@davidberlind<\/a> Your points are well taken. The complexities are what will trip up most average users. In my work experience, I had some users blindly clicking on the option to create a passkey when logging in using username/password, simply because they thought they had to, not because they understood what it meant. I absolutely agree with, “…we have to advance-plan a strategy”; this is imperative if users are to successfully manage and control their credentials.<\/p>\nIn my experience, end users don’t understand the difference between user/password logon vs. passkey logon. Most could care less as long as they get successfully logged in. One would hope that those who have been around since the early days when usernames and passwords were first introduced, having been carried along by ever more complex password requirements and MFA requirements, would be more astute to the value in moving to passkeys. However, those that I have talked with just don’t understand it. Most blindly go along with it because it seems<\/em> like the right thing to do, not because it is better than what they have been using for decades.<\/p>\nI spend a lot of my time educating people on why using a password manager, creating complex passwords, and using passkeys is good idea, but as the saying goes, “You can bring a horse to water but you can’t make it drink”. I know so many people who will not use more secure options simply because they don’t understand the technology, and thus are under the misconception that something they don’t understand is inherently less secure.<\/p>","upvoteCount":1,"datePublished":"2025-05-09T02:18:11.181Z","url":"https://community.spiceworks.com/t/questions-about-passkey-edge-cases/1201130/18","author":{"@type":"Person","name":"rtrauth2","url":"https://community.spiceworks.com/u/rtrauth2"}},{"@type":"Answer","text":"
Yes. but you can also configure it for a short time, which any enterprise customer will do if they don’t trust the initial SSO on computer startup as secure enough.<\/p>\n
Lots of security settings are not required but it doesnt mean they can’t (and should be) be implemented as standard.<\/p>\n
All you are doing here is picking holes for the sake of it when every single one of your points has a solution (and are only really valid if IT ignore best practice), and others like your assumption about support costs have no factual basis whatsoever.<\/p>","upvoteCount":0,"datePublished":"2025-05-15T11:40:34.899Z","url":"https://community.spiceworks.com/t/questions-about-passkey-edge-cases/1201130/19","author":{"@type":"Person","name":"Duncan792","url":"https://community.spiceworks.com/u/Duncan792"}}]}}