Most likely it relies on fully devolving all authentication to Okta via SAML proxying, in which case I'm sure it works, modulo Okta's lousy SAML compliance. Duo is an outlier in supplying just the second factor with a custom API. -- Scott