Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Enrollment, replacement, and recovery

Before the first sign-in

Avery buys a new security key. Before it can open the staff portal, Cedar Inc. must associate the key's credential with Avery's account. This is enrollment. Without it, a valid signature from the key would tell Cedar Inc. nothing about which account Avery is trying to use.

For a new employee, enrollment can begin through a verified onboarding process. Later additions need suitable proof from the person who already controls the account. Knowing Avery's email address or employee number is not enough to add another way to sign in.

The confirmation depends on the method. An authenticator app can demonstrate that it produces a valid code. A security key returns a registration response that Cedar Inc. validates. Before an email address or phone number becomes a recovery destination, Avery must demonstrate control of it.

Adding and replacing methods

Now Avery replaces a phone while the old one still works. After a fresh authentication check, Avery enrolls the new phone and confirms it can sign in. Only then does Avery remove the old phone. Removing it first could leave Avery without a working method.

A list of enrolled methods helps Avery find the right one to remove. Names and enrollment dates can distinguish a personal security key from an old phone without displaying secret material. A name is just a label, though; it does not prove who currently holds the device.

Avery also needs a backup before something is lost. Depending on the service, that might be another registered key, protected recovery codes, or an assisted recovery route. A backup kept only on the phone Avery might lose will not help.

Cedar Inc. should record method changes and notify Avery through an established channel. A notification may reveal an unexpected change, but the service still has to authorize the change before making it.

When a device is lost

If Avery loses a phone, two things may have changed. Avery might lose a way to sign in, and someone else might now have the phone or a session already open on it. Recovery restores Avery's access. Revocation tells Cedar Inc. to stop accepting a credential that can no longer be trusted.

Removing the lost phone's credential from Avery's account stops future sign-ins with that credential at Cedar Inc. It does not erase a key from the phone or end sessions that are already active. Avery may need to review and end those sessions separately.

If the phone held a synced passkey, removing that credential at Cedar Inc. can stop all synced copies from signing in there. Separately, Avery may need to remove the lost phone from the credential provider's account. These changes act in different places.

Recovery without a shortcut

If Avery loses every enrolled method, Cedar Inc. needs another way to establish that Avery may regain the account. It could use recovery codes issued earlier, a verified recovery channel, or an assisted process with its own checks. Simply knowing the account email address cannot be enough.

A recovery code is a secret that may open the account when the usual methods are unavailable. Avery needs to store it somewhere separate from the device it backs up. Because a recovery code can stand in for every other method, Cedar Inc. treats it like a password: it stores only a hash, lets each code work once, limits guesses, and cancels the old set when it issues a new one.

If support staff help with recovery, they need defined authority and a verification process. The decision should be recorded without storing recovery codes or other secrets. A persuasive caller or an answer to a public personal question cannot replace those checks.

Recovery also has to work in ordinary situations: for someone who has changed phone numbers, does not own a smartphone, or cannot use a biometric check.

A recovery walkthrough

In this fictional example, Avery loses a phone but still has a separately registered backup key.

  1. Avery opens the Cedar Inc. staff portal through a trusted address and signs in with the backup key.
  2. Because Avery signed in moments ago with the backup security key, a phishing-resistant method, the service accepts that sign-in as the fresh check it requires before any change to sign-in methods.
  3. Avery removes the lost phone's credential and reviews active sessions. The service records the changes without credential values.
  4. Avery enrolls a replacement authenticator and confirms it works. Cedar Inc. sends a security notification.
  5. Avery checks that an independent backup remains available.

If Avery had lost the backup key as well, this sequence could not begin with an ordinary sign-in. Cedar Inc. would need to use its recovery process before allowing anyone to replace a credential.

Try it in the Lab

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 2 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 2Avery removes a lost authenticator. Does that necessarily end every existing session?

QUESTION 2 OF 2Someone asks support to remove MFA and supplies the account email address. What should support do?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity