Evo Portal
Passkeys
Passkeys provide a secure, passwordless way to sign in to Evo. Instead of entering a password, users authenticate using a supported method such as their device’s biometric or PIN verification, a password manager, or a compatible physical security key. Passkeys use FIDO2/WebAuthn technology and are designed to provide a simpler, phishing-resistant sign-in experience.
Passkeys can be used with supported Portal, SAML, and Microsoft External Authentication Method (EAM) authentication flows.
Before You Begin
Before enabling Passkeys, verify:
- Passkey Login is enabled for the appropriate users.
- Users have MFA enabled.
- Users have not reached their configured Passkey Registration Limit.
- The browser, device, and authenticator being used support Passkeys.
Note: Users with MFA disabled cannot use a Passkey for sign-in.
Configure Passkey Policies
Navigate to:
Admin Portal → Policies
Edit the policy that applies to the intended users and configure the Passkey settings as needed.

Passkey Login
Determines where Passkeys can be used.
Available options include:
- Portal – Allows Passkeys for Evo Portal authentication.
- SAML – Allows Passkeys for SAML authentication and supported Microsoft EAM flows.
Note: Turning off Passkey Login does not delete Passkeys users have already registered.

Passkey Registration Limit
Determines the maximum number of Passkeys each user can register.
Administrators can configure a limit between 1 and 10.
If the user reaches the limit, they must remove an existing Passkey before registering another.

Passkey Hardware Restrictions
Administrators can optionally limit Passkey registration and authentication to one or multiple approved authenticator models.
This can be useful when an organization only wants users authenticating with specific approved hardware or Passkey providers.
If an authenticator is later removed from the approved list, existing Passkeys using that authenticator are not deleted, but they can no longer be used while the restriction remains in place.

Passkey Registration on Login
Administrators can choose whether eligible users are prompted to create a Passkey during authentication.
Available options include:
- Off – Users are not prompted.
- Prompt – Users are prompted but can skip registration.
- Force – Users must successfully register a Passkey before authentication can complete.
To receive the registration prompt, the user must have MFA enabled, have no registered Passkey, and have Passkey Login enabled for the authentication method being used.

Require Recent MFA for Passkey Registration
When enabled, users registering a Passkey from an existing Portal session must have completed MFA within the previous five minutes.
If required, Evo prompts the user to complete MFA again before registration.

Register a Passkey
Admin Portal
- Sign in to the Evo Admin Portal.
- Open your profile.
- Navigate to Devices → Passkeys.
- Enter a recognizable name for the Passkey.
- Select Add Passkey.
- Complete MFA verification if prompted.
- Follow the instructions from the browser or authenticator.

User Portal
- Sign in to the Evo User Portal.
- Navigate to Devices → Passkeys.
- Select Create a Passkey.
- Complete MFA verification if prompted.
- Follow the instructions from the browser or authenticator.
Register a Passkey for Another User
Administrators with the appropriate permissions can register a Passkey for another user.
- Navigate to Users.
- Select the user.
- Open Passkeys.
- Select Add Passkey.
- Verify that the correct user is selected.
- Enter a recognizable name.
- Complete administrator MFA verification if prompted.
- Complete registration using the intended authenticator.
Important: The Passkey is registered to the selected user and may be used to authenticate as that user when their policies allow it. Administrator-assisted enrollment permissions should only be provided to trusted administrators.

Passkey Permissions
Passkey permissions can be configured under:
Evo Admin → Permissions → Roles → Passkeys
Available permissions include:
- View Passkeys
- Manage Passkeys
Manage Passkeys includes Register, rename, and Delete permissions.

Sign In With a Passkey
Portal and SAML
- Navigate to the Evo sign-in page.
- Enter your email address.
- Select Continue.
- Select the available Passkey when prompted.
- Approve the request using the configured authenticator.
A successful Passkey authentication completes authentication without requiring an additional MFA challenge.

Microsoft External Authentication Method (EAM)
Passkeys can also be used with supported Microsoft EAM authentication.
EAM uses the SAML option under Passkey Login. There is no separate Passkey setting specifically for EAM.
When prompted during a Microsoft authentication flow, select the Passkey method and complete the authentication request.
Manage Passkeys
Users can manage their Passkeys from their personal Evo Portal or User Portal.
Authorized administrators can manage Passkeys from the user's Passkeys page.
Depending on permissions, administrators can:
- View registered Passkeys
- Rename a Passkey
- Delete a Passkey
- Register a new Passkey
Deleting a Passkey from Evo removes its Evo registration.
The Passkey may still be stored on the user's device, physical security key, or password manager and may need to be removed there separately.
