Passkeys, one-time codes and a tidy vault: next steps with a password manager
Go beyond the basics of a work password manager. Learn what passkeys are and why they resist phishing, the difference between synced and device-bound passkeys, why typed one-time codes can still be phished, how to look after recovery codes, and how to keep a team vault tidy: owners for shared items, removing unused accounts, and changing passwords when there's evidence of compromise or someone who knew them leaves. Vendor-neutral, based on FIDO Alliance and NIST SP 800-63B-4; your organization's policy decides which tools and settings you use.
- Level
- Intermediate
- Length
- About 40 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 3 Oct 2026
Skills you'll practise
- Explain what a passkey is and why it resists phishing
- Distinguish synced passkeys, device-bound passkeys and passkey providers
- Explain why typed one-time codes are not phishing-resistant and act safely when a page asks for one
- Store and use recovery codes as your organization's policy describes
- Review a shared vault: owners, unused items, and items exposed by a leaver
- Decide when a password should be changed, without unnecessary periodic changes
Course outline
- 1.Passkeys, codes and a tidy vaultVideo · 2 min
- 2.Passkeys: signing in without a password to stealLesson · 14 min
- 3.One-time codes and recovery codesLesson · 13 min
- 4.Keeping a team vault tidyLesson · 13 min
- 5.Passkeys, one-time codes and a tidy vault: next steps with a password manager: knowledge checkKnowledge check · 17 questions
- 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.