Most implementations of passkeys I see fall into two categories
-
Login with User/Password then passkey and/or topt as 2FA
-
Login with just passkey(and maybe TOPT for extra confirmation)
-
Number 2 with Number 1 as fallback
however it seems like with Alta Cloud Management it lets you either login with user/password(less secure 2FA TOPT disallowed with passkey enabled) or via just a Passkey(More Secure) however the purpose is defeated since regular logins are still enabled, if you have passkeys enabled you can only use it as the primary factor or fall back to no user/pass with no 2FA. i.e. If you were using TOPT 2FA before enabling passkeys and then switch to passkeys, you just made your account LESS secure