ActiveManage Docs ← Back to activemanage.co.uk

Passkeys Overview

Passkeys give ActiveManage accounts phishing-resistant sign-in. Instead of typing a password, a user proves possession of a key held by their device or password manager, unlocked with a fingerprint, a face scan or a device PIN.

Why they beat passwords

  • Nothing worth stealing is stored. Only a public key reaches the server, so a stolen database yields nothing anybody can sign in with.
  • They cannot be phished. A passkey is tied to your site's address by the browser itself. A convincing replica on another domain cannot use it, however carefully the user is deceived.
  • Nothing to reuse or write down. There is no password to share with another site.

Passwords still work

Password sign-in, with two-factor authentication where you have configured it, always remains available. Passkeys sit alongside it rather than replacing it, so a user who loses their only device still has a way in.

Which accounts

Passkeys apply to ActiveManage's own accounts. Users signing in through Active Directory, an external identity provider or a social login authenticate at that provider instead, and any passkey support for them is that provider's concern.

Worked Examples

  • Finance team: passkeys required for anyone who can approve a payment, removing the phishing risk entirely.
  • Customer portal: passkeys offered as a faster alternative, with a one-time prompt after sign-in.
  • Field staff: passkeys on company phones, so a shared device PIN is not the weakest link.
  • Administrators: passkeys plus step-up re-authentication for sensitive settings changes.