Roll out passkeys in your organization

Requires passkeys to be enabled for your organization.

A passkey lets an employee sign in with the unlock method their phone already uses: face, fingerprint, or device PIN. There is nothing to remember and nothing to type, and there is no shared secret that can be phished or leaked. For a frontline workforce this removes the single biggest source of sign-in friction and helpdesk load.

This page is for the person deciding whether and how to switch a workforce over. Employees have their own article, Passkeys in Flip: sign in securely without a password, which covers setup, sign-in, and device-level problems in detail.

What you decide

Three settings shape what your people experience. Flip enables them for your organization; they are not self-service, so raise them with your Customer Success Manager.

Decision Effect
Passkeys on or off Whether employees are offered a passkey at all. With it off, nothing changes for anyone.
Setup mandatory or skippable Skippable: the employee can defer with Remind me later and is asked again later. Mandatory: the prompt cannot be skipped and sign-in does not continue until a passkey exists.
How new employees activate If new employees activate with an invite code, a passkey becomes their only sign-in method. See below.

Mandatory setup requires passkeys to be on. The two cannot be configured independently.

What employees experience

There are two different journeys, and the difference matters for how you communicate the change.

A new employee activating with an invite code. They scan or enter their code, accept the terms of use, and are taken to passkey setup. They are not asked to choose a password, and they are not asked to set up a one-time-code app. The passkey is their sign-in method from then on.

The terms-of-use screen is not part of passkey setup. It appears at every employee's first sign-in regardless of passkeys, so do not read it as an extra step you introduced.

An employee who already signs in with a password or single sign-on. Their existing method keeps working. They are prompted to add a passkey alongside it, either at sign-in or from a prompt inside the app, and they can then choose either method each time they sign in.

The practical consequence: for existing staff a passkey is an addition, and for new starters activating by code it is the whole thing. Say that clearly in your rollout communication, because "you can always fall back on your password" is only true for one of the two groups.

See and remove an employee's passkey

  1. Go to Users in the Admin Console and open the person's profile.
  2. Open the Authentication tab. Authentication methods lists password, SSO, and passkey with the state of each, so you can see at a glance whether this person has a passkey.
  3. Expand Passkey to see where it is stored, for example iCloud Keychain, and when it was created.
  4. To remove it, select Remove passkey, then confirm with Delete. The confirmation also offers Keep passkey if you opened it by mistake.

Removing a passkey only removes it from Flip. It stays on the employee's device, where it will still be offered at sign-in and will then fail. Tell the employee to delete it from their password manager too, otherwise you have created the problem you were trying to fix. The confirmation dialog says this as well; read it before you confirm.

Check what else they can sign in with first. For an employee who activated with an invite code and never set a password, the passkey is their only method, so removing it locks them out completely. Generate a new invite code for them at the same time.

Remove a passkey when the device is lost, or when a passkey has stopped working and the employee needs a clean start.

Check this before you enable it

  • Device unlock. A passkey requires an active screen lock on the phone. Employees with no PIN, pattern, or biometric set up cannot create one. Expect a share of your frontline to be in exactly this state.
  • Managed devices. If you deploy MDM, confirm your profiles do not block the platform passkey provider. A policy that disables the device keychain or password manager prevents passkey creation, and the failure looks like a Flip problem to the employee.
  • Operating system age. Passkeys need a reasonably current operating system, so older devices are excluded. The requirements are Flip's general ones, listed in Which devices and operating systems are supported. Check your device inventory against that list rather than assuming.
  • Who has no smartphone. Passkeys live on a device. Decide what those employees use before you make setup mandatory, not after.

Prepare your helpdesk

Three questions will arrive, and all three are answerable in one sentence each.

  • "It says I need a screen lock." That is the operating system, not Flip. The employee sets one up in device settings.
  • "My passkey does not work on my new phone." Passkeys move with the phone's account, Apple ID or Google account. If they did not, sign in with the old method and create a new passkey.
  • "I was never asked to set one up." Either passkeys are not enabled for your organization, or the employee deferred the prompt.
  • "My passkey is not recognised any more." It was removed in Flip but is still on the device. The employee deletes it from their password manager, signs in with their other method, and creates a new one. If they have no other method, they need a new invite code.

Point your first-level support at the employee article. Its troubleshooting section covers the device-side causes in more depth than a helpdesk script needs.

Roll out in stages

Turn passkeys on as skippable first, and leave them skippable long enough to see the adoption curve and the support tickets it produces. You will learn how many devices lack a screen lock and whether an MDM profile is in the way, and you will learn it from volunteers rather than from a shift that cannot clock in.

Make setup mandatory only once that number looks healthy, and only once you have an answer for the people it will block.

Related

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request