Credenti Extend

MFA Without the Device Dependency

Extend TOTP authentication in Okta and Microsoft Entra to brokers, partners, agents, contractors and global help desks with a secure, browser-based virtual authenticator. No phone. No app to install. No authentication hardware to distribute.

Key Capabilities

Browser-Based Virtual Authenticator

Users open Credenti Extend in a supported web browser to access their rotating six-digit TOTP code, instead of an authenticator app on a physical phone.

Phone-Independent Authentication

No mobile phone is required to retrieve the user's TOTP, and routine authentication does not depend on SMS or voice delivery.

No Endpoint Installation

Nothing needs to be installed on the user's workstation to access the virtual authenticator — ideal for personally owned and independently managed devices.

Okta and Microsoft Entra Integration

Works with TOTP in Okta and OATH TOTP in Microsoft Entra ID. Your identity provider keeps validating the code and enforcing your authentication and access policies.

Personal PIN Protection

When configured, a user-specific PIN protects access to the virtual authenticator — much like unlocking a phone before opening an authenticator app.

Phone-Free Enrollment

First-time activation verifies the user with a six-digit code sent to a registered secondary email that is independent of the protected Okta or Entra environment.

A financial broker works on her own laptop in a home office. A Credenti Extend Virtual Authenticator card shows the six-digit code 810 720 and the message 'Signed in · no phone needed', illustrating phone-free TOTP MFA for Okta and Microsoft Entra.

Benefits

Arrow bullet icon

No Phones, Tokens or Hardware to Manage

Stop collecting phone numbers, issuing corporate phones or shipping security keys around the world. There is no physical TOTP device to ship, recover or replace.

Arrow bullet icon

MFA on Devices You Don't Manage

Control application access without controlling the user's device — no MDM, admin rights or software installation needed on BYOD and partner endpoints.

Arrow bullet icon

Keep Your IdP and Policies

Okta or Microsoft Entra still validates every TOTP and enforces your existing authentication and access policies. Keep TOTP, remove the physical-device dependency.

Arrow bullet icon

A Simpler Device Lifecycle

Replace procure, inventory, ship, enroll, support, replace and recover with a simple flow: Verify, Enroll, Authenticate, Revoke.

How It Works

Okta asks for a verification code and the user opens the Credenti Extend tab in the browser.

1. Open Credenti Extend

When Okta or Entra asks for a code, the user opens their Credenti Extend virtual authenticator in a supported web browser.

The user unlocks Credenti Extend by entering their personal PIN.

2. Unlock with a PIN

When configured, the user enters their personal PIN to unlock the virtual authenticator.

The Credenti Extend virtual authenticator shows the current six-digit TOTP code, 810 720.

3. View the TOTP

Credenti Extend displays the current six-digit time-based one-time password, which rotates on the configured interval.

After entering the code, the user is signed in to the Okta My Apps dashboard.

4. Authenticate and Keep Working

The user enters or copies the code into the normal Okta or Microsoft Entra prompt. The IdP validates it and applies your existing policies.

Built for the Extended Workforce

Brokers, Agents and Partners

Give brokers, financial agents, advisors and third-party partners enterprise MFA without issuing phones or installing software on devices owned by another organization.

Help Desks, Contact Centers and BPOs

Authenticate distributed, shift-based and high-turnover support teams without shipping authentication hardware or relying on personal phones.

Contractors and BYOD Workforces

Provide MFA to short-term and BYOD users without creating a physical device lifecycle or installing corporate software on their endpoints.

FAQs

Frequently Asked Questions

What is Credenti Extend?

Credenti Extend is a browser-based virtual authenticator that allows users to access TOTP authentication codes without requiring a physical mobile phone, SMS, voice calls, authenticator application, or physical TOTP token.

Can I use MFA without a phone?

Yes. Credenti Extend provides a phone-independent way for users to access TOTP authentication supported by Okta and Microsoft Entra.

Does Credenti Extend require software installation?

No. Users access their virtual authenticator through a browser. No authenticator application, desktop agent, or browser extension needs to be installed simply to retrieve the TOTP.

Does Credenti Extend work with Okta?

Yes. Credenti Extend is designed to work with TOTP authentication supported by Okta. Okta continues to validate the TOTP and enforce the organization's authentication policies.

Does Credenti Extend work with Microsoft Entra ID?

Yes. Credenti Extend works with OATH TOTP authentication supported by Microsoft Entra ID. Entra remains responsible for validating the authentication code and enforcing authentication policy.

Is Credenti Extend replacing Okta Verify or Microsoft Authenticator?

Credenti Extend provides an alternative way to make TOTP available for populations where requiring a physical phone or authenticator application creates operational challenges. It does not replace the identity provider itself.

Does Credenti Extend replace SMS MFA?

Credenti Extend can provide a phone-independent alternative for appropriate authentication workflows currently dependent on SMS or voice OTP delivery. The user's TOTP is made available through their virtual authenticator instead of being delivered through a telecommunications provider.

Does Credenti Extend require a phone number?

No phone number is required to deliver the TOTP because the user retrieves it from the virtual authenticator rather than through SMS or voice.

How does a user enroll without a phone?

During first-time enrollment, Credenti Extend sends a six-digit verification code to the user's registered secondary email. After successful verification, the user can establish a personal PIN when configured and complete activation of the virtual authenticator.

Why does Credenti Extend require a secondary email?

The secondary email provides an independent channel for verifying the user during first-time enrollment. It should not depend on the same Okta or Microsoft Entra environment being protected.

Is secondary email used every time the user authenticates?

No. Secondary email is used for identity verification during enrollment rather than to deliver every TOTP authentication code.

How does the PIN work?

When configured, the PIN protects access to the virtual authenticator. The experience is similar to unlocking a physical phone with a PIN before accessing an authenticator application.

Is TOTP phishing-resistant?

No. TOTP is not considered phishing-resistant authentication. Organizations requiring phishing-resistant authentication should use methods designed for that requirement, such as passkeys or FIDO2/WebAuthn authentication where appropriate.

Credenti Extend addresses a different problem: making TOTP operationally practical for populations where phones, authenticator applications, security keys, or endpoint installations create significant barriers.

Who is Credenti Extend designed for?

Credenti Extend is particularly suited to brokers, financial agents, partners, contractors, global help desk personnel, BPO workers, contact center agents, temporary workers, and other extended workforce populations.

Can Credenti Extend be used in BYOD environments?

Yes. BYOD and independently managed endpoints are important Credenti Extend use cases because users can access their virtual authenticator without requiring the organization to install authentication software on the endpoint.

See Credenti Extend in Action.

Keep Okta or Microsoft Entra. Extend TOTP. Remove the device dependency — give brokers, partners, contractors and help desks enterprise MFA without a phone, an app to install, or hardware to ship.