Passkeys give ActiveManage accounts phishing-resistant sign-in. Instead of typing a password, a user proves possession of a key held by their device or password manager, unlocked with a fingerprint, a face scan or a device PIN.
Why they beat passwords
- Nothing worth stealing is stored. Only a public key reaches the server, so a stolen database yields nothing anybody can sign in with.
- They cannot be phished. A passkey is tied to your site's address by the browser itself. A convincing replica on another domain cannot use it, however carefully the user is deceived.
- Nothing to reuse or write down. There is no password to share with another site.
Passwords still work
Password sign-in, with two-factor authentication where you have configured it, always remains available. Passkeys sit alongside it rather than replacing it, so a user who loses their only device still has a way in.
Which accounts
Passkeys apply to ActiveManage's own accounts. Users signing in through Active Directory, an external identity provider or a social login authenticate at that provider instead, and any passkey support for them is that provider's concern.
Worked Examples
- Finance team: passkeys required for anyone who can approve a payment, removing the phishing risk entirely.
- Customer portal: passkeys offered as a faster alternative, with a one-time prompt after sign-in.
- Field staff: passkeys on company phones, so a shared device PIN is not the weakest link.
- Administrators: passkeys plus step-up re-authentication for sensitive settings changes.