Configuring FIDO2 Challenge with Mac Touch ID in the Oracle Advanced Authentication Self-Service Portal
Introduction
OAA supports FIDO2 using:
- Mac Touch ID.
- Windows Hello using a PIN, or with biometrics such as facial recognition and fingerprint.
- Yubikey.
This tutorial shows you how to use the Self-Service Portal to configure the FIDO2 challenge factor using Mac Touch ID in Oracle Advanced Authentication (OAA) for the purposes of multi-factor authentication.
To learn how to configure FIDO2 with Windows Hello, see Configuring FIDO2 Challenge with Windows Hello in the Oracle Advanced Authentication Self-Service Portal.
To learn how to configure FIDO2 with Yubikey, see Configuring FIDO2 Challenge with Yubikey in the Oracle Advanced Authentication Self-Service Portal.
Objectives
In this tutorial you will perform the following tasks:
- Configure the FIDO2 challenge factor using Mac Touch ID in the Self-Service Portal.
Prerequisites
Before starting this tutorial ensure you have met these requirements:
- An Oracle Advanced Authentication deployment is available.
- You have access to the Self-Service Portal and can login with your user credentials.
- Your Mac computer must have:
- An Apple ID.
- ICloud Keychain enabled. See Set up iCloud Keychain.
- Touch ID configured on your Mac computer. See Use Touch ID on Mac. You must ensure you can log into your Mac using Touch ID before attempting FIDO2 with OAA.
Configure FIDO2 using Mac Touch ID in the Self-Service Portal
-
Access the Self-Service Portal. For example,
https://oaa.example.com/oaa/rui
. -
Enter your user credentials. For example,
testuser/<password>
. -
In the left navigation menu, select My Authenticators.
-
Select Add Authentication Factor and from the drop down menu select FIDO2 Challenge:
-
In the Add FIDO2 Device screen enter a Friendly Name, for example,
FIDO2-MAC
. Click Register:
Description of the illustration add_friendly.jpg
-
A Sign In page will appear asking you to sign in with Touch ID. Touch the fingerprint scanner with your finger:
-
If the authentication with the FIDO2 device is successful, the Self-Service Portal will show the factor has been added:
Learn More
- Configuring FIDO2 Challenge with Windows Hello in the Oracle Advanced Authentication Self-Service Portal.
- Configuring FIDO2 Challenge with Yubikey in the Oracle Advanced Authentication Self-Service Portal.
- To learn how to use factors when accessing an OAM protected application with MFA, see Integrate Oracle Access Management with Oracle Advanced Authentication.
Feedback
To provide feedback on this tutorial, please contact idm_user_assistance_ww_grp@oracle.com
Acknowledgements
- Author - Russ Hodgson
More Learning Resources
Explore other labs on docs.oracle.com/learn or access more free learning content on the Oracle Learning YouTube channel. Additionally, visit education.oracle.com/learning-explorer to become an Oracle Learning Explorer.
For product documentation, visit Oracle Help Center.
Configuring FIDO2 Challenge with Mac Touch ID in the Oracle Advanced Authentication Self-Service Portal
G11146-01
July 2024