Appearance
Passkeys
WebPasskeys use a WebAuthn-compatible authenticator such as Touch ID, Windows Hello, Face ID, a device PIN, or a security key. When your organization permits local passkey sign-in, a passkey signs you in to ZynoSuite without typing your password.
Sign in with a passkey
The web sign-in page includes Sign in with a passkey. Select it to use a discoverable passkey without entering your email first. If you enter your email, ZynoSuite can also select a configured passkey as the next sign-in method.
Your organization controls whether an account can set up a local passkey. An organization that requires Microsoft Entra or Google Workspace SSO does not offer local browser passkey setup or sign-in; complete the provider's sign-in prompt instead.
Set up or manage a passkey
- Open your user menu and select Personal Security.
- Open the Passkey tab.
- Select Set up passkey or Add passkey.
- Name the device, complete the browser/device prompt, and store the passkey in an authenticator you control.
The Personal Security page lists the passkeys on your account and lets you remove one. An existing passkey remains manageable when the organization allows current passkey sign-in but does not permit new enrollment.
ZynoSuite requires a PRF-capable authenticator for a sign-in passkey. The same passkey unlocks the encryption keys that protect your data in the browser, so use an authenticator that can keep those keys available to you.
Sign-in Method Change
Setting a sign-in passkey turns off browser password and authenticator-code sign-in for that account. A shared ZynoWorkstation retains its password workflow. Do not remove your only passkey unless you have a supported way to sign in again.
ZynoRMM hardware authenticators
ZynoRMM can also register a hardware authenticator for secure technician workflows. ZynoRMM setup can show Register Device for Touch ID, Face ID, Windows Hello, YubiKey, or another FIDO2 security key. Later secure operations can show Authenticate before remote control, terminal access, file management, disk analysis, or similar actions.
That technician authenticator flow is separate from the ZynoSuite sign-in passkey described above.
For the cryptographic authorization model behind secure technician actions, see the ZynoRMM Security Model.
Common issues
| Problem | What to check |
|---|---|
| The Passkey tab is unavailable | Your organization can require SSO or disable new local passkey setup. Use the sign-in method it permits. |
| The browser rejects setup | Use a supported WebAuthn authenticator that supports PRF, then retry from the same approved browser origin. |
| The passkey prompt does not show an account | Select Sign in with a passkey from the web login page, or enter the email for the account first. |
| You use ZynoWorkstation | Workstation uses its shared-device password or fingerprint workflow; manage a personal sign-in passkey in a browser session. |