If you were blocked from signing in to a Samsara application, your Mac did not pass one of our security checks. Find your check below and follow the steps.
Did you install Okta Verify yourself from the App Store? That version makes these checks fail even when nothing is wrong with your Mac. Start here.
Contents
Start here: Okta Verify from the App Store
- Device Is Not Enrolled in macOS MDM
- FileVault Is Not Encrypting the Primary Disk
- Secure Enclave Chip Is Inactive or Not Working Correctly
- macOS Version Is Not Up to Date
- CrowdStrike Agent Is Not Installed or Running
- System Integrity Protection Is Not Enabled
- Screen Lock Is Not Configured Securely
- Required Device Certificate Is Missing
- Chrome Browser Is Not Up to Date
Before you start: to find your serial number, click the Apple menu in the top-left corner of your screen and choose About This Mac. Your serial number looks like
HJ6TL16C9N.
Start Here: Okta Verify from the App Store
Samsara has its own version of Okta Verify. If you installed Okta Verify yourself from the App Store, it will not work properly and you will be blocked even when there is nothing wrong with your Mac. Many of the problems below are caused by this.
How do I fix this?
- Open the App Store and click your name in the bottom-left corner.
- Look for Okta Verify in the list. If it is not there, you already have the Samsara version — skip the rest of this section.
- Click the ⋯ button next to Okta Verify and choose Delete App.
- Open Managed Software Center and click Check for Updates. The Samsara version installs by itself.
- Open Okta Verify and sign in to Okta again.
Still not working?
Find your check in the list above and follow the steps. If it still fails, post in the #help-biztech Slack channel with your serial number.
1. Device Is Not Enrolled in macOS MDM
Why is this a problem?
Your Mac must be enrolled in Samsara's device management system, SimpleMDM. Enrollment makes sure your Mac is set up correctly from day one, and it lets Samsara protect company data if your Mac is ever lost or stolen. It also allows IT to keep your Mac secure and up to date.
How do I fix this?
Your Mac needs a valid MDM certificate. This check often fails simply because your Mac has been offline or switched off for a while — for example, after coming back from vacation. When that happens, your Mac usually reconnects and fetches what it needs on its own.
Try this first:
- Connect your Mac to the internet.
- Wait 5–10 minutes so the MDM profile can fetch the latest certificate.
- Try signing in again.
Still not working?
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – Require Device to Be Enrolled in macOS MDM
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently (returning from time away, a macOS update, a repair)
2. FileVault Is Not Encrypting the Primary Disk
Why is this a problem?
FileVault encrypts your startup disk so that nobody can read your files if your Mac is lost or stolen. Because Samsara devices may hold confidential information such as intellectual property or customer data, disk encryption is a basic requirement.
How do I fix this?
- Click the Apple menu in the top-left corner of your screen and choose System Settings.
- In the sidebar, click Privacy & Security.
- Scroll to the FileVault section.
- Click Turn On and follow the prompts.
- Close System Settings when you are done.
Encryption continues in the background. Keep your Mac plugged in until it finishes.
Still not working?
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – Require Primary Disk to Be Encrypted with FileVault
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
3. Secure Enclave Chip Is Inactive or Not Working Correctly
Why is this a problem?
Your device must have a Secure Enclave chip that is active and functioning correctly. The Secure Enclave is a dedicated security component built into your device that protects sensitive information — such as encryption keys, credentials, and biometric data — by keeping it isolated from the rest of the system. Without it, Samsara cannot guarantee that your device meets the minimum hardware security requirements needed to protect company data.
How do I fix this?
The Secure Enclave is hardware, so it cannot be installed or turned on manually. If this check is failing, it usually means one of the following:
- Your Mac does not meet Samsara's minimum hardware requirements.
- A firmware or software problem is preventing the Secure Enclave from being detected.
Try this first: restart your Mac, then try signing in again.
Still not working?
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – Require Secure Hardware to Be Present
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
4. macOS Version Is Not Up to Date
Why is this a problem?
Your Mac must run a supported, up-to-date version of macOS. Apple regularly releases updates that close security holes and fix bugs. Running an outdated version puts company data at risk and means your Mac no longer meets Samsara's minimum security requirements.
How do I fix this?
- Click the Apple menu in the top-left corner of your screen and choose System Settings.
- In the sidebar, click General.
