Point has no password of its own. You type your email address into the sign-in screen. A message arrives in your mailbox with a link in it. Opening that link puts you into your account. Nobody on the team invents a password, stores one, or resets one at 8:30 on a Monday morning.
That’s the whole mechanism, and it’s the smaller half of the subject. The larger half is where the way in went. A firm that stops maintaining passwords still has a way in, and that way in now sits on an account the firm already owned.
What actually happens when you sign in
Four steps, and the only thing you supply is your address.
You give the sign-in screen an email address. Point sends a message to that address. The message carries a link. Opening the link signs you in, on whichever device you opened it on. The session stays until it ends the way any session ends.
Two things follow from that immediately, and they decide most of what comes later.
The first is that your mailbox is the credential. Reading mail at your address is how you get into your account, and it’s the whole of how you get in. Everything reassuring about this arrangement comes out of that one sentence, and everything worrying comes out of it too.
The second is that a sign-in link is a message, and a message lives with whatever happens to messages. Filters hold it. Scanners open it. Rules forward it. Somebody else with access to the mailbox reads it. That’s the shape of every emailed sign-in link there has ever been, and the practical half of this page follows from it.
One thing to separate before going further, because people merge the two constantly. The way you get into Point and the way Point reaches your mail are two keys on two doors. Your mailbox is connected by an authorization you make at your provider’s own sign-in, so your email password stays with your provider. The anatomy of that key is where your email credentials are kept. This page is about the other door, the one with your name on it.
What a firm stops maintaining
Start with the dull version of the benefit. The dull version is the one that shows up in your week.
Somebody joins, and there’s no password to choose for them. Nothing travels to them, and nothing sits in a message thread afterwards. There’s no password to store either, so it stays out of the shared document, off the card in the drawer, and out of the one browser that held it alone. There’s no reset. Somebody can’t get in, asks you, and you both find out that the credential for a business system lives in your head: that whole interruption stops happening. The rotation ritual goes with it, along with the quarterly reminder and the round of people adding a number to the end of what they had before.
That last one is worth a moment. Most small firms still run a password policy that its own source has withdrawn.
The federal guidance here is NIST Special Publication 800-63B. The current revision was published in July 2025, replacing one dated March 2, 2020. Section 3.1.1.2 says that verifiers “SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords”. The same section says they “SHALL NOT require subscribers to change passwords periodically”, with evidence that the password has actually been compromised as the exception. Those capital letters are how the standard marks a requirement rather than advice.
Be careful about what that governs. NIST writes for federal agencies and their identity systems. A seven-person accounting practice sits outside its scope, so read it as evidence rather than as a rule you’re under. The evidence is the more useful half anyway. The people who study this professionally now hold that the character-class rules and the ninety-day reset cost more than they bought. They pushed people toward predictable patterns and written-down copies. If your firm’s password habits date from a training session some years ago, they are habits the source has since dropped.
The same section carries the number that says most about what a password is now expected to do. A password working on its own, as the single thing in the way, has to be at least 15 characters. Eight is permitted only where the password is one factor among several.
That’s the honest frame for what a magic link buys. It clears out a weakness most firms were already sitting on. The passwords actually in use at a small business are rarely 15 characters, rarely unique to the service, and rarely known to only one person. Take the password out of the arrangement and the weak one goes with it. That’s the password that gets reused, guessed, shared in January and still working in June, or turning up in somebody else’s breach. Point’s own description of the benefit stays deliberately modest: “A magic link gets people in quickly, one less password for the team to manage or lose.”
What an emailed link is not
Now the part a supplier has less reason to tell you. It’s why this page exists, rather than a line on a features list.
The same NIST publication is blunt about email as an authentication channel. Section 3.1.3.1:
Email SHALL NOT be used for out-of-band authentication because it may be vulnerable to: Access using only a password; Interception in transit or at intermediate mail servers; Rerouting attacks, such as those caused by Domain Name System (DNS) spoofing
That’s narrower than it first looks, and more useful once the shape of it is clear. The rule covers email as a second factor, a channel you’re meant to prove you hold. A message to your address proves nothing about which device is holding it. And the first reason on that list is the one that matters most here, because it describes exactly the arrangement we’re in. A password may be the only thing guarding the mailbox.
So here’s the accurate sentence about signing in this way, said once and plainly. It’s single-factor authentication, and its strength is exactly the strength of your mailbox. It beats a reused password on a service nobody protects. It isn’t a password plus a hardware key, and nobody should tell you otherwise, this page included.
That points somewhere specific, and it points out of the product. Whatever protects the provider account underneath your address is the thing actually protecting your Point account, along with a good deal else you own. The subject of why Point never needs your email password is why that account was always the important one, and what it already holds the keys to. An hour there is the highest-value hour anybody reading this page can spend, and it happens entirely outside Point.
