Configure the Passkeys (FIDO2 WebAuthn) authenticator
The Passkeys (FIDO2 WebAuthn) authenticator lets users authenticate with a security key or a biometric method, such as a fingerprint or face recognition. Passkeys (FIDO2 WebAuthn) follows the FIDO2 Web Authentication (WebAuthn) standard. After you enable this authenticator, users authenticate with it when they sign in to Okta or use it for extra authentication.
This authenticator provides several optional features to help you manage your Passkeys (FIDO2 WebAuthn) implementation.
- Create groups of authenticators and use them in policies.
- Manage passkeys and enroll FIDO2 security keys as part of onboarding users.
- Search the list of authenticators that Okta works with to plan equipment purchases and designate which ones are allowed in your org:
- Add your own custom authenticators.
- (Early Access) Nudge end users who haven't enrolled a passkey to do so, without blocking sign-in.
Passkeys (FIDO2 WebAuthn) is a possession and biometric or knowledge-based factor, and fulfills the requirements for phishing-resistant and user presence characteristics. Depending on your configuration, it can also fulfill the requirements for device-bound and hardware-protected characteristics. See Multifactor authentication.
Before you begin
- Review which browsers support the Passkeys (FIDO2 WebAuthn) authenticator and considerations for use. See Passkeys (FIDO2 WebAuthn) support and behavior.
- Review the FIDO Metadata Service (MDS) Authenticator Attestation Global Unique Identifier (AAGUID) list of authenticators. Verify which ones you can use with Okta before you acquire or deploy any security keys in your environment. If your authenticator doesn't appear in the FIDO MDS AAGUID list, you can add it to the custom AAGUID list. See Review and manage FIDO MDS and custom authenticators.
- Review the browser requirements:
- Update Chrome to the latest version. The Passkeys (FIDO2 WebAuthn) authenticator isn't usable if the browser requires an update.
- Encourage your end users to enroll the Passkeys (FIDO2 WebAuthn) authenticator on multiple devices. If a user loses access to one device, they can use the other to continue to retain access to their account.
- Review system requirements:
- The Passkeys (FIDO2 WebAuthn) authenticator isn't supported on MFA Credential Provider for Windows.
- When you block the use of syncable passkeys in your org, users running macOS Monterey can't enroll in Touch ID using the Safari browser.
- When you block the use of syncable passkeys in your org, iPhone users can't use the Passkeys (FIDO2 WebAuthn) authenticator. Enable Okta FastPass or security keys that support NFC or USB-C instead. Enrollments of devices running iOS 16 are supported after you block the use of syncable passkeys for non-passkey purposes.
- Re-enroll any security keys that were added before November 30, 2022.
Get started