Enroll a WebAuthn device, such as a USB security key, so the user can complete offline multifactor authentication with a FIDO device.
Note:The user must perform this procedure during an active Windows Authentication Client sign-in session while the device has an active network connection.
Requirements
- The WAC offline policy assigned to the user in RapidIdentity
- A Windows machine with TPM 2.0 enabled
- A FIDO device, such as a USB security key
The FIDO device is registered for offline access, and the system stores the public key. At the next offline sign-in, the Windows Authentication Client prompts the user for WebAuthn and the password.
To manage an enrolled device, click WebAuthn and select the device from the list:
- To rename the device, click Edit, enter a new name, and click Save.
- To remove the device from local storage, click Delete.