A single FIDO policy can check the app integrity in iOS apps using Apple’s app integrity service, and that same FIDO policy can check the app integrity in Android apps using Google’s Play Integrity service. A single FIDO policy can also cover both UAF and FIDO2 protocols.
UAF protocol
You can only update a draft policy. If the policy that you want to modify is active, then copy the policy and make your modifications. A policy must be active in order to be used.
In the Admin Console, login and, if needed, switch to the desired tenant. Navigate to Authentication > FIDO Policies.
On the Policies page, copy the active policy you want to modify. In the Actions column for that policy, click
(copy). The Policy Details page opens, rename your new policy.In addition to letters and digits, only the following characters are allowed in a policy name: hyphen (-), forward slash (/), underscore (_) and space ( ).
Find the FIDO UAF Authenticators panel. Allow FIDO UAF Authenticators must be checked in order to create or modify a UAF FIDO policy. Check the Request App Attest Credential and/or check the Request Google Play Integrity Extension checkbox.

To require App Integrity for the UAF protocol, add a Post Operation Rule to your policy.
a. Under Post Operation Rules click Add Rule. Fill in the *Rule Name field, with something like “Require App Integrity for UAF”.
b. On the Post Operation Rule dialog box, set the Action to Deny, click Add Post Operation Check and set the condition to read “If App Integrity is not known”.c. Still on the Post Operation Rule dialog box, click Add Post Operation Check again and set the condition to read “or App Integrity is not acceptable”. Click Save Rule.

FIDO2/WebAuthn protocol
Back at the Policy Details page, scroll down to the FIDO2/WebAuthn Authenticators panel. Allow FIDO FIDO2/UAF Authenticators must be checked in order to create or modify a FIDO2 FIDO policy. Check the Request App Attest Credential and/or check the Request Google Play Integrity Extension checkbox.

To require App Integrity for the UAF protocol, add a Post Operation Rule to your policy.
a. Under Post Operation Rules click Add Rule. Fill in the *Rule Name field, with something like “Require App Integrity for FIDO2”.
b. On the Post Operation Rule dialog box, set the Action to Deny, click Add Post Operation Check and set the condition to read “If App Integrity is not known”.c. Still on the Post Operation Rule dialog box, click Add Post Operation Check again and set the condition to read “or App Integrity is not acceptable”. Click Save Rule.

Save your policy.
To activate your policy, on the Policies page, look for the row containing your policy. Click
(activate) in the Actions column.