Loading

Enabling Passkeys

Two settings govern passkeys. Both are worth understanding before switching either.

Where to find it

Architect Panel → Configuration:

  • Site Settings — Enable Passkeys, and the prompt setting

Architect Panel → Security:

  • Passkeys — registered credentials, their devices and last use

Enable Passkeys

Ships off. Turning it on makes passkeys available — users can register one and use it. It compels nobody and changes nothing for people who ignore it.

That is the right first step: enable, let people enrol, and see where you get to before considering anything stronger.

Prompt to Set Up a Passkey after Logon

Ships on. After signing in, a user without a passkey is invited to create one.

This is what actually drives adoption. Passkeys enabled with no prompt produces a feature almost nobody discovers — people do not go looking through their profile settings for authentication options they have not heard of.

The prompt is tracked per user

Worth knowing, because it is what makes the prompt tolerable. The platform records whether somebody has been prompted and when, so they are not asked on every single sign-in.

Somebody who declines is not nagged into resentment, and somebody who has never seen it still gets asked. That balance is the difference between a prompt that drives adoption and one that trains people to dismiss dialogs.

Prepare before you enable the prompt

The prompt will be the first most users hear of passkeys, so what they see matters. Send a short note first explaining what it is and why — a prompt arriving with no context is dismissed by people who assume it is optional noise.

One sentence works: your password may already be in a breach somewhere, and this means that does not matter.

Administrators first

Enable, ask administrators to register, and confirm the flow works on the devices and browsers your organisation actually uses. They are a small population, able to tell you what is awkward, and the accounts most worth protecting.

Decide recovery before you start

Somebody will lose their only credential. Work out now who can reset it, how they verify the caller, and what is recorded — before anybody is locked out.

Make that check at least as rigorous as the passkey it bypasses. An attacker who cannot phish a passkey will telephone your service desk instead, and a weak reset process quietly undoes the whole control.

Do not remove passwords yet

Enabling passkeys does not mean removing the alternative. Keep it until enrolment is genuinely complete and recovery has been tested with a real person.

Worked example

An organisation enables passkeys with the prompt on, having first sent a two-sentence explanation to all staff. Administrators register within a week. After a month, 60% of staff have registered at least one credential, entirely through the prompt — nobody had to be chased.

Recommendations

  • Leave the prompt on — it is what drives adoption.
  • Explain it briefly first, so the prompt is not a surprise.
  • Design and test recovery before enabling.
  • Keep passwords until enrolment is complete.