Skip to main content
Version: 10.7.0

FIDO2 Authenticators Granular Control (UI)

Prerequisites

Before managing FIDO2 authenticator policies in the UI, ensure that:

Manage which authenticators users can register and authenticate with using AAGUID policies. Create either an allowlist (permit specific authenticators) or denylist (block specific authenticators), but not both.

Accessing FIDO2 Authenticator Policies

  1. Navigate to Control Center Settings in the left menu pane in Control Center
  2. Select the FIDO2 Settings tab
  3. Scroll down to the FIDO2 Authenticator Attestation GUID (AAGUID) Policies section

This section appears below the standard FIDO2 configuration options and includes four action buttons and a table displaying current policies.

Understanding AAGUIDs

An AAGUID uniquely identifies a FIDO2 authenticator model (e.g., YubiKey 5, Windows Hello, TouchID) in standard UUID format: 00000000-0000-0000-0000-000000000000

Policy Types: Allowlist vs Denylist

Only specified authenticators can be used; all others are blocked.

Use Cases:

  • Require specific hardware authenticators
  • Meet compliance requirements for approved devices
  • Standardize on specific authenticator models

Denylist

All authenticators are permitted except those specifically blocked.

Use Cases:

  • Block problematic or vulnerable authenticators
  • Prevent consumer-grade authenticators in enterprise settings
  • Temporarily block specific models
Important

You cannot have both policy types active simultaneously; creating one type disables the other.

Managing Authenticator Policies

Adding Authenticators

  1. Click Add to Allowlist or Add to Denylist

  2. The modal opens with two panels:

    • Left panel: Available authenticators from FIDO2 Metadata Service
    • Right panel: Selected authenticators
  3. Search and select authenticators from the left panel

  4. Review selections in the right panel

  5. Click Add to Allowlist/Denylist to save

Manual Entry (Denylist Only)

To block an authenticator not in the metadata service, enter its AAGUID in format 00000000-0000-0000-0000-000000000000 and click Submit.

Viewing Current Policies

The policies table displays AAGUID, friendly name, and status (Allowed/Blocked). Click rows to select them for bulk operations.

Removing Authenticators

Select authenticators in the table and click Remove Selected to remove them from your policy.

Removing All Policies

Click Remove All and confirm to clear all policies and return to default (all authenticators permitted).

Policy Status

  • No policies: All authenticators permitted (default)
  • Allowlist active: Only listed authenticators allowed (green status)
  • Denylist active: Listed authenticators blocked (red status)

Saving Changes

Click Save at the bottom of the FIDO2 Settings page to apply changes. Policy changes take effect immediately.