Users can authenticate through the Windows Authentication Client using the WebAuthn method when they have enrolled a FIDO2 external security key device.
Before users can authenticate with WebAuthn, an administrator must create an authentication policy with WebAuthn included as an authentication method. Users assigned to this policy can use WebAuthn to log in to the RapidIdentity portal and the Windows Authentication Client using a FIDO2 external security key. Users must also enroll their FIDO2 device in their RapidIdentity profile.
Note:The Windows Authentication Client does not support PIN codes associated with security keys. If a security key has a PIN code defined, the Windows Authentication Client and RapidIdentity ignore it. To verify the identity of the user presenting the security key, at least one additional authentication method must be configured alongside WebAuthn.
The following limitations apply to WebAuthn FIDO2 authentication through the Windows Authentication Client:
- FIDO2 with MFA is the only available authentication option for WebAuthn through the Windows Authentication Client.
- The Device tab in the Windows Authentication Client is the only way to use WebAuthn FIDO2 authentication.
- The Windows Authentication Client does not support password recovery with WebAuthn FIDO2 authentication.
- WebAuthn FIDO2 does not enforce account lockout in the Windows Authentication Client.