Independent MFA supports FIDO2 for infrastructure applications
Infrastructure applications now support independent multi-factor authentication using FIDO2 keys for SSH access. Users can enroll FIDO2 keys through the App Launcher and configure them at both application and policy levels.
Infrastructure applications support independent multi-factor authentication (MFA) with FIDO2 keys. You can allow ssh_fido2_key, piv_key, or both in application-level and policy-level MFA settings.
Users enroll FIDO2 keys through the App Launcher and connect with the generated SSH identity. FIDO2 keys for SSH are separate from browser-based WebAuthn security keys and Personal Identity Verification (PIV) keys.
For setup instructions, refer to Enroll a FIDO2 key for infrastructure apps and Configure MFA for infrastructure applications.
Source: original entry ↗