Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Authenticator configuration options

Use the Authenticator Configuration page to manage authenticator options on your instance.

Navigate to Multi-factor Authentication > Web Authentication > Authenticator Configuration to view and edit the default configuration options.

FieldDescription
Allowed authenticator typeType of authenticators allowed to be registered. Select from: - Platform authenticators are attached or integrated into a device. Fingerprint readers or facial recognition available on mobile devices(such as Apple FaceID or TouchID) fall under this category. - Roaming authenticators can be removed from a computer or other client device and used elsewhere. Hardware keys fall under this category.
Attestation TypeSetting the value to direct or indirect will require importing authenticator metadata to attest to the provenance of an authenticator during registration.- None - Direct - Indirect
Platform self-attestationWhether self-attestation is enabled for platform authenticators.
Cross platform self-attestationWhether self-attestation is enabled for roaming authenticators.
User verificationSelect from Preferred or Required. If required, web authentication flow prompts users for verification using PIN or Biometrics.
Verify user presenceWhether web authentication flow requires the user presence verification.
Resident keySelect from Preferred or Required. If required, the authenticator persists the public key credentials within the authenticator storage.
Timeout \(In ms\)Maximum time limit for completing web authentication registration and authentication. Time is in milliseconds.