Pandorex
Security

Passkeys in the Enterprise: Why 2026 Is the Year Passwords Should Finally Die

Published Pandorex Redaktion·8 min read
—

Passwords are the weakest link in IT security. This has been known for 20 years. Phishing, credential stuffing, brute force, infostealers. 80% of all successful attacks begin with compromised credentials. And yet in 2026, most employees still log in with username and password. Often without MFA. Sometimes with the same password they use privately.

The technology meant to change this is here. It is called Passkeys.

What Passkeys Are Technically

Passkeys are based on the FIDO2/WebAuthn standard. Instead of a password, a cryptographic key pair is generated: a private key that never leaves the device, and a public key that is stored with the service. Authentication is done via challenge-response: the server sends a random number, the device signs it with the private key, the server verifies the signature with the public key.

The private key is bound to an authenticator: the smartphone (Face ID/Touch ID), a hardware key (YubiKey, Titan Key), or the platform authenticator of the operating system (Windows Hello, macOS Keychain). Phishing is thereby technically impossible because the key is bound to the domain. A fake login page under a different domain cannot trigger the passkey.

The Status at the Major Platforms

  • Apple: Passkeys since iOS 16 / macOS Ventura. iCloud Keychain synchronizes passkeys across all Apple devices. Since 2025: passkey sharing in family groups and enterprises (Managed Apple IDs).
  • Google: Passkeys as the default login for Google accounts since October 2024. Chrome and Android synchronize via Google Password Manager. Cross-device login via QR code + Bluetooth.
  • Microsoft: Windows Hello as platform authenticator. Entra ID (Azure AD) has supported passkeys since 2025. Integration into Microsoft 365 Conditional Access Policies.

The infrastructure is in place. Every modern browser supports WebAuthn. Every current smartphone has a biometric authenticator. The question is no longer "Can you use passkeys?" but "Why are you not doing it?"

The Hurdles in the Enterprise

In practice, adoption fails due to familiar problems:

  • Legacy systems: SAP GUI, old terminal server applications, internal tools from the 2000s. These systems do not know WebAuthn. Migration is expensive and takes years.
  • Heterogeneous device landscape: Not every employee has a current smartphone. Shift workers in production share terminals. External consultants bring their own devices.
  • Recovery processes: What happens when the smartphone is lost? Who resets the passkey? How do you ensure the recovery process itself does not become an attack vector?
  • Regulation: In some industries (banking, healthcare), there are specific authentication requirements that cannot simply be fulfilled by "use passkeys."

The Pragmatic Path: Hybrid Strategy

No company will eliminate all passwords overnight. The realistic path:

  1. Phase 1: Enforce MFA. Every account gets MFA. Hardware keys (FIDO2) for admins and privileged accounts. Authenticator apps for everyone else. Immediately implementable, immediately effective.
  2. Phase 2: Passkeys for cloud services. Microsoft 365, Google Workspace, Salesforce, ServiceNow. These services support passkeys natively. Roll out to a pilot group, then scale.
  3. Phase 3: Passkeys for internal systems. Identity provider (Entra ID, Okta, Keycloak) as the central authentication layer. Internal systems delegate auth to the IdP. Passkeys are used at the IdP; the legacy systems behind it notice nothing.
  4. Phase 4: Passwordless organization. Long-term goal. Passwords exist only as a fallback that is actively restricted (e.g., only from the corporate network, only with additional verification).

Costs and ROI

The direct costs for passkey rollout are manageable: hardware keys cost 25-60 EUR each. Software (IdP, Conditional Access) is already included in Microsoft 365 E3/E5 or Google Workspace Enterprise. The largest cost block is change management: training, communication, support during the transition phase.

The ROI, however, is measurable: helpdesk costs for password resets decrease (Gartner estimates 70 USD per reset). Phishing attacks on credentials become ineffective. Account takeover risk drops drastically. And compliance requirements (NIS2, DORA, ISO 27001) become easier to fulfill.

In 2026, there are no more technical excuses. Only organizational ones. And those can be solved.

Sources: FIDO Alliance, Google Security Blog, Microsoft Entra Documentation, Gartner Password Reset Cost Study.

Comments

Sign in to write a comment.

Swipe up
Next Article

AI Agents as Attack Vector: Why Autonomous AI Systems Are the Biggest New Security Risk in 2026

Security