Passwords are still ubiquitous in businesses. At the same time, stolen or misused login credentials remain among the most common entry points for cyberattacks. The latest Verizon Data Breach Investigations Report 2026 shows that, across phishing, stolen login credentials and so-called pretexting, compromised identities are still involved in around 39 per cent of all data breaches. Against this backdrop, passwordless authentication methods such as FIDO2 are coming to the fore. They promise a new level of security, user-friendliness and scalability for modern businesses.
In an increasingly digital business world, passwords have become a risk. They are difficult to manage, easy to steal and often the cause of serious security incidents. Particularly in organisations that handle sensitive customer data and business-critical systems on a daily basis, a compromised password can have serious consequences. The need for a secure, user-friendly and scalable authentication solution is greater than ever.
FIDO2 and passkeys offer a modern alternative. Employees can log in, for example, using facial recognition, a fingerprint or a device PIN, without having to enter a password. For accounts requiring a particularly high level of protection, physical security keys can also be used. Passwordless authentication thus becomes not only more secure, but also simpler. However, this requires a well-planned implementation that is tailored to the existing IT landscape and the various user groups within the organisation.
FIDO2 is an open authentication standard developed by the FIDO Alliance (Fast Identity Online), an international industry consortium with members including Google, Microsoft and Apple. The aim of this alliance is to phase out passwords in the long term and replace them with secure, user-friendly authentication based on cryptographic keys. FIDO2 is based on WebAuthn, a standard from the World Wide Web Consortium, and the Client to Authenticator Protocol (CTAP). WebAuthn enables the use of cryptographic credentials in browsers and applications, whilst CTAP governs communication with the authenticator being used – such as a laptop, smartphone or physical security key.
Passkeys are the most common implementation of this principle today. Instead of a password, a cryptographic key pair is used: the public key is stored with the relevant service, whilst the private key remains securely stored on the device or authenticator and is never transmitted during login. The passkey is authorised using the same method used to unlock the device – facial recognition, fingerprint or device PIN. Biometrics therefore does not directly replace the password, but rather confirms locally that the authorised person is permitted to use the cryptographic key. Biometric data never leaves the device.
When setting up a passkey, the device generates a unique key pair. The private key remains on the device, whilst the public key is stored with the corporate service. When logging in, the service sends a request to the device; the user confirms this via fingerprint, facial recognition or PIN, and the device signs the request with the private key.
The key factor is the link to the specific application or domain: A passkey for Microsoft 365 will not work on a fake login page with a similar-looking address. This makes passkeys significantly more resilient to traditional phishing attacks than passwords or transferable one-time codes.
For most employees, an additional USB or NFC key is no longer strictly necessary. On modern, centrally managed devices, the passkey can be stored directly on a laptop or smartphone – for example, via Windows Hello for Business or passkeys in Microsoft Authenticator. Physical security keys are still useful, however:
The physical key is therefore not the standard solution for all staff, but one of several options. Which option is used should depend on the security requirements, the user group and the existing device environment.
With device-bound passkeys, the private key remains on a specific device (e.g. in the laptop’s security chip) or a physical security key, from which it cannot be copied. This option offers a high level of control and is particularly suitable for managed work devices and privileged accounts.
Synchronised passkeys, on the other hand, are available across multiple devices via a supported provider (e.g. iCloud Keychain, Google Password Manager or an enterprise password manager). This enhances user-friendliness and simplifies switching between devices, but requires an assessment of the synchronisation and recovery processes used. Organisations must also ensure, via policy (MDM), that business passkeys do not end up in employees’ private cloud accounts.
Microsoft Entra ID supports both options and will make passkeys the default sign-in method from September 2026, gradually phasing out SMS and phone calls as multi-factor authentication methods. Microsoft recommends device-bound passkeys (e.g. FIDO2 security keys, passkeys in Microsoft Authenticator) for administrators and privileged roles, and synchronised passkeys for the rest of the workforce.
The most significant security benefit lies in protection against phishing and the misuse of stolen login details: without a reusable password, there is no password that can be entered on a fake website or used for other services following a data breach.
At the same time, logging in becomes simpler: there is no longer any need to create, remember or reset complex passwords. This also reduces the workload on support teams, as password resets are among the most common enquiries received by the service desk. However, this gives rise to new processes relating to device registration, device changes and the recovery of lost access details – these must be taken into account from the outset.
Strong authentication is a key component of modern zero-trust architectures: every access attempt must be verifiably linked to a uniquely confirmed identity. FIDO2 provides better protection against phishing and credential theft during the login process.
However, a successful login alone is not enough. Organisations must also verify which device is being used to access the system, what its security status is, and which applications or data the user is authorised to access. FIDO2 therefore does not replace authorisation management, endpoint protection or the monitoring of suspicious activity, but rather strengthens a key part of the security architecture.
A successful implementation begins with an analysis of the existing environment: Which identity platform, devices, operating systems and line-of-business applications are in use, and which of these support FIDO2 or passkeys?
Suitable user groups and areas of application are then defined. It is often advisable to start by securing privileged accounts or applications requiring particular protection, and then to expand the solution step by step.
The recovery process is particularly important: If a device is lost, it must be possible to set up new access quickly without creating an easier attack vector. Identity verification by support staff, the handling of replacement devices and the blocking of lost authenticators must therefore be clearly regulated – as must the controlled use of weaker fallback methods. Last but not least, clear communication is essential: staff should know why the login process is changing, how it works and what to do if a device is lost.
FIDO2 and passkeys offer a very high level of protection against traditional phishing attacks and the reuse of stolen passwords. However, this does not make a company invulnerable: a compromised end device, a stolen active session, incorrectly granted permissions or exploited software vulnerabilities remain areas of risk in their own right – according to the latest DBIR, the latter are in fact the most common point of entry. Social engineering targeting the service desk and insecure recovery processes also remain potential points of attack.
When implemented correctly, however, FIDO2 significantly reduces a particularly frequently exploited risk and is therefore an important, but not the sole, component of IT security.
The introduction of passkeys affects not only the login process itself, but also the management of identities and endpoints, the security of privileged accounts, and clear support and recovery processes. MTF supports organisations in analysing their existing environment and developing a suitable strategy for passwordless authentication – from the integration of FIDO2 and Windows Hello for Business, through the configuration of Microsoft Entra ID and Intune, to the selection of appropriate authenticators for different user groups.
Contact us and play an active part in shaping the path to a passwordless future.