- Click Software Update.
- Click Update Now (or Upgrade Now) to install everything that is missing.
- Follow the on-screen instructions and let your Mac restart.
Tips
- Plug your Mac into power before you start.
- Use a reliable Wi-Fi network — updates can be several gigabytes.
- If you have not used your Mac in a while, the download may be larger and take longer than usual. That is normal.
Still not working?
If the check still fails after updating, post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – OS Version Must Be at Least {version}
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
5. CrowdStrike Agent Is Not Installed or Running
Why is this a problem?
CrowdStrike Falcon is Samsara's endpoint protection software. It watches your Mac for malware, ransomware, and other threats in real time. Without it, your Mac is unprotected and puts Samsara's network and data at risk. This check fails if CrowdStrike is missing, has been stopped, or is not working correctly.
How do I fix this?
Installing or repairing CrowdStrike requires administrator rights and corporate installer packages, so IT needs to do this for you.
Important: do not try to uninstall or disable CrowdStrike. It is required on all Samsara devices, and removing it on purpose may trigger a security investigation.
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – CrowdStrike Falcon System Extension Active
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
6. System Integrity Protection Is Not Enabled
Why is this a problem?
System Integrity Protection (SIP) is a built-in macOS feature that stops malicious software from changing critical system files. Turning SIP off significantly weakens your Mac's defenses and means it no longer meets Samsara's minimum security requirements.
How do I fix this?
SIP must stay on at all times on Samsara devices. Re-enabling it requires starting your Mac in Recovery mode, so IT will walk you through it.
If you turned SIP off yourself to install software or troubleshoot something, let the #help-biztech team know — they can help you find another way to do what you needed.
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – Require System Integrity Protection to Be Enabled
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
7. Screen Lock Is Not Configured Securely
Why is this a problem?
Your Mac must lock its screen automatically after a short period of inactivity. Screen lock is a simple but important protection: it stops anyone from using your Mac and reading company data when you step away.
How do I fix this?
- Click the Apple menu in the top-left corner of your screen and choose System Settings.
- Click Lock Screen in the sidebar.
- Set Require password after screen saver begins or display is turned off to After 1 minute.
- Close the window when you are done.
Still not working?
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – Require Screen Lock Password
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
8. Required Device Certificate Is Missing
Why is this a problem?
A device certificate is a unique digital ID for your Mac. Samsara's systems use it to confirm your Mac is a trusted, company-managed machine before granting access to internal tools. Without it, your Mac cannot be verified and you may lose access to company applications. This check fails if the certificate is missing, expired, or was never installed correctly.
How do I fix this?
The certificate is installed automatically by SimpleMDM during setup, so you should not need to install it yourself. This check usually fails because:
- Your Mac was recently re-enrolled or erased.
- The certificate expired and has not renewed yet.
- Your Mac was offline for a while — for example, after vacation — and has not fetched the updated certificate.
Try this first:
- Connect your Mac to the internet.
- Wait 10–15 minutes so SimpleMDM can install the certificate.
- Try signing in again.
Still not working?
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – Required Device Certificate Is Installed
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
9. Chrome Browser Is Not Up to Date
Why is this a problem?
Google Chrome must be updated to a supported version. Chrome releases frequent updates that fix security flaws attackers use to reach your device or steal information. Running an outdated Chrome puts both your data and Samsara's systems at risk. This check fails if your Chrome version is below Samsara's minimum.
How do I fix this?
On Samsara-managed Macs, Chrome updates are delivered automatically, and you will usually be prompted to update.
First, check for a managed update:
- Open Finder and search for Managed Software Center.
- Click Updates in the sidebar.
- If Chrome is listed, click Update All.
- Relaunch Chrome once the update finishes.
If Chrome is not listed, update it manually:
- Open Google Chrome.
- Click the three-dot menu (⋮) in the top-right corner.
- Go to Help → About Google Chrome.
- Chrome checks for and downloads any available update automatically.
- Click Relaunch to finish.
Still not working?
Post in the #help-biztech Slack channel and include:
- Device serial number (for example,
HJ6TX66C9N) - Operating system and version (for example, macOS 15.3.1)
- Check name: macOS – Chrome Browser Version
- Source: Okta Device Assurance
- When the problem started, and anything that changed recently
Comments
0 comments
Article is closed for comments.