
KerryK.85181 (Customer) asked a question.
We are leveraging autopilot enrollment for Apple devices in our UEM platform (VMware Workspace ONE). WS1 is integrated with Okta for user provisioning and authentication. The scenario we’re trying to build is:
- New employee is onboarded into AD and JIT provisioned into Okta
- Pre-enroll FIDO2 hardware token (YubiKey) for new user
- Apple laptop and YubiKey ship directly to end-user (Apple Business Manager points laptop to WS1 during activation)
- Laptop begins UEM enrollment by prompting user to authenticate (via Okta)
- Username and PW entered then challenged for MFA (only FIDO2 enabled)
- End-user inserts YubiKey and successfully authenticates, Okta groups dictate UEM groups and policies are applied
- Enrollment completes
We can build this same scenario with Okta Verify Push in place of FIDO2 and it works perfectly. But when we change to FIDO2, MFA never completes and simply displays an error Operation failed.
I suspect this might be an issue with the mini-browser window that launches for the Okta authentication but can’t check any logs since the laptop is not fully functional since it has not completed enrollment.
This is obviously a very specific use-case but wondering if anyone has successfully implemented an Okta-integrated UEM autopilot enrollment process with FIDO2 hardware tokens.
Thanks!

Hi @KerryK.85181 (Customer) , Thank you for reaching out to the Okta Community!
I wasn't able to locate any similar reports of issues with the enrollment.
Maybe it's a long shot but you mentioned the use case is for Apple devices.
There's mention in the following documentation about
" • The FIDO2 (WebAuthn) authenticator may not function correctly using the Safari browser on Apple Macintosh computers running on the Apple M1 processor. " - under Browser-specific Considerations
https://help.okta.com/oie/en-us/Content/Topics/identity-engine/authenticators/configure-webauthn.htm
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Community members help others by clicking Like or Select as Best on responses. Try it today.
Thanks Mihai! That link applies to OIE. We're on Okta Classic Engine. Do you know if the same limitations apply?
For what it's worth, I do think this is an issue with the mini-browser that launches during the activation / enrollment process. But was hoping that there might be a workaround somewhere.
Thanks again!
Kerry
Sorry I missed the Okta Classic Engine part, but I would expect the same applies for it.
I've tracked down the appropriate docs for it:
https://help.okta.com/en-us/Content/Topics/Security/mfa-webauthn.htm
https://help.okta.com/en-us/Content/Topics/Security/mfa/webauthn-compatibility.htm
Beyond that, you will have to open a support case to have the issue properly investigated.