Skip to main content

Getting started · Public

Your account and security

Update your profile, verify contact details, register passkeys on enterprise tenants, and understand what happens when credentials change.

Your ONE ID belongs to you across every tenant. Profile and security settings live on the account area at my, separate from organisation administration in IAM.

Contact details

Open Security on the account area to update your email address and phone number. Both are used for sign-in recovery and verification.

Phone numbers use a country code picker and a local number field, the same as sign-up. ONE stores the combined value in international format. Keep this current if your organisation allows SMS password recovery.

Email changes

When you change your email, ONE sends a six-digit verification code to the new address. Your account stays in an unverified state until you enter that code on the verification screen. If you had secondary email addresses saved, ONE removes any that match the new primary address.

After you verify a changed address, ONE restores your established account state. You are not sent back through tenant setup or other first-time onboarding unless you are genuinely a new account.

Enterprise email rules

On enterprise tenants, members need the profile:email:edit permission before they can change their primary email on the Security page. Without it, the email field stays read-only.

When a change is allowed, the new address must use one of the organisation's verified domains. The Security page asks for the local part and a separate domain selection. ONE also blocks addresses on domains managed by another tenant, the same rule that applies during sign-up. Tenant administrators manage the available domains in IAM → Organisation → Domains.

Passkeys on enterprise tenants

Passkeys are available when your ONE ID belongs to at least one enterprise tenant. They let you sign in with the platform authenticator on your device — Touch ID, Windows Hello, or an equivalent — instead of typing a password every time.

To add a passkey:

  1. Open Security on the account area.
  2. Choose a short label that identifies the device, such as "MacBook Pro" or "Work laptop".
  3. Complete the browser prompt to register the passkey.

When your organisation has an enabled custom domain, ONE completes the registration ceremony on that hostname. My → Security starts the flow and hands your session to the custom hostname when needed so the passkey is bound to the hostname you sign in on.

You can register more than one passkey and remove any you no longer use. Removing a passkey does not delete your ONE ID or tenant memberships.

Passkeys are not available on personal or commercial-only accounts today. If you also use a password, keep recovery options current in case you move to a device without your registered passkey.

When your organisation changes its custom sign-in hostname, passkeys registered on the previous hostname are disabled. Enabling a custom domain for the first time also disables passkeys that were registered on platform hostnames such as auth.skyfallen.one. My → Security shows active passkeys only. IAM administrators can review disabled credentials — including the hostname and reason — on a member record. If passkey enforcement applies to you, register a new passkey on the current hostname before you can continue.

After a password reset

If your account has passkeys registered, ONE may return you to the sign-in screen after you set a new password so the passkey step can still run. This keeps both factors aligned when you recover access.

Tenant switching and security

Security settings apply to your ONE ID globally. Tenant permissions apply only inside the organisation you have selected. Changing your email or phone does not change what you can do in IAM — that still depends on your membership and permission grants in each tenant.

English