WebAuthn passkeys
Standards-based passwordless sign-in where the private key stays on the authenticator and only a signature crosses the network.
WebAuthn passkeys and two-factor sign-in, with self-service password reset for everything not yet migrated.
A password that is never created cannot be phished, reused or leaked. Zetect supports WebAuthn passkeys so the credential stays on the user’s device and is never transmitted, with self-service password reset covering the applications and users still on passwords during a phased migration.
The mechanics behind the capability — what the platform does, and where it does it.
Standards-based passwordless sign-in where the private key stays on the authenticator and only a signature crosses the network.
FIDO2 can also serve as a strong second factor while you migrate populations gradually rather than all at once.
Users recover their own access for accounts still on passwords, without raising a ticket.
Composition and lifetime rules still govern the accounts that have not moved yet, so the transition is managed rather than uneven.
Who feels the difference once Passwordless & FIDO2 is in place, and how.
Security
With no shared secret to type, the most common route into an organisation simply closes.
Service desk
Password resets are one of the largest categories of service-desk work, and passwordless removes the cause rather than the symptom.
IT operations
Passwords and passkeys coexist, so populations move when they are ready instead of in one disruptive cutover.
End users
Sign-in becomes a touch or a glance, which is faster than any password a policy would accept.
It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.