Skip to content

Settings and activity

2 results found

  1. 47 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    Hi team, we've just launched passkeys to our first group of users. From this week, Xero Me app users who haven't set up MFA yet will be able to use passkeys to log into Xero. Next, we'll be progressively rolling this out to more users over the coming months. We look forward to and welcome your feedback here. As we have more news on the rollout I'll share with you on this idea.

    An error occurred while saving the comment
    James Bonifield commented  · 

    Passkeys are a decent alternative to the embarassing lack of SSO. Stop wasting time with AI agents and JAX that no one asked for and provide for basic security features

    James Bonifield supported this idea  · 
  2. 493 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    Hi community, we appreciate many businesses have adopted single sign on with providers like Google, Microsoft Azure/Entra, and Okta to easily streamline logins to many applications and manage operational risk. Our team are staying close to votes and feedback of the idea here, and though we can't commit to development at this time, we will be sure to let you know of any progress toward enabling single sign on

    An error occurred while saving the comment
    James Bonifield commented  · 

    I am looking at moving off Xero, as it is ridiculous that SSO support is not provided, and as a provider of Identity & Access Management services it's sort of a deal breaker to use software that doesn't provide this fundamental security benefit.

    By the way - as an enterprise software provider - you should be mindful of CISA's Secure By Design Framework and the myriad other frameworks that you are not in compliance with by not providing SSO (even behind a paywall, which is a separate conversation, but at least it's offered)

    If you need help implementing shoot me an email - james@anthropicidentity.com I work in IAM and have implemented SSO many times. How easy it is to do this vs the impact it has on the maturity of your software makes me a little shocked you still don't have it in place

    James Bonifield supported this idea  ·