
IsaacB.81593 (Customer)
Can Fido enrollment be simplified? Am I missing something?
It seems to me that one used to be able to enroll a Fido factor (security key or print reader) by just choosing that option from the available authenticators and following simple prompts. This appears to have gotten more complex. I'm trying to enroll a physical key in Chrome.
Prompt 1. "Create a passkey."
[I tried adding a screenshot, but app won't let me save the post]
As an end-user, I'd be asking "what's a passkey and I don't have time to learn what it is." Hit "continue" and I'm being prompted by my browser's print reader and it enrolls the print reader. Never offers to enroll the key.
Try "Save another way."
Prompt 2 "Choose where to save..."
[I tried adding a screenshot, but app won't let me save the post]
I figure the third choice makes sense, but I'd hate to be an end user, or the team that supports them.
Prompt 3. QR code or key.
[I tried adding a screenshot, but app won't let me save the post]
I tap the key and get enrolled. But can I keep that QR code away from my end users and simplify their path?
We have "Block synced passkeys for FIDO2 (WebAuthn) Authenticators" enabled. Org is Classic. Device is Mac Sequoia. Browser is Chrome, 100% up-to-date.
Thanks.

Hello @IsaacB.81593 (Customer) Thank you for posting on our Community page!
Enrolment should be straight forward, maybe something has been miss-configured or additional steps added to the enrolment. please see our doc below:
https://help.okta.com/oie/en-us/content/topics/identity-engine/authenticators/configure-webauthn.htm
If there are still issues I would recommend to Open a case with Support for additional assistance.
Thank you for reaching out to our Community and have a great day!
--
Help others in the community by liking or hitting Select as Best if this response helped you.