Use the App Attest service to provide assurance that client apps connecting to the Auth Server are valid instances of your apps. App Attest asserts that the authenticator has attestation and the app is legitimate. The Auth Server uses the App Attest service for both registration and authentication. For more information, see Establishing your app’s integrity | Apple Developer Documentation.
When considering whether or not to use the App Attest service, weigh the security requirements of your app against the processing overhead of using the App Attest service. If the App Attest service is fielding too many requests, it could throttle incoming traffic. Older Apple devices do not support App Attest, so evaluate how many of your customers will benefit from this service.
To configure the S3 Suite to use the App Attest service, you need to
You must register an App ID for each iOS app that uses App Attest on the Apple Developer website. You need the Team ID of your Apple Developer Account to configure your iOS App. This can be found at https://developer.apple.com/account/<your membership number>/membership/.
Update Your Policy to Require App Attest
You can only update a draft policy. If the policy that you want to modify is active, then copy the policy and make your modifications. A policy must be active in order to be used.
In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Authentication > FIDO Policies.
On the Policies page, copy the active policy you want to modify. In the Actions column for that policy, click
(copy). The Policy Details page opens, rename your new policy.In addition to letters and digits, only the following characters are allowed in a policy name: hyphen (-), forward slash (/), underscore (_) and space ( ).
Scroll down to the FIDO UAF Authenticators panel. Select both the Request App Attest Credential and Reject if missing or invalid checkboxes. The latter checkbox ensures that the App Attest credential is required.
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A53%3A28Z&se=2026-09-30T04%3A05%3A28Z&sr=c&sp=r&sig=qIU4BQJV%2BPbKuc5bTZ3SZBc0t7rc0zMajkxB5FJRjlo%3D)
If your policy includes the FIDO2 protocol, scroll down to the FIDO2/WebAuthn Authenticators panel. Select both the Request App Attest Credential and Reject if missing or invalid checkboxes. The latter checkbox ensures that the App Attest credential is required.
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A53%3A28Z&se=2026-09-30T04%3A05%3A28Z&sr=c&sp=r&sig=qIU4BQJV%2BPbKuc5bTZ3SZBc0t7rc0zMajkxB5FJRjlo%3D)
Save your policy.
To activate your policy, on the Policies page, look for the row containing your policy. Click
(activate) in the Actions column.
Configure an iOS App to Use App Attest
Use the Admin Console to update your iOS App.
Login to the Admin Console and, if needed, switch to the desired tenant. Navigate to Configuration > Apps.
The Apps page appears. Find your app in the list and either click its name or the
(edit) icon at the end of its row..png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A53%3A28Z&se=2026-09-30T04%3A05%3A28Z&sr=c&sp=r&sig=qIU4BQJV%2BPbKuc5bTZ3SZBc0t7rc0zMajkxB5FJRjlo%3D)
The App page appears. Enter your Team ID and save.
.png?sv=2026-02-06&spr=https&st=2026-09-30T03%3A53%3A28Z&se=2026-09-30T04%3A05%3A28Z&sr=c&sp=r&sig=qIU4BQJV%2BPbKuc5bTZ3SZBc0t7rc0zMajkxB5FJRjlo%3D)