<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Can FIDO2(WebAuthn) Keys Be Used with Both the Default Okta Domain and a Custom Domain
Okta Classic Engine
Multi-Factor Authentication
Okta Identity Engine
Overview

When enabling the FIDO2 Web Authentication (WebAuthn) factor on the *.okta.com URL, access to the organization will only be granted through that URL. On the other hand, if the FIDO2 (WebAuthn) factor is set up using a custom URL for the Okta organization, access will only be permitted via that custom URL.

Applies To
  • Multi-Factor Authentication (MFA)

  • Custom Domain
Solution

To use both URLs, it is necessary to enroll the WebAuthn authenticator twice: once for the custom domain and once for the default Okta domain. It is required to specify the Okta organization domain, a custom domain, or a registrable suffix of a custom domain. Once this configuration is complete, users will be able to authenticate using passkeys or security keys across the designated domain and all associated sub-domains.

 

Related References

Loading
Can FIDO2(WebAuthn) Keys Be Used with Both the Default Okta Domain and a Custom Domain