One account gets you into several apps across your organization. If someone else signs in as you, the impact is much wider than a single app.
A verification request you did not start
Section titled “A verification request you did not start”This is the situation to watch for. You are not signing in, but you receive any of these:
- A verification code pushed to you by @SSOBot
- A Confirm this sign-in? page
- An SMS or email asking you to enter a code
Someone is trying to sign in to your account. When that happens:
- Do not give the code to anyone.
- Select Decline on the confirmation page.
- Contact SSOSupport Bot promptly and tell them when the request arrived.
Read confirmation pages before you allow
Section titled “Read confirmation pages before you allow”The Confirm this sign-in? page shows the application that started sign-in, while the User Consent page lists the apps requesting access. Before selecting Allow, check that these are apps you intentionally opened. If they are not, or if you did not start the action, select Decline.
Set up a Passkey
Section titled “Set up a Passkey”Of the verification methods, a Passkey is the easiest one to set up and manage yourself. As long as you still have the device and its Passkey, routine verification usually needs only your fingerprint, face, or screen lock. Your organization may still require an extra face check.
The other methods depend on more conditions: verifying with another device requires that device to be at hand, while one-time password requires a new OTP from SSOSupport Bot.
Replacing or losing a device
Section titled “Replacing or losing a device”| Situation | What to do |
|---|---|
| Getting a new phone or computer | Before replacing it, ask SSOSupport Bot how to handle the old Passkey and sign in on the new device; do not remove the old Passkey until you know the new device can sign in |
| A device is lost | Ask SSOSupport Bot to remove the old Passkey and issue an OTP for account recovery |
| Lending a device to someone | Sign out in the app and close every browser window when you finish |
On public or shared devices
Section titled “On public or shared devices”Sign out in the app and close every browser window when you finish. Closing only the tab does not sign you out. Never register a Passkey on a public device.
What you must never forward
Section titled “What you must never forward”Never forward a verification code, an OTP, or a full sign-in link from an email. Any one of them is enough for someone else to sign in as you.