Skip to content

Security tips

Practical habits that protect your account, and what to do when something looks wrong.

One account gets you into several apps across your organization. If someone else signs in as you, the impact is much wider than a single app.

This is the situation to watch for. You are not signing in, but you receive any of these:

  • A verification code pushed to you by @SSOBot
  • A Confirm this sign-in? page
  • An SMS or email asking you to enter a code

Someone is trying to sign in to your account. When that happens:

  1. Do not give the code to anyone.
  2. Select Decline on the confirmation page.
  3. Contact SSOSupport Bot promptly and tell them when the request arrived.

The Confirm this sign-in? page shows the application that started sign-in, while the User Consent page lists the apps requesting access. Before selecting Allow, check that these are apps you intentionally opened. If they are not, or if you did not start the action, select Decline.

Of the verification methods, a Passkey is the easiest one to set up and manage yourself. As long as you still have the device and its Passkey, routine verification usually needs only your fingerprint, face, or screen lock. Your organization may still require an extra face check.

The other methods depend on more conditions: verifying with another device requires that device to be at hand, while one-time password requires a new OTP from SSOSupport Bot.

Situation What to do
Getting a new phone or computer Before replacing it, ask SSOSupport Bot how to handle the old Passkey and sign in on the new device; do not remove the old Passkey until you know the new device can sign in
A device is lost Ask SSOSupport Bot to remove the old Passkey and issue an OTP for account recovery
Lending a device to someone Sign out in the app and close every browser window when you finish

Sign out in the app and close every browser window when you finish. Closing only the tab does not sign you out. Never register a Passkey on a public device.

Never forward a verification code, an OTP, or a full sign-in link from an email. Any one of them is enough for someone else to sign in as you.