FIDO Passwordless Authentication User Manual

This page explains the overview of FIDO passwordless authentication, the setup flow, and important notes.
Please review this page before proceeding with setup.

Table of Contents:

About FIDO Passwordless Authentication

Usage Procedure

List of FIDO Passwordless Authentication Setup Guides

FAQ

Important Notes

What Is FIDO Passwordless Authentication?

This feature lets you authenticate without a password using a FIDO authenticator when logging in to TrustLogin.
Up to 10 authenticators can be registered per user.
Note: A TrustLogin PRO plan subscription is required to use this feature. For pricing details, click here

Usage Procedure

Setup requires action from both the administrator and the member (the authenticator user). The basic setup flow is as follows.

 ① Administrator: Assign FIDO passwordless authentication to members.

 Note: To restrict which authenticators can be used, configure the FIDO options.

 ② Member: Register a FIDO authenticator.

 ③ Member: Log in passwordlessly using the FIDO authenticator.

List of FIDO Passwordless Authentication Setup Guides

Please refer to the pages below for setup instructions.
Note that depending on your OS, device, and browser settings, actual behavior may differ from what is described in these setup guides.

1-1. (For Administrators) Assigning FIDO Passwordless Authentication and Sending Emails to Target Users
1-2. (For Administrators) Restricting Which Authenticators Can Be Used
2-1. (For Members) Registering an Authenticator [Windows]
2-2. (For Members) Registering an Authenticator [macOS]
2-3. (For Members) Registering an Authenticator [iOS]
2-4. (For Members) Registering an Authenticator [Android]
3-1. (For Members) Editing an Authenticator Name
3-2.
(For Members) Deleting an Authenticator
4-1. (For Administrators) Unassigning FIDO Passwordless Authentication and Deleting Authenticators
4-2. (For Administrators) Exporting Authenticator Registration Information to CSV
4-3. (For Administrators) Filtering the List by Registration Information
4-4. (For Administrators) Bulk Retrieval of Authenticator Registration URLs

FAQ

Q1: Which devices support FIDO passwordless authentication?

The devices that have been verified to work are as follows.

Verified Device AAGUID
Security Key by Yubico (NFC) -
GoTrust Idem Key - A. -
iePass K44
AUTHENTREND ATKey.Pro USB Type-A
YubiKey 5 NFC
YubiKey Bio - FIDO Edition
Windows 10/11 Windows Hello (fingerprint/facial recognition)
MacBook Pro: M2 Chip (TouchID)
MacBook Air: Intel chip (TouchID)
iPhone 12 Pro (FaceID)
iPhone 8 (TouchID)
iPad Air
iPhone 15 Pro Max (FaceID)
Android Pixel 7a
Android Pixel 5

Note: This reflects results at the time verification was performed and does not guarantee operation.
 In addition, depending on differences and combinations of OS versions, browser versions,
 and authenticator firmware, registering or authenticating with an authenticator may not be possible.
 Be sure to verify operation before deployment.

Important Notes

・When the FIDO option setting "Allow both built-in and external authenticators" is enabled,
 external authenticators cannot be selected on Android devices.
 Supported patterns (registering and logging in with an internal authenticator):
 - Registering an Android device as an authenticator from Android
 - Logging in using an Android device as an authenticator from Android
 Unsupported patterns (registering and logging in with an external authenticator):
 - Registering an external authenticator from Android
 - Logging in using an external authenticator from Android
Note: To use an external authenticator from Android, select "Allow external authenticators only."
 In that case, you will not be able to register another smartphone as an authenticator.


・On Windows, macOS, and iOS, FIDO authentication has been confirmed to fail during SAML authentication
 from native apps (such as Outlook for Mac or the iOS Outlook app).

FIDO Passwordless Authentication User Manual

This page explains the overview of FIDO passwordless authentication, the setup flow, and important notes.
Please review this page before proceeding with setup.

Table of Contents:

About FIDO Passwordless Authentication

Usage Procedure

List of FIDO Passwordless Authentication Setup Guides

FAQ

Important Notes

What Is FIDO Passwordless Authentication?

This feature lets you authenticate without a password using a FIDO authenticator when logging in to TrustLogin.
Up to 10 authenticators can be registered per user.
Note: A TrustLogin PRO plan subscription is required to use this feature. For pricing details, click here

Usage Procedure

Setup requires action from both the administrator and the member (the authenticator user). The basic setup flow is as follows.

 ① Administrator: Assign FIDO passwordless authentication to members.

 Note: To restrict which authenticators can be used, configure the FIDO options.

 ② Member: Register a FIDO authenticator.

 ③ Member: Log in passwordlessly using the FIDO authenticator.

List of FIDO Passwordless Authentication Setup Guides

Please refer to the pages below for setup instructions.
Note that depending on your OS, device, and browser settings, actual behavior may differ from what is described in these setup guides.

1-1. (For Administrators) Assigning FIDO Passwordless Authentication and Sending Emails to Target Users
1-2. (For Administrators) Restricting Which Authenticators Can Be Used
2-1. (For Members) Registering an Authenticator [Windows]
2-2. (For Members) Registering an Authenticator [macOS]
2-3. (For Members) Registering an Authenticator [iOS]
2-4. (For Members) Registering an Authenticator [Android]
3-1. (For Members) Editing an Authenticator Name
3-2.
(For Members) Deleting an Authenticator
4-1. (For Administrators) Unassigning FIDO Passwordless Authentication and Deleting Authenticators
4-2. (For Administrators) Exporting Authenticator Registration Information to CSV
4-3. (For Administrators) Filtering the List by Registration Information
4-4. (For Administrators) Bulk Retrieval of Authenticator Registration URLs

FAQ

Q1: Which devices support FIDO passwordless authentication?

The devices that have been verified to work are as follows.

Verified Device AAGUID
Security Key by Yubico (NFC) -
GoTrust Idem Key - A. -
iePass K44
AUTHENTREND ATKey.Pro USB Type-A
YubiKey 5 NFC
YubiKey Bio - FIDO Edition
Windows 10/11 Windows Hello (fingerprint/facial recognition)
MacBook Pro: M2 Chip (TouchID)
MacBook Air: Intel chip (TouchID)
iPhone 12 Pro (FaceID)
iPhone 8 (TouchID)
iPad Air
iPhone 15 Pro Max (FaceID)
Android Pixel 7a
Android Pixel 5

Note: This reflects results at the time verification was performed and does not guarantee operation.
 In addition, depending on differences and combinations of OS versions, browser versions,
 and authenticator firmware, registering or authenticating with an authenticator may not be possible.
 Be sure to verify operation before deployment.

Important Notes

・When the FIDO option setting "Allow both built-in and external authenticators" is enabled,
 external authenticators cannot be selected on Android devices.
 Supported patterns (registering and logging in with an internal authenticator):
 - Registering an Android device as an authenticator from Android
 - Logging in using an Android device as an authenticator from Android
 Unsupported patterns (registering and logging in with an external authenticator):
 - Registering an external authenticator from Android
 - Logging in using an external authenticator from Android
Note: To use an external authenticator from Android, select "Allow external authenticators only."
 In that case, you will not be able to register another smartphone as an authenticator.


・On Windows, macOS, and iOS, FIDO authentication has been confirmed to fail during SAML authentication
 from native apps (such as Outlook for Mac or the iOS Outlook app).