Accept the default value of Enabled for the field Authenticate with user name. Do this regardless of the client your apps are implemented on. In particular, this fixes a limitation with how the old Android FIDO2 API handles native FIDO2 by enabling an authentication flow in which the username is known up front.
If your organization wants to hide the user's FIDO2 registrations, activate the API Server's Privacy Credential Generator plugin.
You can perform both these actions using the Admin Console.
Login to the new tenant. Navigate to Configuration > API Server > Session Plugins.

Click the value for Authentication with the user name and select Enabled.
To hide the user's FIDO registrations, find the Privacy Credential Generator label and click its Modify button. Click the Generate button and confirm that you want to generate a new configuration object. Click Activate if the plugin is deactivated.
You can view the current configuration by clicking the Privacy Credential Generator label.