FIDO2 Authenticators
FIDO2 is an authentication standard from the FIDO Alliance. FIDO2 authenticators include on-device authenticators, such as Windows Hello or Mac Touch ID, and external security keys, such as a YubiKey. Passkeys are FIDO2 credentials. MFA always requires setting up an authentication profile and setting up an identity policy linked to that authentication profile. To use a FIDO2 authenticator, you must set it up in your user profile, your authentication profile, and your identity policy.
In your User Profile, set up your personal FIDO key.
Click your user icon > Account details > Security tab > FIDO2 > configure > Save.
In the Authentication profile you're going to use, add FIDO2 authenticator as an authentication challenge.
Click Settings > Authentication profiles > select the profile > Edit > select FIDO2 authenticator > Save.
In the Identity policy linked to the authentication profile you're going to use, select Enable users to enroll FIDO2 authenticators.
Click Access > Identity policies > select the policy > User security tab > Authentication settings sub-tab > Edit > Enable users to enroll FIDO2 authenticators > Save.