Passkeys replace the password with a credential that cannot be typed into a fake site. A rollout succeeds or fails on the boring parts: who goes first, what happens when a phone is lost, and whether the help desk knows what to say. This playbook assumes your people sign in through single sign-on and that you can see sign-in logs.
Before you start
Decide what success looks like and who owns it. A named owner, a pilot group and a date for the first review are enough to begin.
Phase 1: the pilot (2 to 3 weeks)
Choose 20 to 40 volunteers across functions and device types, including some from IT support so they learn it first.
Phase 2: administrators first
Administrators carry the most risk, so give them the strongest factor early. Security keys suit them well because they are portable and phishing-resistant.
Phase 3: everyone
Roll out department by department over a few weeks, never everyone on one Monday.
Recovery and lost devices
Most rollout stress comes from lost phones. Decide the recovery route before launch and test it.
Help-desk script
- Ask which device the person is on and which passkey they registered.
- Do not read out or ask for codes or secrets.
- If the device is lost, follow the recovery route and revoke sessions.
- After recovery, ask the person to register a second passkey.
Retiring passwords and codes
When most people have a passkey, narrow the fallbacks. Keep one for recovery, but stop offering text-message codes for accounts that no longer need them.
Measures to track
- Share of active users with at least one passkey, and with two.
- Password-reset and lockout tickets per week.
- Sign-ins by method.
- Time to resolve a lost-device case.
About this runbook
AuthMantra supports passkeys through WebAuthn, including Face ID, Touch ID and Windows Hello, security keys and phones, along with authenticator-app codes and SMS codes (SMS provider integration is planned).
authmantra.com/praxis/run/passkey-rollout-playbook/ · info@authmantra.com