4. Going Passwordless with Passkeys & SSO
Register a passkey for phishing-resistant login and understand how Google, Microsoft or GitHub sign-in works.
What are passkeys?
A passkey lets you log in without typing a password. Instead, your device confirms your identity using something built in — Face ID, Touch ID, Windows Hello, or a physical security key. Because the passkey is cryptographically bound to the real OUPI website, it cannot be tricked by a fake look-alike page. That makes passkeys one of the strongest defenses against phishing.
You can register more than one passkey (for example, your laptop and your phone) and remove any of them at any time from Settings > Passkeys.
How does SSO with Google, Microsoft or GitHub work?
If your administrator has enabled it, you can sign in to OUPI using your existing Google, Microsoft, or GitHub account. OUPI matches your account by email address, so no extra password is needed. If your team requires a specific provider, the login page will tell you which one to use.
Already signed up via SSO and want a traditional password too? You can set one from Settings in the Change password section — handy as a backup.
Passkeys vs. passwords vs. SSO — when to use what
• Passkeys: fastest and most phishing-resistant option. Great as your primary login method.
• SSO (Google / Microsoft / GitHub): convenient if your organization already manages identities through one of these providers.
• Password + 2FA: a solid fallback. If you keep a password, pair it with two-factor authentication (authenticator app + backup codes) for extra protection.
You can combine all three: register a passkey, link an SSO provider, and still have a password with 2FA enabled.
AstuceRegister passkeys on every device you use to log in — your phone and your laptop, for example. That way, losing one device doesn't lock you out. You can manage and remove any passkey from Settings > Passkeys at any time.
AstuceIf you also use a password, enable two-factor authentication and store the one-time backup codes somewhere safe outside your phone (like a password manager on another device). Each backup code can replace your authenticator app once if you lose access.
À vous de jouerHead to Settings > Passkeys and register your first passkey now. Your device will prompt you to use Face ID, Touch ID, Windows Hello, or a security key. Once registered, try logging out and back in using only the passkey — no password needed!Suivre ce cours dans OUPI → Cet exercice se fait dans la plateforme OUPI.
À retenirYou now know three ways to sign in to OUPI:
1. Passkeys — phishing-resistant, password-free login tied to your device. Register several for backup.
2. SSO — sign in with Google, Microsoft, or GitHub, matched by email.
3. Password + 2FA — a reliable fallback; always pair it with an authenticator app and save your backup codes.
Combine methods for maximum security and convenience.