Two smaller things belong here. People run into both, and they’re unsure what they’re seeing.
A sign-in link you didn’t ask for means somebody typed your address into a sign-in screen. Usually that’s all it is. Occasionally it’s the first visible sign of somebody working through a list. Either way your account stands where it stood, because the link works only for whoever can read the message. Notice it rather than delete it. Point’s terms put the duty of “promptly notifying Point of suspected unauthorized access to an Account or Customer Data” on the customer (section 5, checked September 7, 2026). That’s the correct division, and it works when somebody at your end is looking.
The link belongs to you alone, and nobody legitimate ever asks for it. A phone call, a chat message, or a mail asking you to forward a sign-in link or read out a code is the whole attack, start to finish. Support, an administrator, a colleague covering for you, anybody at all: the link stays with you. It’s the door.
Passkeys and why this is not one
If you searched for password-less sign-in, there’s a fair chance you had passkeys in mind. The two differ enough that the difference is worth four paragraphs.
A passkey is a key pair. Your device or your password manager keeps the private half, and that half stays where it is. The site keeps the public half. Signing in is a proof performed against a challenge. The specification behind it is the W3C’s Web Authentication API, which reached Level 3 as a W3C Recommendation on August 25, 2026 (checked September 7, 2026). What makes passkeys interesting is binding rather than convenience. The credential is tied to the site’s domain, so a convincing copy of a sign-in page at a lookalike address gets nothing out of it. There’s nothing to type, so there’s nothing to type into the wrong box.
An emailed link works another way. It’s a bearer token in a message, so whoever holds it can use it, and the only question is who can read the mailbox. That’s why the two sit on different rungs. The word “password-less” covers both at once: a genuinely phishing-resistant method, and a method that inherits whatever your email inherits.
Point’s sign-in is the link. Saying so lets you do the arithmetic yourself. Your firm may carry a written requirement for phishing-resistant authentication, from an insurer, from a client’s security questionnaire, or from a professional obligation you have taken on. A mailed link falls short of that requirement, and asking any supplier the question beats assuming the answer. Point’s published team and admin capabilities are inviting people into one organization, signing in without a password, changing seats as the team changes, and moving between businesses. Single sign-on through your own identity provider sits outside that list, so if that’s a firm requirement, ask before you plan around it.
There’s a version of this worth knowing even if you never think about Point again. A passkey on one business application, sitting above an email account still guarded by a password and a reset link, is a strong lock on an interior door. Most services in your practice will send a reset to your address, so the address is the account that decides the others. Whatever the strongest authentication your email provider offers happens to be, that’s where it earns the most.
The address is the account
The administrative consequences all come down to one fact. The address is the person.
Joining. An invitation goes to an address, and that address becomes the way in. You issue nothing, and no credential travels between two people, which quietly removes the most awkward step in onboarding anybody. The invitation asks one thing before anything else: which business the person is joining. For an owner who runs more than one, that’s a real decision, made in about four seconds. Two businesses on one login is where that line gets drawn, and what a seat costs and how a plan moves is the other half of adding somebody.
Leaving. Removing a person’s membership ends what they can do next, and it lands on that one person rather than on everybody. That’s the whole difference between this and a shared password. The address being the credential also cuts both ways at exactly this moment. Somebody whose mailbox stays live, at an address that’s still a member somewhere, can request a link and get in. So the offboarding step that matters is the same one it always was, done in the same week. The person’s mailbox closes, the membership ends, and each one needs the other. Point’s terms are explicit that “secure configuration and use of the Services, including Admin roles, account access, credentials, authorization settings” sits with the customer (section 5, checked September 7, 2026). That’s the concrete shape of the responsibility, and it reads as a working instruction rather than a disclaimer.
Role addresses. An address like info@ or admin@ is read by several people by design. Use one as a sign-in address and you hand the account to everyone in that rotation, and to whoever inherits it next year. A named person gets a named address. A queue is a different thing with a different purpose, and who has it is the version of that question a two-partner firm runs into first.
Changing an address. If somebody’s address changes, their way into Point changes with it. The old address stays a way in for as long as it stays a member. Handle the two as one act.
What is recorded. Signing in leaves a record. Point’s privacy policy lists “login events, session data, authentication method, email verification status, security settings, device identifiers, and access logs” among the account and authentication information collected (section 3.2, checked September 7, 2026). That’s what makes “who was in this account on Tuesday” a question with an answer. It sits apart from the record of what Point itself did on your behalf, which is the activity log behind every action.
