When you attempt to remove a FIDO credential via the REST API or the Self-Service Portal, you receive a successful 204 No Content response. However, when you refresh the page or query the credentials again, the FIDO credential still appears. This issue typically affects specific credentials where the documentDomain is set to localhost or where there is an internal database inconsistency between the user mapping and the device records.
Symantec Identity Security Platform (IDSP) 4.0.2
A product defect causes an inconsistency in the FIDO credential deletion logic. The system returns a success code even when the backend fails to complete the removal of the credential mapping from the database.
This issue is confirmed as a product defect.
Targeted to be fixed in release 4.0.4.