Sign-in methods in your tenant
Each tenant chooses how its users sign in, from passwords to passkeys, and how strictly each method is rolled out.
Authentication settings
Open Authentication in the tenant sidebar. Five methods are available: passwords, email sign-in links, email one-time codes, authenticator apps, and passkeys or security keys. Each method has a rollout: Off, Optional, or Required. The page also shows how many users have set up each method.
Method settings include how long email links and codes last, whether a link may be opened on another device, the name shown in authenticator apps, and whether passkeys need a PIN or biometric, which kinds of authenticator are allowed, and whether a passkey alone can sign someone in. You can also decide when to ask for a second step, whether users who hold management roles always need one, how many days a browser can be trusted to skip it, and how many recovery codes each user gets. Registration settings control whether people can create their own accounts on your sign-in page and whether users can change their own email address.
Changing these settings needs the Authentication update permission, which the built-in Tenant Admin role has and custom roles can include. Every change is recorded in the tenant's Audit. Settings that would leave users without a way to sign in are refused.
Optional and required methods
An Optional method appears on each user's Security page, and new users are offered it once after registering. A Required method is a forced migration: new users set it up while registering, and existing users sign in the usual way one last time, then set it up before they can continue.
A Required method can have a deadline. After the deadline, users who have not set up the method cannot sign in. An administrator with the reset permission can open the user's row in Users and choose Reset sign-in methods. That removes the user's methods and gives them seven days to sign in and set up again.
A Required sign-in method can also replace passwords. Set passwords to Optional or Off first. Each user's password is then removed as soon as they set up the new method.
What users see
Tenant users sign in on your tenant's own address, at /login. Applications that use your tenant send them there during an authorization request, and they return to the application once every step is done. The sign-in page offers each method you turned on, plus Create an account and Forgot your password? when those apply.
Signed-in tenant users have their own Your Profile and Security pages at /account and /account/security. There they can confirm their email address, change their password, turn email sign-in on or off, set up an authenticator app or passkey, create new recovery codes, and forget trusted browsers. Changing sign-in methods needs a recent sign-in, and users receive an email whenever a method is added or removed.
Tenant users with management roles
A tenant user can manage your tenant when you give them a management role. In Users, choose Management roles on their row and select the built-in Tenant Admin role or a custom role. They then manage the tenant at /manage on your tenant's address, and can do exactly what their roles allow. A tenant user's roles never reach Beyond the Login or another tenant, and at least one BTL Tenant Admin must always remain.
BTL accounts
Beyond the Login accounts follow the same kinds of settings, managed by BTL administrators for BTL's own organization. Your account's Security page shows the methods BTL offers and the ones you have set up.