Inability to Enroll Windows Hello as Authentication Factor for User(s)
Okta Classic Engine
Multi-Factor Authentication
Overview
The Windows Hello second factor enrollment has been removed from a user or multiple users.  They are also unable to re-enroll Windows Hello as a factor.
Applies To
  • Windows 10 1903 or later
Cause

Windows 10 1903 utilizes the FIDO2/WebAuthn protocol for Windows Hello.  The former proprietary Windows Hello factor is no longer compatible with 1903 and later.

Solution

Enable Web Authentication as a multi-factor and enroll impacted users:

  1. If Windows Hello is still active as a factor, deactivate it in the Okta Admin Console under Security > MultiFactor > Factor Type > Windows Hello and select Deactivate. Windows Hello and FIDO2 (WebAuthn) are not compatible.

  2. Open a case with support to enable the WebAuthn feature.

  3. Work with end-user(s) to re-enroll as FIDO2/WebAuthn.

Recommended content

No recommended content found...