Prisma Browser
Passkey Login
Table of Contents
Expand All
|
Collapse All
Prisma Browser Docs
Passkey Login
this is information for Passkey login
| Where Can I Use This? | What Do I Need? |
|---|---|
|
|
Passkeys offer a passwordless, secure, and convenient method for signing
into apps and websites. They use your device's built-in security (like fingerprint,
face scan, or PIN) and public-key cryptography to generate unique,
phishing-resistant credentials that automatically sync across your devices and act
as a Multi-Factor Authenticator.
Some passkeys are managed for corporate access (such as IdP authentication,
or PB authentication factor). However,
users are frequently prompted by third-party websites to create passkeys for
convenience. Consequently, they often generate personal passkeys that are unseen and
outside of IT control.
PB solves this by providing granular control over passkey login.
Administrators can apply policies to allow or deny passkey usage based on
application, device posture, network, or location. For example, you can explicitly
allow passkey login for your sanctioned Identity Provider (e.g. Okta), while
blocking passkey usage on other, non-corporate applications.
The Passkey Login control is supported on Prisma Browser and Prisma Browser Extension.
To enable Passkey Login Control:
- At the Login controls tab, select Passkey login.
Click on the Passkey login tab to open Control Passkey login, and select one of the following options:- Allow - Logins using Passkeys will be permitted.Block - Logins with Passkeys will be blocked.
If you select Allow, you can require the use of multi-factor authentication.- Click on the MFA tab to open the Multi Factor Authentication.Select Require additional MFA prior to login.
The Prisma Browser Extension does not support Multi Factor Authentication; any configuration for Prisma Browser Extension will be ignored.If you select Block, you can allow your users to prompt for special permission to bypass the negative result. Click the Prompt tab.- Pop-up Notifications. Select one of the following options.
- Warn and allow to proceed anyway - Users will receive a warning but they can proceed anyway.
- Warn and allow to proceed anyway with a reason - Users will receive a warning but they can proceed if they provide a reason.
- Permission Request – You will receive a message requesting permission.
Bypass timeframe – Indicate how long any bypass will be valid.
If you want to configure a custom Dialog text that will appear when the user is blocked, do the following:- Click Dialog text.Select one of the following options:
- Use default texts - Do not provide any custom texts for your users.
- Customize default texts - Enter a Title for your message and an optional description
Click Set.