GlossarySecurity awareness

Passkeys

Short answer

A passkey is a sign in credential that replaces the password with a cryptographic key pair stored on the user's device or password manager, unlocked with a fingerprint, face or PIN. Passkeys are based on the FIDO2 standards and are resistant to phishing.

How they work

When a user creates a passkey for a website, the device generates a pair of keys. The website stores the public key; the private key never leaves the user's device or password manager. To sign in, the website sends a challenge, the device signs it after the user unlocks it with biometrics or a PIN, and the website checks the signature. No shared secret travels over the network or sits in the website's database.

Why they resist phishing

Each passkey is bound to the exact domain where it was created. A fake login page, even a perfect copy relayed in an adversary in the middle attack, cannot use it because the domain does not match. There is also no password to reuse, guess or leak, which removes the basis of credential stuffing and brute force attacks.

Synced and device bound passkeys

Synced passkeys are backed up and shared across a user's devices through Apple, Google, Microsoft or a password manager, which makes them convenient and easy to recover. Device bound passkeys, such as those on hardware security keys, never leave a single device and suit administrators and other high risk accounts.

Adoption in companies

Microsoft 365, Google Workspace, the main identity providers and many SaaS applications support passkeys. A practical path is to enable them as an MFA method, require them first for administrators and finance, and then extend them to all staff through SSO. The FIDO Alliance publishes guidance on deploying them.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub