I have a question regarding Platform SSO and the use of Secure Enclave–backed keys with biometric policies.
If we configure userSecureEnclaveKeyBiometricPolicy with userSecureEnclaveKey, my understanding is that the Secure Enclave key is protected by biometric authentication (e.g., Face ID / Touch ID).
In this setup, during a login request that also refreshes the id_token and refresh_token, the assertion is signed using the userSecureEnclaveKey.
My question is:
Will this signing operation trigger a biometric prompt every time the assertion is generated (i.e., during login/token refresh) ?
Topic:
Developer Tools & Services
SubTopic:
Developer Forums
Tags:
Touch ID
SSO Extensions
Platform SSO
0
0
17