WebAuthn with FIDO Device Biometrics - "invalid_request (No MFA factors enabled for enrollment)" Error
Sep 10, 2025
Overview
The following error is received during login after disabling WebAuthn Device Biometric.
invalid_request (No MFA factors enabled for enrollment)
Applies To
- FIDO
Cause
The ‘Identifier First + Biometrics’ Authentication Profile was enabled with the New Universal Login experience. However, the Universal Login page has been customized, which means the tenant is using the Classic Login experience, which has automatically updated the Authentication profile to ‘Identifier + Password’ as the ‘Identifier First + Biometrics’ is only available with the New Universal Login experience.
Solution
- Navigate to the Dashboard > Authentication > Authentication Profile.
- Click on Identifier + Password option (even if it appears to be selected) > click on the Save on the top right corner.
- This will override the previously selected Identifier First + Biometrics Authentication Profile with Identifier + Password.
NOTE: When the 'WebAuthn with FIDO Device Biometrics' MFA option is disabled in the Dashboard > Security > Multi-factor Auth the user should be able to login successfully without having to provide biometrics.