A SaaS company wants to implement FIDO2 but their users span dozens of organizations with different IT policies. Which FIDO architecture component best addresses federated identity across these organizations?
-
A
Deploying separate Relying Party servers for each organization
-
B
Using a FIDO metadata service to normalize authenticator trust across organizations
-
C
Implementing a shared IdP that federates FIDO assertions to each tenant RP
-
D
Requiring all organizations to use the same hardware security key model