Passkey Policy
Updated 16 May 2026
Admin only. The Passkey Policy tab is restricted to administrators. Senior managers and below do not have access to this tab.
What is a passkey?
A passkey is a phishing-resistant login method that uses your device's built-in biometric system (Touch ID, Face ID, Windows Hello) or a hardware security key (such as a YubiKey) instead of a password. When a user logs in with a passkey, TacDesk verifies a cryptographic signature generated by their device — no password is transmitted or stored. Passkeys cannot be phished, guessed, or stolen through data breaches in the way that passwords can.
Configuring passkey requirements by role
Set whether passkeys are Optional, Encouraged, or Required for each role:
- Admins and senior managers — recommended baseline: require passkeys. High-privilege accounts should use the strongest available authentication.
- Managers and supervisors — recommended: require passkeys. These accounts have significant access to sensitive data.
- Guards — recommended: optional but encouraged. Many guards use shared or older devices that may not support passkeys; enforcing here risks locking out operational staff.
Fallback options
Configure what happens when a passkey is not available — for example, a user on a new or incompatible device:
- Allow password fallback — the user can log in with their password if no passkey is enrolled
- Require password + email code — the user must verify via email one-time code in addition to their password, providing a second factor without passkey hardware
Ensure at least one fallback is configured for each role where passkeys are required, otherwise users without compatible devices will be locked out.
Session timeout
Set how long an authenticated session remains valid before the user must log in again, configurable per role. Shorter timeouts improve security but increase friction. Typical settings:
- Admins: 8 hours
- Managers / senior managers: 12 hours
- Guards: 24 hours (guards often work long shifts or overnight)
Passkey enrolment
After you enable passkeys for a role, users in that role are prompted to enrol a passkey on their next login. The enrolment process is guided — they follow their device's standard biometric or security key setup. Users can enrol multiple passkeys (e.g. one on their phone, one on their laptop) for resilience. Each enrolled passkey is listed under the Settings tab of their hub (the cog icon in the bottom navigation), where they can add a new device or remove an old one at any time.
Audit log
Every passkey enrolment, removal, and login is recorded in the audit log. Use this to verify compliance and investigate any unexpected authentication activity.
Why this matters
- Cyber insurance — many insurers now require MFA or phishing-resistant authentication for privileged accounts as a policy condition
- ISO 27001 — passkeys satisfy strong authentication controls under access management requirements
- Reduced support burden — passkeys eliminate forgotten-password resets for enrolled users