Zetect

Sign in without a password at all

WebAuthn passkeys and two-factor sign-in, with self-service password reset for everything not yet migrated.

A password that is never created cannot be phished, reused or leaked. Zetect supports WebAuthn passkeys so the credential stays on the user’s device and is never transmitted, with self-service password reset covering the applications and users still on passwords during a phased migration.

How Passwordless & FIDO2 works

The mechanics behind the capability — what the platform does, and where it does it.

Passkey registeredbound to the deviceChallenge issuedby ZetectDevice signskey never leavesSigned inno shared secretWHY THE CREDENTIAL CANNOT LEAKThe private key never leaves the authenticator, so there is nothing to interceptNothing is typed, so nothing can be captured by a fake sign-in pageSelf-service reset covers the accounts still using passwords during migration

WebAuthn passkeys

Standards-based passwordless sign-in where the private key stays on the authenticator and only a signature crosses the network.

Two-factor sign-in

FIDO2 can also serve as a strong second factor while you migrate populations gradually rather than all at once.

Self-service password reset

Users recover their own access for accounts still on passwords, without raising a ticket.

Password policy control

Composition and lifetime rules still govern the accounts that have not moved yet, so the transition is managed rather than uneven.

What it changes

Who feels the difference once Passwordless & FIDO2 is in place, and how.

Security

Nothing to phish

With no shared secret to type, the most common route into an organisation simply closes.

Service desk

Reset tickets fall away

Password resets are one of the largest categories of service-desk work, and passwordless removes the cause rather than the symptom.

IT operations

Migrate at your own pace

Passwords and passkeys coexist, so populations move when they are ready instead of in one disruptive cutover.

End users

Better daily experience

Sign-in becomes a touch or a glance, which is faster than any password a policy would accept.

See Passwordless & FIDO2 in context

It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.