<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
"The user agent does not support public key credentials" Error During MFA Enrollment on Mobile Devices
Okta Classic Engine
Devices and Mobility
Okta Identity Engine
Overview

This article provides additional information about the error message end users receive when they try to enroll WebAuthn or FIDO2 Biometric MFA factors on their mobile devices:

 

The user agent does not support public key credentials

 

Error Message

Applies To
  • Multi-Factor Authentication (MFA)
Cause

All users will encounter an error message, regardless of their account privileges or Okta tenant Engine. If end-users attempt to enroll biometric MFA factors on their mobile devices, the above error message will be displayed.

Solution

The WebAuthn authentication flow and/or MFA enrollment process are not supported on Android Mobile devices since the Android platform only supports CTAP1 (U2F) authenticators. Android supports clients (browsers) that make WebAuthn requests to a relying party.

 

NOTE: CTAP stands for Client to Authenticator Protocol.

 

To avoid this issue, please make sure that the authentication flow performed on an Android Mobile device is not evaluated by a Policy that requires a mandatory Biometric MFA factor.

For additional information on WebAuthn Compatibility, please take a look at WebAuthn Compatibility.

 

Related References

Loading
"The user agent does not support public key credentials" Error During MFA Enrollment on Mobile Devices