FIDO2/WebAuthn is the latest authentication standard co-authored by Google, Microsoft, and others in collaboration with the World Wide Web Consortium (W3C). FIDO2 relies on an asymmetric (public/private) pair of cryptographic keys to authenticate users. The public key is stored internally within Secure & Govern, while the private key is kept by the user and is protected on a physical security key.
Egnyte Secure & Govern has recently added support for FIDO2/WebAuthn standards. It enables a user to make their account more secure by adding a second-factor authentication using FIDO2/WebAuthn compatible security keys for a user's login process.
FIDO2/WebAuthn only applies to accessing Egnyte Secure & Govern. For details on how to set up two factor authentication for Collaborate, please see Two Step Login Verification Overview.
How do I set up my Egnyte Secure & Govern account to use FIDO2/WebAuthn?
- Navigate to Settings and click on Account on the left navigation.
- Turn on Hardware Security Key to add a label to the key and then click Done.
- The Security Key setup window appears, select OK
- Click OK again to continue with key setup
- Verify the user's identity by inserting the FIDO2 key in the USB port or the user can use a built-in sensor. Click on USB Security Key if the user wishes to use a physical FIDO2/WebAuthn key or click on Built-in-sensor to use the device's built-in reader.
- If the user clicked on the Built-in sensor in the previous step then they will be prompted to place their finger on the Built-in fingerprint sensor.
- After inserting the security key inside one of the computer's USB port or after using the Built-in sensor, click on Allow.
- The hardware security key is now setup and Two-factor authentication will be required each time the user logs into Egnyte Secure & Govern.
For additional information regarding FIDO2/WebAuthn please review FIDO2/WebAuthn FAQ