FIDO2 Authenticators

FIDO2 is an authentication standard from the FIDO Alliance. FIDO2 authenticators include on-device authenticators, such as Windows Hello or Mac Touch ID, and external security keys, such as a YubiKey. Passkeys are FIDO2 credentials. MFA always requires setting up an authentication profile and setting up an identity policy linked to that authentication profile. To use a FIDO2 authenticator, you must set it up in your user profile, your authentication profile, and your identity policy.

To configure tenant-level passkey settings, such as user verification and attestation, see Configuring Passkeys (FIDO2).

In your User Profile, set up your personal FIDO key.
Click your user icon > Account details > Security tab > FIDO2 > configure >  Save.

In the Authentication profile you're going to use, add FIDO2 authenticator as an authentication challenge.
Click Settings > Authentication profiles > select the profile > Edit > select FIDO2 authenticator > Save.

In the Identity policy linked to the authentication profile you're going to use, select Enable users to enroll FIDO2 authenticators.
Click Access Identity policies > select the policy > User security tab > Authentication settings sub-tab > Edit > Enable users to enroll FIDO2 authenticatorsSave.