Okta FIDO2 WebAuthn Login Fails Due to Missing YubiKey AAGUID in Allowlist
Last Updated:
Overview
FIDO2 (WebAuthn) login fails when the authenticator configuration restricts access to specific Authenticator Attestation Globally Unique Identifiers (AAGUID) and the user's security key model is missing from the allowlist. Add the missing AAGUID to the FIDO2 (WebAuthn) authenticator configuration in the Okta Admin Console to resolve this issue. The System Log displays the following error:
AllowList is setup that does not allow this factor's aaguid.
Applies To
- Okta Identity Engine (OIE)
- Multi-Factor Authentication (MFA)
- FIDO2 (WebAuthn)
- Security Keys
Cause
This issue occurs when administrators configure the FIDO2 (WebAuthn) authenticator with an allowlist that explicitly defines permitted security key models. Okta rejects the authentication attempt if a user attempts to use a security key with an AAGUID missing from this list. This commonly happens when users acquire newer key models, such as newer firmware versions of YubiKeys, that possess different AAGUIDs than the older models already present on the allowlist.
Solution
How is the missing AAGUID added to the allowlist?
Identify the missing AAGUID from the System Log and add it to the FIDO2 (WebAuthn) authenticator configuration in the Okta Admin Console by following these steps.
- Identify the missing AAGUID from the System Log.
- Navigate to Security > Authenticators in the Okta Admin Console.
- Locate the FIDO2 (WebAuthn) authenticator and select Actions > Edit.
- Scroll to the Allowed AAGUIDs configuration section.
- Select Add Authenticator.
- Enter the AAGUID retrieved from the System Log.
- Enter a description for the key in the description field.
- Select Save.
- Instruct the user to retry the login to verify successful authentication without requiring re-enrollment.
