Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Specifying allowed authenticators for mobile app users

Prev Next

Mobile app users can choose how they authenticate into your apps. Depending on their OS or device, they can login using a:

  • Security Key

  • Biometric (face or fingerprint)

  • Passcode

  • PIN

  • Yes/No

  • Watch

  • Device

If you wish users to login in a specific way, you can limit these options by changing which authenticators will be available to them in your FIDO policy.

Update the default FIDO policy

  1. Login to the Digipass S3 Authentication Cloud portal.

  2. Access the FIDO Policies page by clicking Configure server on the Authentication Cloud tile and:      

    • Clicking Review/Add FIDO Policies in the FIDO Policies section, or

    • Clicking FIDO Policies on the Authentication menu.

  3. On the Search bar, enter default.      

    • You will see that there is only one default (Default FIDO Policy), which is provisioned along with your tenant.

    • The default policy is active, so it cannot be modified, i.e., if you hover over the edit button, you won't be allowed to click it. However, you should be able to make a copy and modify it.

  4. Click the duplicate icon.
    FIDO Policies table displaying policy names, statuses, and modification dates for management.

  5. You should see a message saying, Operation completed successfully — click OK.
    Operation completed successfully, draft policy named 'default' created with confirmation button.

  6. You should see the Policy Details of the policy you just copied.

  7. FIDO Policy Name: leave this as default so that any changes you make here will overwrite the original default policy.

  8. Under Allowed Authenticator Groups, you will see:      

    • Android/iOS Strong Biometric - Hardware

    • Android/iOS Strong Lock Screen - Hardware

    • Android/iOS PIN - Hardware

    • Android/iOS Presence - Hardware

    • Android/iOS Silent - Hardware

  9. In this case, we will prevent mobile users from authenticating using a PIN, so click the trashbin next to Android/iOS PIN - Hardware.
    FIDO policy details including authenticator groups and options for app attest credentials.

  10. Scroll to the bottom of the page and click Save.

  11. The FIDO Policies page should now show two policies named default. The one you created should have a Status of DRAFT and have the current date under Modified (UTC +00:00).

  12. Activate your policy by clicking the checkmark under Actions.
    FIDO Policies table displaying active and draft policy statuses with action options.

  13. You should see a dialog asking you to confirm activation. Click Activate.
    Confirmation prompt to activate the default policy, warning about overwriting existing policy.

  14. This will overwrite the original default policy and update your policy's Status to ACTIVE. Note that changes may take up to 120 seconds to take effect.
    FIDO Policies table displaying active status and modification date for default policy.

For more information about specifying allowed authenticators, see Creating a policy to use platform authenticators.

Verify which authenticators are allowed

Once you have:

  • configured the Android or iOS Tutorial App to use the Authentication Cloud, and

  • updated the default FIDO policy to specify which authenticators are allowed

you can use either app to verify which authenticators are available for use.

For instance, if you now attempt to register a new authenticator with an Android phone, PIN authentication will no longer be displayed in the list of available authentication methods

Select an authentication method including PIN, Yes/No, Screen Lock, and Silent ASM.

With original default FIDO policy

Select an authentication method from the options displayed on the mobile app interface.

With updated default FIDO policy