{"found":true,"collection":"facts","library_url":"https://www.grokbotdb.com/library/fact.identity.okta-rule-settings","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"fact.identity.okta-rule-settings","subject":"security","claim":"The recommended Okta rule sets Device platform to Other Desktop and Device state to Any, grants Allowed after successful authentication with Password plus another factor, and must sit above the unmanaged-device deny catch-all.","kind":"policy","status":"current","tier":"official","source_id":"src.docs.identity-and-access","source_url":"https://docs.x.ai/grok-bot/identity-and-access","quote":"Set **Device platform** to **Other Desktop** and **Device state** to **Any**.","observed_at":"2026-09-03","confidence":"high","notes":"On Classic Engine the guidance is to allow Other Desktop without requiring Device Trust equals Trusted.","first_seen":"2026-09-03","last_verified":"2026-09-03"}}