ActiveManage Docs ← Back to activemanage.co.uk

Enabling Passkeys

Three settings control the feature, in the Passkeys option group.

The settings

  • Enable Passkeys — the master switch. With it off, no passkey can be created or used.
  • Prompt users to set up a passkey — after a password sign-in, whether to invite users who have none. Choose No, Yes — each time, or Yes — just once.
  • Relying-Party ID — the web address passkeys are tied to. Leave this blank unless you have a specific reason not to.

Why the Relying-Party ID should stay blank

Left blank, ActiveManage works it out from the address users visit, which is correct for a normal installation. It only needs setting where one installation is reached on several domains.

If you change it after passkeys have been registered, every existing passkey stops working. Users fall back to passwords and must register again. Decide this before you roll the feature out, not afterwards.

Choosing a prompt setting

  • No — available on the account page but never advertised. Right for a pilot with a small group.
  • Yes — just once — a single invitation per user, remembered so nobody is asked repeatedly. The sensible choice for a general rollout.
  • Yes — each time — prompt on every password sign-in until they create one. Effective, and irritating; reserve it for a deliberate migration push.

Users who already have a passkey are never prompted, whichever setting you choose.

Requirement

Passkeys need a secure (HTTPS) connection and will not work on a site served over plain HTTP.

Worked Examples

  • Phase 1: enable with prompting off, and tell the IT team to try it.
  • Phase 2: switch to "just once" so every user is invited exactly one time.
  • Phase 3: "each time" for a fortnight before a deadline, then back to "just once".