When the link does not turn up
Most of the trouble people have with this arrangement is delivery, and almost all of it has one of five causes.
It went where mail goes. Spam, quarantine, a rule somebody wrote three years ago, a filter that files anything from an unfamiliar sender. Look first where you’d look for any other message that went missing.
A security product is holding it or has already opened it. This is the cause people least expect, and it produces the strangest symptoms. Microsoft’s documentation for Defender for Office 365, checked September 7, 2026, describes Safe Links as providing “URL scanning and rewriting of inbound email messages during mail flow, and time-of-click verification of URLs and links in email messages”. With the option to wait for scanning selected, “Messages that contain URLs are held until scanning is finished”. That’s a link that arrives late. And “URLs that don’t have a valid reputation are detonated asynchronously in the background”. That’s a link something other than you has already visited, before you ever saw it. So a one-time link that reports itself already used, on a tenant with mail filtering in front of it, usually has an explanation of that kind. Take it to whoever administers your mail security, rather than solving it from your own inbox.
The link opened somewhere else. The session lands on the device where the link was opened. Asking for a link on a laptop and then opening it on a phone signs the phone in and leaves the laptop where it was.
The address has a typo in it. Nothing arrives, and nothing tells you why. A sign-in screen that says which addresses have accounts will say so to anybody who asks, so this one stays quiet. The silence is deliberate, and it looks exactly like every other reason a message goes missing.
You cannot get into your mail. If you’re locked out of Point because you’re locked out of your mailbox, the mailbox is the thing to fix, and your email provider is the one who can fix it. It’s the clearest possible demonstration of what the first section said: the mailbox is the credential.
Common questions
Is signing in with a link less secure than using a password?
It depends entirely on which password you’re comparing it to. For most small firms, the honest answer is that it’s better than what was there before. NIST’s current guidance sets a minimum of 15 characters for a password doing the job on its own (checked September 7, 2026). The passwords actually in use at small businesses are usually shorter, reused elsewhere, and known to more than one person. A link clears all three of those at once. It still leaves you with one factor. The same guidance says email “SHALL NOT be used for out-of-band authentication”, and the reason listed first is that a mailbox may itself be behind only a password. So the comparison that matters is your mailbox’s protection against a strong unique password plus a second factor. The second of those is stronger.
If somebody gets into my email, are they in Point?
Yes, and any supplier should tell you so plainly. That’s the arrangement working as described, and it’s why the useful work sits at your email provider rather than in Point’s settings. What that person would find is what Point sees and the surfaces Point offers, at whatever each kind of work is currently set to. That’s a real exposure, and a bounded one. The argument for treating the provider account as the account that matters, and the reasons it already was before any of this, is why Point never needs your email password.
Can we use our own single sign-on instead?
Today, no. Point’s published team and admin capabilities are inviting people into an organization, signing in without a password, changing seats, and moving between businesses. Single sign-on through your own identity provider sits outside that list. Ask rather than assume, because this is the one thing on this page a firm can be genuinely constrained on. If an insurer, a client questionnaire, or a professional standard requires federated sign-in or phishing-resistant authentication, a mailed link falls short of it. Take that requirement as it stands today, rather than as a supplier’s roadmap.
I received a sign-in link I did not request. What does that mean?
It means somebody put your address into a sign-in screen. Your account is where you left it, because the link is only usable by whoever can read the message it arrived in. Once is usually a mistyped address, or a person testing what exists. Repeatedly is a pattern worth reporting, and Point’s terms put prompt notice of suspected unauthorized access on the customer (section 5, checked September 7, 2026). Keep the link to yourself, whatever anybody says they need it for.
Does Point have my email password?
No. These are two separate keys. Your mailbox is connected by an authorization you made at your provider’s own sign-in page, so the password stayed with the provider. What Point holds is a grant issued in its name, and either side can end it. Getting into Point is the separate door this page is about, and it has no password either. Somebody inside your Point account could work through Point’s own surfaces, and your mailbox password stays at your provider throughout. Where your email credentials are kept sets out the first key properly.
The short version
Signing in without a password means there’s no password to invent, share, store or reset. For a small firm that’s a real subtraction from the week rather than a feature. It also means the address is the account. Everything protecting your mailbox is protecting your Point account, and that’s the whole of the protection. So the strongest authentication your email provider offers is the single best thing you can do about any of this. Point’s arrangement is a mailed link rather than a passkey. It’s convenient, and it isn’t phishing-resistant, and a firm carrying a written requirement for the latter should ask before assuming. The administrative half comes down to one habit. The week somebody leaves, the mailbox and the membership both end, because each one on its own leaves the door open. Point is what an account signs you into, and everything waiting on the other side of the link is listed on benefits.