What Are Passkeys?

Also called: Passkey

Related problems: Staff typing passwords into fake login pages; Users tired of passwords plus MFA codes; Need phishing-resistant MFA without buying hardware keys for everyone; Not sure whether passkeys synced to personal accounts are acceptable for work

Passkeys are sign-in credentials that replace passwords with cryptography. When a user creates a passkey for a website or app, their device generates a pair of keys: the public key goes to the service, and the private key stays with the user, on a phone, laptop or hardware security key, or in a credential manager that syncs it between their devices. To sign in, the user unlocks the passkey with a fingerprint, face scan or device PIN, and the device proves possession of the private key. Passkeys are built on FIDO2 standards and are one of the main forms of passwordless authentication.

At a glance

  • Based on the FIDO2 standards (WebAuthn and CTAP), supported by major operating systems and browsers.
  • Each passkey is tied to one website or app, so the browser or device won’t use it on a look-alike phishing site.
  • Unlocked locally by biometric or PIN; the biometric itself is not sent to the service.
  • Comes in two forms: synced (backed up across a user’s devices) and device-bound (kept on one device or security key).
  • Commonly used to meet phishing-resistant MFA goals, subject to how they are deployed and policy.

What problem it solves

Passwords are the weak point in most account takeovers: they’re reused, leaked in breaches and typed into fake login pages. Adding a code or push approval as a second factor helps, but attackers relay those through phishing proxies or wear users down with repeated prompts.

Passkeys remove both problems for services that support them. There is no password stored on the server to steal, nothing for the user to type, and the credential only responds to the genuine site. Users also tend to find them faster than a password plus a code. For IT, that means fewer resets and a practical route to phishing-resistant sign-in without necessarily buying a hardware key for every user.

How it works

Registration. The user signs in the usual way and chooses to create a passkey. Their device creates a new key pair scoped to that service’s domain, stores the private key securely and sends the public key to the service.

Sign-in. The service sends a random challenge. The browser or operating system checks which domain is actually asking, finds the matching passkey and asks the user to unlock it with biometric or PIN. The device signs the challenge, and the service verifies the signature with the stored public key.

Synced passkeys. Credential managers built into operating systems, and many third-party password managers, encrypt and sync passkeys across a user’s devices. This makes passkeys easy to recover, but their security then depends on the sync account, which may be a personal account outside company control.

Device-bound passkeys. Hardware security keys and some managed devices keep the private key in hardware that doesn’t export it. Organizations can use attestation to restrict which authenticator models are accepted.

Cross-device sign-in. A user can sign in on a computer using a passkey on their phone, typically by scanning a QR code, with a proximity check between the devices.

Enterprise control. Your identity provider (IdP) decides whether passkeys are allowed, which kinds and for whom. Device management tools, such as mobile device management (MDM), help ensure the devices holding passkeys are company-managed and locked.

When it matters for buyers

  • When moving beyond SMS or app codes. Passkeys are a common way to upgrade multi-factor authentication (MFA) to a phishing-resistant method.
  • When choosing an identity provider or tier. Support for passkeys, device-bound restrictions and attestation varies.
  • When deciding on synced versus device-bound. Many organizations allow synced passkeys for general staff and require device-bound keys for admins.
  • When managing devices. Passkey policy works best when the devices that hold them are managed and up to date.
  • When planning recovery. Lost devices and new phones are routine; recovery processes need to be strong without overloading the help desk.

Questions to ask vendors

  • Do you support passkeys for workforce sign-in, and on which license tiers?
  • Can we allow only device-bound passkeys for certain users, or restrict accepted authenticator models?
  • Can we prevent passkeys from syncing to personal accounts, and how?
  • How are passkeys enrolled for new users, and how do we stop an attacker from enrolling one?
  • What is the recovery process if a user loses every device?
  • Which of our applications can use passkeys directly, and which go through the identity provider?

How it differs from passwordless authentication

Passwordless authentication is the broad category of signing in without a password. It includes passkeys, but also smart cards, platform sign-in features, push approvals and one-time links or codes, some of which can still be phished. Passkeys are a specific, standards-based method within that category, built on public-key cryptography and tied to the genuine site. For managing and securing the laptops and phones that hold passkeys, see our unified endpoint management overview.

Frequently Asked Questions

Are passkeys more secure than passwords?
Generally, yes. There is no shared secret for a website to leak or for a user to type into a fake page, and each passkey works only with the site it was created for. Security still depends on protecting the device and, for synced passkeys, the account that syncs them.
What is the difference between synced and device-bound passkeys?
Synced passkeys are backed up and shared across a user's devices through a credential manager, which makes them convenient and recoverable. Device-bound passkeys stay on one device, such as a hardware security key, and are designed not to be copied or exported. Organizations often require device-bound passkeys for administrators and allow synced ones for other users.
Do passkeys count as multi-factor authentication?
They can. A passkey can satisfy MFA when the service requires user verification, a fingerprint, face scan or PIN checked on the device, and confirms in the sign-in response that it was performed: that combines the device you have with something you know or are. If user verification is not required and checked, the sign-in may prove only possession of the device. Separately, whether a given insurer, auditor or regulation accepts passkeys as MFA depends on its own wording, so check it.
Are passkeys the same as FIDO2?
Not exactly. FIDO2 is the set of standards, WebAuthn and CTAP, that passkeys are built on. Passkey is the user-friendly name for credentials created under those standards, including both synced and device-bound ones.
What happens if a user loses their phone?
With synced passkeys, the user can sign in from another device on the same sync account. With device-bound passkeys, they need a backup key or another registered method, or must go through account recovery. Recovery should require strong identity checks.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.