Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Runbook · 10 min read · 23 steps

Passkey rollout playbook

A phased plan for moving a workforce from passwords and codes to passkeys, with pilots, recovery, support and measures of success.

Passkeys replace the password with a credential that cannot be typed into a fake site. A rollout succeeds or fails on the boring parts: who goes first, what happens when a phone is lost, and whether the help desk knows what to say. This playbook assumes your people sign in through single sign-on and that you can see sign-in logs.

Before you start

Decide what success looks like and who owns it. A named owner, a pilot group and a date for the first review are enough to begin.

Phase 1: the pilot (2 to 3 weeks)

Choose 20 to 40 volunteers across functions and device types, including some from IT support so they learn it first.

Phase 2: administrators first

Administrators carry the most risk, so give them the strongest factor early. Security keys suit them well because they are portable and phishing-resistant.

Phase 3: everyone

Roll out department by department over a few weeks, never everyone on one Monday.

Recovery and lost devices

Most rollout stress comes from lost phones. Decide the recovery route before launch and test it.

Help-desk script

  • Ask which device the person is on and which passkey they registered.
  • Do not read out or ask for codes or secrets.
  • If the device is lost, follow the recovery route and revoke sessions.
  • After recovery, ask the person to register a second passkey.

Retiring passwords and codes

When most people have a passkey, narrow the fallbacks. Keep one for recovery, but stop offering text-message codes for accounts that no longer need them.

Measures to track

  • Share of active users with at least one passkey, and with two.
  • Password-reset and lockout tickets per week.
  • Sign-ins by method.
  • Time to resolve a lost-device case.

About this runbook

AuthMantra supports passkeys through WebAuthn, including Face ID, Touch ID and Windows Hello, security keys and phones, along with authenticator-app codes and SMS codes (SMS provider integration is planned).

General information, not legal advice. Published by AuthMantra, Titanium Tech Park, Bidarahalli, Bengaluru 560066.

Want help applying this?

We are happy to walk through it with your team.