetooth transfer supports three types of credentials, but which ones can move depends on the operating systems of the original and new devices:

  • Native Okta Verify accounts — accounts enrolled directly in Okta Verify.

  • Third-party TOTP accounts — time-based one-time password codes for services such as GitHub, AWS, and Google.

  • Device Access codes — codes tied to desktop authentication features, including Okta Device Access and Platform SSO.

Original device

New device

Native Okta Verify accounts

Third-party TOTP accounts

Device Access codes

iOS

iOS

Yes

Yes

Yes

Android

iOS

Yes

No

No

macOS or Windows

iOS

Yes

No

No

Android

Android

Yes

No

No

iOS, macOS, or Windows

Android

Yes

No

No

Third-party TOTP accounts and Device Access codes can currently be transferred only when both the original and new devices are iOS devices. In every other combination, only native Okta Verify accounts move over Bluetooth.

What's new in Okta Verify 9.70.0 for iOS?

Bluetooth transfer of native Okta Verify accounts has been available across multiple platforms for some time. Starting with Okta Verify for iOS version 9.70.0, the feature was expanded so that third-party TOTP accounts and Device Access codes can also be transferred on iOS-to-iOS moves. This removes the need to manually re-enroll each third-party account on the new device and results in faster iPhone upgrades.

What do you need before you start?

Before beginning a transfer:

  • Install the latest available version of Okta Verify on both devices.

  • Enable Bluetooth on both the original and new devices.

  • Confirm the Okta Verify account shows no warnings or errors.

  • Enable Okta FastPass for the Okta Verify account.

  • Configure biometrics or screen-lock verification on the new device.

  • Keep both devices available and nearby throughout the transfer.

On Android, Okta Verify requires Android 12 or later. Support for Android 11 was removed in the Okta Verify for Android 9.0.0 release (June 15, 2026), the same release that introduced Bluetooth account transfer on Android, so any current Android device capable of a Bluetooth transfer already meets this requirement.

How do you run the transfer?

The step-by-step process runs inside Okta Verify on the new (destination) device. Follow Okta's official instructions for the destination platform:

Limitations to be aware of

  • The 9.70.0 expansion for third-party TOTP accounts and Device Access codes applies to iOS-to-iOS transfers only.

  • A new Android device can import native Okta Verify accounts from Android, iOS, macOS, or Windows, but not third-party TOTP accounts or Device Access codes.

  • If the original device is unavailable and the user has no other enrolled authentication method, the user will need help-desk assistance to re-enroll.

Why does this use Bluetooth instead of cloud backup?

Okta Verify does not back up or synchronize authentication secrets through a personal cloud account. Bluetooth transfer keeps that security model intact: secrets move directly between two verified devices rather than being stored in, and restored from, a cloud service. This keeps MFA secrets device-bound and out of personal Google, Apple, or Microsoft accounts, which is the behavior high-assurance and regulated environments expect.

Next steps

  • Confirm Okta FastPass is enabled and the account is error-free before any planned device change. Both are prerequisites for transfer.

  • For iOS-to-iOS upgrades, use Bluetooth transfer rather than manual re-enrollment to move all supported credentials in one pass.

  • If a user has lost access to their original device with no other enrolled method, route them to your help desk for identity verification and re-enrollment.

Did this answer your question?