- 
Requesting FIDO2 token on Defender Self-Service Portal
 - 
Register token on ISAPI [One time operation]
 - 
Authenticate/Login using FIDO2 registered token
 
Requesting FIDO2 Token program on the Defender Self-Service Portal
- 
Click on Request FIDO2 Token tile.
 - 
Click on Program Token button.
 - 
User should enter FIDO2 token Name:
- 
Should be at least four characters
 - 
Special character and space are not allowed.
 - 
Maximum length of 40 characters
 - 
Underscore (_) is allowed
 
 - 
 - 
Click on Next and window will display success message.
 - 
FIDO2 token will appear in assigned token list of user with unique ID.
 - 
FIDO2 tokens cannot be re-registered.
 - 
In case an unregistered FIDO2 token is already present on the user’s assigned token list, they cannot request a new token from the portal.
 
For more information, see Registering a hardware token.
To register a FIDO2 Token
FIDO2 tokens can be registered on ISAPI before authentication for the first time. This is a onetime operation.
- 
If FIDO2 tokens are already assigned to users, FIDO2 Registration screen will display list of unregistered FIDO2 tokens.
 - 
Users need to select any one unregistered FIDO2 token to register.
 - 
Users need to enter serial number of Token in serial number field.
- 
Should be at least four characters
 - 
Special character and space are not allowed.
 - 
Maximum length of 40 characters
 - 
Underscore (_) is allowed
 
 - 
 - 
After entering the AD password, users need to click on Register button and browser pop-up will appear asking user to insert and touch on FIDO2 compatible YubiKey to complete the registration of FIDO2 token.
 - 
On successful registration, Login screen will appear for users to continue to authenticate.
 - 
During registration, users can authenticate using other assigned tokens by clicking on Sign in with another option, if they do not want to use FIDO2 token.
 - 
In case users have at least one already registered FIDO2 token, they need to click on the register button to register any unregistered tokens.
 
To login using a FIDO2 Token
- If user has registered FIDO2 tokens, they can initiate the login process by entering username on the login screen.
 - On next screen, list of registered FIDO2 tokens will appear in combo list for User to
 - Select one to continue authentication. If user has a single registered FIDO2 token, the browser pop-up will appear directly.
 - After selecting registered FIDO2 token, on click of Sign in, browser pop-up will appear asking user to insert and touch the FIDO2 compatible YubiKey to match credentials stored while registration.
 - Users need to touch the YubiKey within 20 seconds once browser po-up appears for user input. On timeout, user can either reload session to continue login with FIDO2 token or choose Sign in with another option.
 - If credentials match, user will be logged in to ISAPI.
 
For more information, see Registering a hardware token.