You can easily export one or more FIDO Policies, along with their dependencies. This enables you to freely experiment with different variations of a policy in your development environment as well as copying a tested and curated policy to your production environment. Dependencies for a FIDO policy include authenticator groups and authenticator metadata.
Exporting
Using the Admin Console
Login to the Admin Console and, if needed, switch to the tenant whose FIDO Policy you want to export.
Navigate to Authentication > FIDO Policies.
To export all active FIDO policies, click Export Active.
To export a specific policy, either in an active or draft status, locate the policy in the table and, in the same row, click the download icon in the Actions column.
The Export Policy dialog appears.
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A54%3A59Z&se=2026-09-30T04%3A07%3A59Z&sr=c&sp=r&sig=Bk8WzONJoUb8RLDoaRmrxMZueJZu1la507fD9SHPmbc%3D)
To include all the authenticator groups that a policy uses, select the With dependencies checkbox.
You can optionally select the Include metadata checkbox to export authenticator metadata that is referenced by the policy. This option is only valid if you checked With dependencies. Use this option in limited situations, such as when you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 installation. Normally, you should use the instructions in Update Authenticator Metadata to import metadata.
Click Export.
If you are exporting one or more policies without dependencies or authenticator metadata, the Admin Console saves the policies in a JSON file.
If you are exporting policies with their dependencies (and metadata), the Admin Console saves all the objects in a ZIP file.
Using nnl-mgmt.sh
Use the nnl-mgmt.sh policy export command. The following example exports the test1 FIDO policy from the finance tenant into test_directory. The resulting file is a JSON file.
./nnl-mgmt.sh policy export -name test1 -dir test_directory -tenantid financeFor details on the nnl-mgmt.sh policy export command, see FIDO Policy Commands in the reference to Command Line Interface. There are additional parameters to this command to export authenticator groups and authenticator metadata.
Importing
Using the Admin Console
Login to the Admin Console and, if needed, switch to the tenant where you want to import the FIDO Policy.
Navigate to Authentication > FIDO Policies. To import from a policy file, click Import.
The Import Policies dialog appears.
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A54%3A59Z&se=2026-09-30T04%3A07%3A59Z&sr=c&sp=r&sig=Bk8WzONJoUb8RLDoaRmrxMZueJZu1la507fD9SHPmbc%3D)
To select the policy file for import, click Choose File and navigate to the file’s location. If the file is larger than 512 KB, you need to use ./nnl-mgmt.sh to change the default maximum size. See Note below.
If the policy file is a ZIP file, you can optionally use the checkboxes in this dialog.
To overwrite policies and dependent objects with the same name, select the Overwrite any existing policy with the same name checkbox. Overwrite handles objects differently depending on their type and status, as shown in the table below.
Object | Status of Existing Object | Result |
|---|---|---|
FIDO Policy | draft | The system overwrites the existing FIDO policy with the one from the file and maintains its status as draft. |
active | The system overwrites the existing FIDO policy with the one from the file and changes its status to active. | |
Authenticator Groups | N/A | The system overwrites the existing authenticator group with the one from the file. This is true even if the authenticator group is being used by a different active FIDO Policy. |
You can optionally select the Import and overwrite metadata checkbox to import authenticator metadata. Use this option in limited situations, such as you intend to use authenticator metadata that was only in a development deployment in a production deployment. Remember, authenticator metadata is accessible to all tenants in an S3 Suite installation and overwriting metadata could have unintended consequences. Normally, you should use the instructions in Update Authenticator Metadata to import metadata.
Change the default maximum policy size by using nnl-mgmt.sh to update the nnl.policies.file.size.kb property for the Admin tenant, as shown below.
Changing the maximum size of the ruleset file to 1024 KB:
./nnl-mgmt.sh properties set -name nnl.policies.file.size.kb -value 1024 -tenantid AdminUsing nnl-mgmt.sh
Use the nnl-mgmt.sh policy import command. The example below imports the FIDO policies and their dependent objects into the tenant with ID NorthAmerica.
./nnl-mgmt.sh policy import -file EuropePolicies.zip -tenantid NorthAmerica -overwrite yesFor details on nnl-mgmt.sh's policy import command, see FIDO Policy Commands in the reference to Command Line Interface. There are additional parameters to this command to import authenticator metadata.