Configure Passkeys for an Integration Beta
A passkey lets users complete MFA with their fingerprint, face, screen lock or a security key, in the browser or in the XFA mobile app. Enable it on an integration on its own or next to Silent MFA and TOTP.
Passkeys are in beta and stay off until XFA turns them on for your organization. If you do not see Enable passkeys under Multi-Factor Authentication, your organization does not have them yet: contact XFA and we will switch them on for you.
Before you start
- An integration with XFA. MFA is available on every integration type except OAuth2.
- Passkeys turned on for your organization, and a plan that includes advanced MFA. The Enable passkeys switch appears once both are in place.
Enable passkeys
- Go to the XFA Dashboard and navigate to Enforcement
- Click Manage on the integration you want to configure
- Under Multi-Factor Authentication, switch on Enable passkeys
Users are asked for a passkey on their next sign-in through this integration. If other methods are enabled too, see which method users get.
How it works
A passkey is a sign-in key that the user's device or password manager creates for XFA. The private key never leaves the user's device or password manager. XFA stores the public key, and never the private key or any fingerprint or face data. Every sign-in asks the user to unlock the passkey with a fingerprint, face, screen lock or security key PIN. A passkey only works on XFA's own sign-in pages, so a look-alike site cannot use it.
Users can keep their passkey in:
- iCloud Keychain on Apple devices
- Google Password Manager on Android and in Chrome
- Windows Hello
- A password manager that supports passkeys, such as 1Password or Bitwarden
- A security key, such as a YubiKey. See Security keys below
Passkeys in iCloud Keychain, Google Password Manager or a password manager sync to the user's other devices. Windows Hello passkeys and security keys stay on that one device or key.
Security keys
A security key is a small device the user plugs in or taps, such as a YubiKey. Users pick it during setup with Use a security key, under the button on the passkey screen. XFA does not store a passkey on the key itself, so it does not use up one of the key's passkey slots, and the key can hold as many XFA sign-ins as you need.
By default the user must unlock the key with its PIN, which proves who is using it. Keys that only support the older U2F standard cannot set a PIN, so they cannot be used this way.
Allow security keys without a PIN
Under Enable passkeys, you can switch on Allow security keys without a PIN. A touch on the key is then enough, and older U2F keys work too.
What this changes:
- A touch proves possession, not who is holding the key. That is the same assurance as an authenticator app code, and better in one way: a security key only answers XFA's real sign-in page, so it cannot be phished.
- Only security keys are affected. Passkeys on phones and laptops keep asking for a fingerprint, face or screen lock, whatever this setting says.
- Switching it back off locks people out. Users whose key has no PIN can no longer sign in, until you remove their MFA with Reset MFA authentication and they set up a new method. The dashboard asks you to confirm before switching it off.
The setting is per integration, and it only appears while passkeys are enabled.
User experience
First-time setup
- The user selects Passkey as their verification method (if multiple methods are available)
- The user receives an email and approves the new passkey from there. The sign-in page continues on its own once approved
- The browser or phone asks the user to create the passkey and confirm with their fingerprint, face, screen lock or security key
- The user is signed in. In the browser, the user confirms once more with the new passkey right away. In the XFA mobile app, creating the passkey is enough
If Auto-approve first device is enabled on the integration and the user has no MFA set up yet, the approval in step 2 is skipped.
On a computer without fingerprint or face unlock, the browser offers to use a phone or a security key instead.
Subsequent logins
The browser or phone asks the user to confirm with their passkey. After confirming, the user continues to the application.
Managing Users and Devices
- Reset MFA authentication removes all of a user's MFA, including their passkeys. Go to Devices, open the People tab and choose it from the actions menu next to the user. The user sets up a new passkey on their next sign-in.
- Reset 2FA on a device does not remove passkeys, because a passkey is not tied to one device.
After a reset, the old passkey stays in the user's password manager but no longer works with XFA. The user can delete it there.
Notes and troubleshooting
- Beta. Passkeys are in beta, so behavior and wording can still change.
- XFA mobile app. Passkeys work in the XFA mobile app from version 1.0.116, on iOS 16 or later and Android 9 or later. On older iOS and Android versions, the passkey option is hidden. If passkeys are the only enabled method, those users see "Passkeys aren't supported on this device. Update your device, or sign in on another one."
- Browsers. Current versions of Chrome, Edge, Firefox and Safari support passkeys. In a browser that does not, users see "This browser or device cannot use passkeys. Choose another verification method."
- Security keys. In the browser only: the XFA mobile app has no security key option yet. A key needs its PIN unless the integration allows keys without one. See Security keys.
- A passkey proves the user, not the device. A synced passkey works on any of the user's devices, so it does not show which device the user signed in from. XFA's device checks still run on the device used to sign in.
Related
- MFA methods
- Silent MFA
- TOTP
- Passkeys, the user guide