FIDO2 passwordless authentication enables you to identify and authenticate a user based on the FIDO2 protocol without requiring the user to enter their username and password.
To configure FIDO2 passwordless authentication, you must configure a PingFederate policy for a passwordless authentication flow. FIDO2 must then be enabled in the administrative console.
The process of registering a FIDO2 passkey is the same for both a passwordless and a multi-factor authentication flow. The user is directed to the relevant flow, according to your organization’s configuration. Once registered, the same FIDO2 passkey can be used to authenticate with either flow.
This feature requires PingFederate 9.3 or later. For more information, see FIDO2 authentication requirements and limitations.