Skip to content

Account security and recovery

Workspace delegates passwords and passkeys to the deployment’s identity provider. Open Account security → Manage sign-in and recovery to manage these methods. Your organization membership and scientific project permissions remain separate.

On a supported, correctly configured HTTPS deployment, open the provider’s Signing in page and add a passkey. Follow your browser’s device or security-key prompt. Keep an approved fallback method while testing. End the provider session, then select Sign in with Passkey on a fresh login. Signing out of Workspace alone does not necessarily end the identity provider’s SSO session.

The private Keycloak pilot has passed virtual CTAP2 enrollment and a fresh passwordless assertion with user verification. An uninvited test identity remained denied by Workspace. Physical Touch ID, synced passkeys and hardware-key acceptance are still separate customer/device qualification steps.

If the hostname does not resolve, contact IT about DNS/network configuration. Passkeys are bound to the configured relying-party hostname; a different address or an insecure certificate workaround is not an equivalent test.

When IT has configured and tested the provider’s email service, use Forgot password at sign-in. Use only the newest valid recovery message. If none arrives, check spam and ask IT to inspect delivery; avoid repeated requests. A local captured mail test is not proof of internet delivery. The private pilot now has a verified Proton-to-Gmail recovery test: receipt, password reset, fresh login and rejection of the old password passed. This does not qualify every customer mail provider. Workspace invitation delivery is a separate qualified workflow.

The single-VPS pilot now uses a persistent identity database, service startup units, encrypted off-site backups and readiness checks. Database restoration was tested in isolation, and encrypted remote read-back was verified. These do not establish a complete machine-loss recovery drill or high availability. IT owns provider/network policy, secrets, backup retention and monitoring. End users manage their own allowed sign-in methods and sessions; project owners separately control scientific data access.