Configure and Manage Passkey-Based MFA for Your Environment
As an administrator, you can enable multi-factor authentication (MFA) using passkeys for users in your environment. Once enabled, users who sign in with a username and password will be required to verify their identity with a passkey — such as a fingerprint, face scan, or hardware security key — after entering their password.
You can also view and remove passkeys from individual user profiles, and control which device types are permitted to store passkeys.
Before you start
This feature applies to standalone users — those who sign in with a username and password. It does not affect users who authenticate through an organization-managed SSO connection.
Enable passkey-based MFA
- Open Settings and navigate to the Security or Authentication section.
- Enable Multi-factor authentication for your environment.
- Optionally, configure which device types are permitted to store passkeys.
- Save your changes. Users will now be prompted to register and use a passkey when they sign in.
View and remove passkeys from a user profile
- Open the user’s profile in the admin panel.
- Navigate to the Passkeys section to see all passkeys registered to that user.
- Click Delete next to any passkey you want to remove.
Limitations
Administrators can restrict which device types are allowed to store passkeys — for example, limiting registration to hardware security keys only. Consult your organization’s security policy when configuring this setting.
Single sign-on (SSO) is an authentication scheme that allows logging in securely to multiple related applications with only one set of credentials. This method implies authenticating users for applications as well as synchronizing user attributes.