With FIDO passwordless authentication, you can customize settings to match your environment, such as changing the expiration period of the registration URL or restricting which authenticators can be used.
This page explains how to configure these settings.
Log in toTrustLogin, open the "Admin Page > Settings > Optional Features" menu,
and click the "Settings" button to the right of "FIDO Passwordless Authentication."
Click the arrow inside the red box to expand the settings screen. Click "Edit" to change the settings. After you finish changing the settings, click "Save" to apply them.
FIDO Option Settings:
Registration URL Validity Period (Default: 1 day):
You can set the validity period of the URL used to register an authenticator. (1-30 days)
Start date for the validity period: the date the email is sent(when the feature is assigned, or when the email is resent)
Note: If the email is resent, the previous URL becomes invalid.
Validity check : The URL is valid if it is accessed within the configured number of days from the start date
Maximum Number of Registered FIDO Authenticators (Default: 10):
You can set the maximum number of authenticators that a single user can register. (1-10)
Notify Assigned Members (Default: On):
When a member or group is added, an email is sent to the assigned member, or to members belonging to the assigned group,
titled "Please Register Your Authenticator for FIDO Passwordless Authentication."
When disabled, no notification email is sent to the target user at the time of assignment.
If the administrator wants to send the email manually, click here
Allow Members to Register Authenticators (Default: Off):
When enabled, members can register authenticators from their profile screen.
When disabled, members cannot register authenticators.
Allow Members to Edit Authenticator Names (Default: Off)
When enabled, members can edit authenticator names from their profile screen.
When disabled, members cannot edit authenticator names.
Allow Members to Delete Authenticators (Default: Off)
When enabled, members can delete authenticators from their profile screen.
When disabled, members cannot delete authenticators.
Authenticators Allowed for Use:
Internal/External Authenticator Designation (Default: Allow both built-in and external authenticators):
|
Built-in (Platform) Authenticator: Authentication built into the device used to log in Example: Windows Hello, macOS Touch ID, iPhone Face ID/Touch ID, Android face/fingerprint authenticator External (Roaming) Authenticator: A dedicated authentication device connected via USB, NFC, or Bluetooth to the device used to log in Example: Security key devices such as YubiKey, iePass K44, and ATkey.Pro |
If you want to restrict the authenticators used to only built-in or only external types, change the setting to the authenticator type you want to allow.
User Verification Designation (Default: Allow authenticators without user verification):
If you want to allow only authenticators with a security key's user verification feature (fingerprint authentication, PIN), change the setting to
"Allow only authenticators with user verification."
If a registration operation is attempted with an authenticator that does not have user verification, the following message is displayed and registration cannot be completed. (The screen shown is for Windows.)
Restrict the Security Key Models You Use (Registering AAGUID (Authenticator Identifier)):
AAGUID is an identifier assigned to external authenticators. In general, the same AAGUID is assigned to each authenticator model.
By registering an AAGUID, you can restrict which authenticators can be used for TrustLogin authentication.
Note: Please be aware that some models do not have an AAGUID assigned.
Note: Once you register an AAGUID, authenticators that are not allowed can no longer be used. Please be careful.
- Click "Register AAGUID (Authenticator Identifier)."
- Enter the AAGUID directly, or click "Get AAGUID from Device."
- Example: Steps to register an external authenticator using Chrome on a Windows device
Note: The displayed content and screen flow may differ depending on your device and browser.
A "Create a passkey" pop-up will appear; select "Windows Hello or external security key."
- Click "OK."
- Click "OK."
- Insert the authenticator into a USB port.
- Enter the authentication method configured on the authenticator (the screen image shows a PIN).
Note: This may differ depending on the authentication method configured on the authenticator.
- Once authentication on the authenticator is complete, the AAGUID is retrieved. Click "Add."
- You can check the registered information from the AAGUID List tab on the Admin Page.