
Passkeys for enterprises promise a passwordless sign-in that leaves phishing attacks with nothing to steal. In this post, I look at how FIDO passkeys have developed and what that means for companies. Technology giants such as Microsoft, Google and Apple are pushing the topic of passwordless authentication on the consumer side. And on the corporate side?
The FIDO Alliance, founded by companies like Infineon, Lenovo, and PayPal, originally aimed to develop a standard for two-factor authentication (2FA). Over time, this initiative evolved into the passkey, a fully passwordless authentication method based on asymmetric cryptography.
Instead of storing passwords, passkeys utilize a private-public key pair: the private key remains securely stored on the user’s device, while the public key is associated with the specific domain of the service provider.
This domain-specific binding makes passkeys inherently resistant to phishing attacks, as they won’t work on fake sites with mismatched domain names. Our article on AiTM attacks shows how attackers get around conventional MFA.
Passkeys come in two variants: device-bound and synced.
Device-bound passkeys, such as USB FIDO security keys like the iShield Key, store keys locally on a single device.
In contrast, synced passkeys synchronize key material across multiple devices through ecosystems Apple’s iCloud Keychain or Google Password Manager, greatly boosting consumer adoption thanks to seamless cross-device compatibility
But for enterprises, can Passkeys offer the same benefits, or do they introduce potential drawbacks and security concerns? Let’s take a closer look.
| Device-bound passkey | Synced passkey | |
|---|---|---|
Stored on | One device, e.g. a hardware security key | Cloud account with Apple, Google or a password manager |
Can be copied | No | Yes, through synchronization |
IT control | High, model verifiable via attestation | Low, depends on the provider |
Recovery | Backup key and IT process | Via the provider account |
NIST assurance level | Up to AAL3 | Up to AAL2 |
Best suited for | Admins, privileged accounts, regulated areas | Accounts with lower protection needs |
NIST, the US standards body, places synced passkeys at AAL2 at most in its Digital Identity Guidelines (SP 800-63-4). For AAL3, the highest level, it requires a private key that cannot be exported. Device-bound passkeys on a hardware security key meet that requirement.
In Microsoft Entra ID, administrators decide which types of passkeys are allowed. Attestation can also restrict sign-in to specific security key models.
The suitability of passkeys for enterprise deployment depends on a detailed assessment of security needs, user workflows, and MFA processes. Before introducing passkeys, companies should thoroughly review and update their MFA policies, which might have been designed with legacy hardware tokens in mind.
Passkeys represent a significant advancement in authentication technology, especially for reducing the risk of phishing attacks. However, their introduction into the enterprise setting requires careful consideration. Beyond technical integration, enterprises need to prepare for potential dependencies on third-party systems, manage device policies, and establish robust processes to safeguard against evolving social engineering tactics. In the end, passkeys may prove to be a valuable addition to enterprise security, provided they are part of a thoughtfully designed and resilient MFA strategy.
From my perspective, there is already a scalable solution for companies seeking enhanced security and phishing resistance: hardware authentication in the form of FIDO security keys. By far the most innovative and technologically advanced security key is the iShield Key Pro MIFARE. Always worth mentioning is the hybrid functionality of the iShield Key Pro MIFARE, which supports not only passkeys, but also conventional one-time password (OTP) and personal identity verification (PIV) as well as MIFARE for contactless physical access to company buildings, parking garages, use of the wallbox and payments in the cafeteria.
This once again underlines Swissbit's innovative leadership in the field of hardware authentication.
Convince yourself of our expertise.
Receive the latest news and announcements about storage and security solutions as well as current events and new products.