Configure MFA for passwordless users
Learn which authenticators support multifactor authentication (MFA) in passwordless sign-in scenarios and see the available methods to configure two-factor authentication for these flows.
Available authenticators for passwordless users
Users can sign in with the authenticators that are configured in the authenticator enrollment policies and app sign-in policies.
The app sign-in policy provides different factor options, but for passwordless MFA, you can only use the Any 2 factor types option.
The Any 2 factor types option requires the user to authenticate with two authenticators from two of the following factor types:
- Knowledge-based: Something the user knows
- Possession: Something the user has
- Biometric: Something the user is
These factors can be hardware-protected, device-bound, or phishing-resistant.
Knowledge-based authenticators include passwords and security questions. Because security questions require an enrolled password to be used for MFA, knowledge-based authenticators alone can't satisfy MFA requirements for passwordless sign-in.
Hence, the user needs one possession-based and one biometric factor to sign in without a password.
Set up 2FA for passwordless sign-in
You can set up two-factor authentication for a passwordless sign-in experience in the following ways:
Okta Verify or Passkey (FIDO2 WebAuthn)
While there are several possession-based factors, options for biometric factors include only Okta Verify and Passkey (FIDO2 WebAuthn). However, when biometrics are enabled on Okta Verify or Passkey (FIDO2 WebAuthn), either of them alone satisfies both the Possession and Biometric factor type requirements for 2FA. And therefore, the user isn't prompted for any more factor types.
Thus, to configure two-factor authentication for passwordless sign-in, you need either Okta Verify with Push notification or Passkey (FIDO2 WebAuthn) with User verification set to Required. When user verification is required, the user must enable biometrics during the factor enrollment. This adds a Biometric component to the authenticator.
For example, if the user is using Okta Verify on an iPhone and user verification is required, a FaceID check is performed before the user is allowed to use Okta Verify to answer a challenge.
To set up Okta Verify, see Configure the Okta Verify authenticator.
To set up Passkey (FIDO2 WebAuthn), see Configure the Passkey (FIDO2 WebAuthn) authenticator.
Okta FastPass
Okta FastPass is a device-specific configuration for Okta Verify. It can also be used to enable passwordless sign-in with two-factor authentication. However, in this case, Okta Verify must be installed on the device the user is signing into.
For an ordinary Okta Verify Push challenge, the Okta Verify app doesn't need to be installed on the device the user is signing in to. For example, Okta Verify installed on a cell phone may be used to answer a challenge from the desktop.
However, this isn't possible when using Okta FastPass. To be able to sign in to the desktop using Okta FastPass, you must have Okta Verify installed on your desktop.
To set up Okta FastPass, see Configure Okta FastPass.