Skip to main content

21 de agosto de 2026

Configuring FIDO2 Redirection

When you enable WebAuthn redirection, the entire FIDO2 device does not need to be forwarded. For example, a YubiKey can continue to be used on the local endpoint while also being available in the remote session. For use cases that require full device access, consider using USB redirection instead.

The WebAuthn redirection code is installed automatically on supported client and agent machines.

To use FIDO2 devices in a nested mode setup, use USB redirection in the first hop and WebAuthn or USB redirection in the second hop. This mixed USB/FIDO2 redirection in nested mode does not support RDS hosts as the first hop.

You can collect logs on the client and agent using DCT. See Using DCT to Collect Logs for Remote Desktop Features and Components in the Horizon Administration guide.

ClientRemote DesktopRDS Host
Windows, macOS, LinuxWebAuthn authenticators are supported using WebAuthn redirection. Full FIDO2 authenticators are supported using USB redirection.USB FIDO2 authenticators are supported using FIDO2 redirection
iOSNo USB or WebAuthn redirection supportNo USB or WebAuthn redirection support
Android, WebUSB FIDO2 authenticators are supported using USB redirectionUSB FIDO2 authenticators are supported using USB redirection (Chrome browser only, run as Administrator)

System Requirements for FIDO2 Redirection

SystemRequirements
DeviceFIDO2 enabled security keys
Client machine operating system
  • Windows 10 20H2 and later
  • Windows 11
  • Windows 2022
  • macOS
  • Ubuntu
  • Red Hat Enterprise Linux
  • ARM Linux
Agent machine operating system
  • Windows 10 20H2 and later
  • Windows 11
  • Windows 2022

Using Group Policy Settings to Configure FIDO2 Redirection

You can configure WebAuthn redirection by editing the group policy settings. See View Agent Configuration ADMX Template Settings.

Esta página foi útil?

Enviar feedback sobre este tópico

Este tópico foi útil?

Não inclua informações pessoais ou confidenciais.

Gerando o link…