Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configure FIDO2 as an MFA factor

Configure policy input and condition to display FIDO2 as an MFA factor policy for authentication.

Before you begin

Role required: adaptive_auth_admin

Procedure

  1. Navigate to All > Multi-factor Authentication > MFA Context.

  2. Select the MFA Factor Policies tab.

  3. Select the Display FIDO2 as an MFA Factor Policy.

  4. Select New to add Policy Inputs.

  5. Select the filter criteria that you want to create.

    Following are the types of filter criteria:

Image omitted: mfa-email-filter.png
Filter Criteria.
  1. Select Role Filter Criteria, fill the fields for the role filter criteria and submit the record.

    The new policy is created. For more information, see Role Filter Criteria.

    Let's take an example of using ITIL role for the user (andrew.och) as the policy input and submit.

Image omitted: mfa-fido-itil-role.png
Policy input
  1. On the Policy - Display FIDO2 as an MFA Factor Policy page, select Policy Conditions.

  2. Select New to add policy conditions.

  3. On the form, fill in the fields.

FieldDescription
LabelName to identify the condition.
DescriptionDescription of the condition.
ConditionLogical combination of multiple policy inputs \(filter criteria\) that is used to evaluate authentication requests.Select the role-based filter criteria policy that was created for the condition.
Image omitted: mfa-fido-itil-role-condition.png
MFA FIDO - Policy conditions
  1. Select Submit.

    Based on the policy input and condition, if the user (andrew.och) tries to log in to the instance, the user is shown as the FIDO screen to either enroll and register.

Image omitted: biometirc-mfa.png
MFA- Biometric or Hardware keys
To know more about different configuration example and user behaviors, see [Example Configurations and User Behaviors](mfa-with-fido.md).
  1. Repeat step 8 to create additional policy conditions.

    Note: If you create multiple policy conditions, the final output of the access policy depends on the logical OR output of the all policy conditions. Based on the conditions the policy is evaluated.