Mobile app users can choose how they authenticate into your apps. Depending on their OS or device, they can login using a:
Security Key
Biometric (face or fingerprint)
Passcode
PIN
Yes/No
Watch
Device
If you wish users to login in a specific way, you can limit these options by changing which authenticators will be available to them in your FIDO policy.
Update the default FIDO policy
Login to the Digipass S3 Authentication Cloud portal.
Access the FIDO Policies page by clicking Configure server on the Authentication Cloud tile and:
Clicking Review/Add FIDO Policies in the FIDO Policies section, or
Clicking FIDO Policies on the Authentication menu.
On the Search bar, enter default.
You will see that there is only one default (Default FIDO Policy), which is provisioned along with your tenant.
The default policy is active, so it cannot be modified, i.e., if you hover over the edit button, you won't be allowed to click it. However, you should be able to make a copy and modify it.
Click the duplicate icon.

You should see a message saying, Operation completed successfully — click OK.

You should see the Policy Details of the policy you just copied.
FIDO Policy Name: leave this as default so that any changes you make here will overwrite the original default policy.
Under Allowed Authenticator Groups, you will see:
Android/iOS Strong Biometric - Hardware
Android/iOS Strong Lock Screen - Hardware
Android/iOS PIN - Hardware
Android/iOS Presence - Hardware
Android/iOS Silent - Hardware
In this case, we will prevent mobile users from authenticating using a PIN, so click the trashbin next to Android/iOS PIN - Hardware.

Scroll to the bottom of the page and click Save.
The FIDO Policies page should now show two policies named default. The one you created should have a Status of DRAFT and have the current date under Modified (UTC +00:00).
Activate your policy by clicking the checkmark under Actions.

You should see a dialog asking you to confirm activation. Click Activate.

This will overwrite the original default policy and update your policy's Status to ACTIVE. Note that changes may take up to 120 seconds to take effect.

For more information about specifying allowed authenticators, see Creating a policy to use platform authenticators.
Verify which authenticators are allowed
Once you have:
configured the Android or iOS Tutorial App to use the Authentication Cloud, and
updated the default FIDO policy to specify which authenticators are allowed
you can use either app to verify which authenticators are available for use.
For instance, if you now attempt to register a new authenticator with an Android phone, PIN authentication will no longer be displayed in the list of available authentication methods
![]() With original default FIDO policy | ![]() With updated default FIDO policy |

