Troubleshooting: FIDO Enrollment Fails with "We Couldn't Verify Your Device"

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    After configuring a FIDO enrollment realm in the New Experience, enrolling a FIDO device can fail with the following error:

    A red error banner reading: We couldn't verify your device. Try again later or use a different browser, device, or operating system, with a Learn more link.

     

    Cause

    This happens when the Authenticator Type reported by the FIDO authenticator itself is not one of the Authenticator Type options selected in the FIDO enrollment realm's Advanced Settings. For example, the realm below has Cross platform and Platform (TPM) selected under Authenticator Type, which allows enrollment from authenticators such as YubiKeys and Windows Hello, but not Unspecified:

    The FIDO realm's Advanced Settings, with Authenticator Type options Cross platform and Platform (TPM) checked and Unspecified unchecked; a tooltip explains Unspecified registers an internal or external authenticator like a biometric reader or YubiKey, Cross platform registers an external roaming authenticator like a YubiKey or USB security key, and Platform (TPM) registers an internal authenticator like a biometric reader, Face ID, or Windows Hello.

    If the authenticator instead reports an Authenticator Type of Unspecified, and Unspecified is not selected in the realm configuration, enrollment fails with the error above. Identity Platform cannot influence which Authenticator Type a given authenticator reports back, and limiting the realm to only Cross platform and Platform (TPM) authenticators may be too restrictive for some deployments.

     

    Resolution

    Select the Unspecified Authenticator Type in addition to Cross platform and Platform (TPM) in the FIDO enrollment realm's Advanced Settings:

    The same Advanced Settings with Unspecified now also checked alongside Cross platform and Platform (TPM) under Authenticator Type.

    This allows enrollment to complete as expected in most cases, even when an authenticator reports an Unspecified Authenticator Type.

     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.