How to Enroll Multiple FIDO2 MFA Options
Last Updated:
Overview
This article explains how to enable the FIDO2 (WebAuthn) factor and how users can enroll in it.
Applies To
- Multi-factor Authentication(MFA)
- Okta Classic Engine
Solution
- Navigate to Security > Multifactor.
-
Activate FIDO2 (WebAuthn) for Classic Engine.
Select Add Authenticator and add FIDO2 (WebAuthn). -
Click on Factor Enrollment.
-
Make FIDO2 (WebAuthn) either optional / required for the correct policy. If the factor is required, the user will be prompted to enroll in that factor the next time they log in. Otherwise, they will be prompted to they will be given the option to enroll in that factor, but they can skip it. At any point, the user can enroll in that factor from their end-user dashboard.
-
Click My end user dashboard (from the 4 squares symbol - top right-hand side).
-
Click {My name} and then Settings.
-
Navigate to the Extra Verification section.
-
Click Setup for FIDO2.
-
If enrolling for a fingerprint, continue through the process.
-
To enroll a security key, click cancel on the fingerprint screen and follow the process.
-
