Skip to main content

April 9, 2026

Configuring FIDO2 Redirection

FIDO2 redirection allows applications running on the agent to access FIDO2 authenticators attached to client endpoints.

FIDO 2 stands for Fast Identity Online 2. This feature is installed automatically on supported client and agent machines. It is not an optional feature.

To use FIDO2 devices in a nested mode setup, use USB redirection in the first hop and FIDO2 redirection in the second hop. This mixed USB/FIDO2 redirection in nested mode does not support RDS hosts as the first hop.

You can collect logs on the client and agent using DCT. See Using DCT to Collect Logs for Remote Desktop Features and Components in the Horizon Administration guide.

ClientRemote DesktopRDS Host
WindowsFIDO2 authenticators are supported using FIDO2 redirectionFIDO2 authenticators are supported using FIDO2 redirection
Linux, Mac, AndroidUSB FIDO2 authenticators are supported using USB redirectionUSB FIDO2 authenticators are supported using USB redirection
WebUSB FIDO2 authenticators are supported using USB redirectionUSB FIDO2 authenticators are supported using USB redirection Chrome browser only (Run as Administrator)

System Requirements for FIDO2 Redirection

SystemRequirements
DeviceFIDO2 enabled security keys
Client machine operating system
  • Windows 10 20H2 and later
  • Windows 11
  • Windows 2022
Agent machine operating system
  • Windows 10 20H2 and later
  • Windows 11
  • Windows 2022

Using Group Policy Settings to Configure FIDO2 Redirection

You can configure FIDO2 redirection by editing the group policy settings. See View Agent Configuration ADMX Template Settings.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…