---
title: Configuring FIDO2 authentication (Passkeys)
description: You can configure FIDO2 devices as an authentication method. FIDO2 devices include passkeys, FIDO2 biometrics, and security keys.
component: pingone
page_id: pingone:strong_authentication_mfa:p1_strong_auth_configuring_fido
canonical_url: https://docs.pingidentity.com/pingone/strong_authentication_mfa/p1_strong_auth_configuring_fido.html
revdate: September 5, 2024
section_ids:
  before-you-begin: Before you begin
  about-this-task: About this task
  steps: Steps
---

# Configuring FIDO2 authentication (Passkeys)

You can configure FIDO2 devices as an authentication method. FIDO2 devices include passkeys, FIDO2 biometrics, and security keys.

## Before you begin

To add FIDO2 as an authentication method, you need:

* A PingOne environment. The authentication policy should include the relevant MFA policy.

|   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| - | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|   | FIDO2 biometrics and security keys are legacy authentication methods and must be updated to support FIDO2 authentication. Learn more: [Updating an existing MFA policy to use FIDO2](p1_updating_an_mfa_policy_to_fido2.html), and for legacy PingID accounts, see [Updating a PingID account to use PingOne FIDO2 policy for Passkey support](https://docs.pingidentity.com/pingid/pingid_service_management/pid_update_to_fido2_authentication_method.html). |

## About this task

Learn more about FIDO2 authentication in [FIDO policies](../authentication/p1_fido_policies.html).

Adding FIDO2 as an authentication method involves the following steps:

## Steps

1. [Configuring a FIDO2 policy](../authentication/p1_creating_a_fido_policy.html).

2. [Configure the MFA policy to include the FIDO2 authentication method, and include the relevant FIDO2 policy](p1_creating_an_mfa_policy_for_strong_auth.html).
