Enrolling a WebAuthn Device for Offline Access - RapidIdentity Platform Documentation

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Enroll a WebAuthn device, such as a USB security key, so the user can complete offline multifactor authentication with a FIDO device.

Note:The user must perform this procedure during an active Windows Authentication Client sign-in session while the device has an active network connection.
Requirements
  • The WAC offline policy assigned to the user in RapidIdentity
  • A Windows machine with TPM 2.0 enabled
  • A FIDO device, such as a USB security key
  1. In the RapidIdentity Offline Enrollment Manager, click WebAuthn.
  2. Click Add Device.
  3. In the Device name field, enter a name for the FIDO device.
  4. In the Device PIN field, enter the PIN for the FIDO device.
  5. Click Save.
  6. When prompted, touch the FIDO device to confirm user presence.

    The system validates the signature using the stored public key to complete enrollment.

The FIDO device is registered for offline access, and the system stores the public key. At the next offline sign-in, the Windows Authentication Client prompts the user for WebAuthn and the password.

To manage an enrolled device, click WebAuthn and select the device from the list:

  • To rename the device, click Edit, enter a new name, and click Save.
  • To remove the device from local storage, click Delete.