-
Requesting FIDO2 token on Defender Self-Service Portal
-
Register token on ISAPI [One time operation]
-
Authenticate/Login using FIDO2 registered token
Requesting FIDO2 Token program on the Defender Self-Service Portal
-
Click on Request FIDO2 Token tile.
-
Click on Program Token button.
-
User should enter FIDO2 token Name:
-
Should be at least four characters
-
Special character and space are not allowed.
-
Maximum length of 40 characters
-
Underscore (_) is allowed
-
-
Click on Next and window will display success message.
-
FIDO2 token will appear in assigned token list of user with unique ID.
-
FIDO2 tokens cannot be re-registered.
-
In case an unregistered FIDO2 token is already present on the user’s assigned token list, they cannot request a new token from the portal.
For more information, see Registering a hardware token.
To register a FIDO2 Token
FIDO2 tokens can be registered on ISAPI before authentication for the first time. This is a onetime operation.
-
If FIDO2 tokens are already assigned to users, FIDO2 Registration screen will display list of unregistered FIDO2 tokens.
-
Users need to select any one unregistered FIDO2 token to register.
-
Users need to enter serial number of Token in serial number field.
-
Should be at least four characters
-
Special character and space are not allowed.
-
Maximum length of 40 characters
-
Underscore (_) is allowed
-
-
After entering the AD password, users need to click on Register button and browser pop-up will appear asking user to insert and touch on FIDO2 compatible YubiKey to complete the registration of FIDO2 token.
-
On successful registration, Login screen will appear for users to continue to authenticate.
-
During registration, users can authenticate using other assigned tokens by clicking on Sign in with another option, if they do not want to use FIDO2 token.
-
In case users have at least one already registered FIDO2 token, they need to click on the register button to register any unregistered tokens.
To login using a FIDO2 Token
- If user has registered FIDO2 tokens, they can initiate the login process by entering username on the login screen.
- On next screen, list of registered FIDO2 tokens will appear in combo list for User to
- Select one to continue authentication. If user has a single registered FIDO2 token, the browser pop-up will appear directly.
- After selecting registered FIDO2 token, on click of Sign in, browser pop-up will appear asking user to insert and touch the FIDO2 compatible YubiKey to match credentials stored while registration.
- Users need to touch the YubiKey within 20 seconds once browser po-up appears for user input. On timeout, user can either reload session to continue login with FIDO2 token or choose Sign in with another option.
- If credentials match, user will be logged in to ISAPI.
For more information, see Registering a hardware token.