The Admin Console is a special web app. You use it to configure the authentication behavior for client apps you develop on a tenant-by-tenant basis but you can also use it to configure authentication behavior used by the Admin Console itself. For example, you can restrict your administrative users to login using a FIDO face authenticator by creating a FIDO UAF authentication policy that only contains face authenticator AAIDs.
When you install the Auth Server, it automatically creates an Admin tenant. This tenant contains the information necessary to configure the Admin Console. The Admin tenant has a preconfigured default FIDO policy, described in the next section, that controls which authenticators administrative users are allowed to register and authenticate with. You can configure the Admin Console to use Adaptive Authentication and Quick Authentication. You can manage operational tasks for the Admin Console, such as deleting transient and managing inactive registrations.
The Admin Console's default FIDO policy
For security reasons, the default FIDO policy requires the use of strong FIDO authentication backed by hardware key protection. This policy disallows all UAF presence and silent authenticators. It only allows authenticators with user verification that employ a hardware keystore.
The requirements for FIDO2 authenticators are summarized below and you can refer to the diagrams below for a succinct review of the default policy.
Both platform and cross-platform authenticators are allowed.
User verification is enforced to allow for additional factor authentication, like a PIN-based YubiKey. All admin users must be verified.
Digipass S3 strongly discourages changing the user verification requirement or disabling the enforcement of user verification because this compromises security for the Admin Console. If you have concerns about privacy, you can make the policy more strict. Digipass S3 recommends making a copy of the default policy and modifying the copy. See Configuring FIDO2 Authenticators for detailed descriptions of the FIDO2 authenticator attributes and instructions on how to modify a policy.
.png?sv=2026-02-06&spr=https&st=2026-09-30T02%3A58%3A43Z&se=2026-09-30T03%3A09%3A43Z&sr=c&sp=r&sig=Q8qMZCQm8WXYDBuqdn0Pm5daK9ALyLe7aqrQkFRXcps%3D)
