What Is Passwordless Authentication?

Also called: Passwordless login, Passwordless sign-in

Related problems: Staff reusing weak passwords across work apps; Help desk buried in password reset requests; Phished passwords leading to account takeovers; Users frustrated by passwords plus MFA codes on every sign-in

Passwordless authentication is any way of signing in that doesn’t ask the user to type a password. Instead, the user proves who they are with something they have, such as a phone, laptop, security key or smart card, usually unlocked with a fingerprint, face scan or PIN, or with a one-time link or code sent to them. The goal is to remove the password as the thing attackers steal and users forget, though how much security improves depends heavily on which method you choose.

At a glance

  • An umbrella term covering several methods: passkeys, hardware security keys, certificate-based smart cards, device sign-in with biometrics, and emailed or texted links and codes.
  • Methods based on public-key cryptography, such as passkeys and smart cards, resist phishing far better than passwords.
  • Link- and code-based methods remove the password but can still be phished or intercepted.
  • Passwordless is not automatically multi-factor: a passkey unlocked by biometric or PIN is generally treated as multi-factor; an email link is not.
  • Account recovery and legacy apps are the usual places where passwords linger.

What problem it solves

Passwords cause two persistent problems. Security-wise, they are guessed, reused across sites, leaked in breaches and typed into fake login pages during phishing attacks. Operationally, they generate help desk tickets, lockouts and frustrated users, especially when combined with MFA prompts.

Passwordless authentication tackles both. With strong methods, there is no shared secret for an attacker to steal from a server or trick a user into revealing, and sign-in is often quicker: a fingerprint or PIN on a device the user already holds. Fewer passwords also means fewer resets.

How it works

Public-key methods. Passkeys, FIDO2 security keys and smart cards all rely on a key pair. The private key stays on the user’s device or security key, or in an encrypted credential manager; the service holds only the public key or a certificate containing it. At sign-in, the service sends a challenge, the device signs it after the user unlocks it with a biometric or PIN, and the service checks the signature. Passkeys and security keys bind each credential to the website or app it was created for, which is why they resist phishing. Certificate-based smart cards use public key infrastructure (PKI) and are common in government and regulated settings.

Device sign-in. Operating systems let users sign in to a managed computer with a biometric or PIN backed by a key in the device’s secure hardware, and that sign-in can carry through to cloud apps via the identity provider.

Links and one-time codes. The service emails or texts a link or code that the user enters or clicks. This removes the password but relies on the security of the inbox or phone number, and codes can be relayed by a fake login page.

Push approval. Some authenticator apps sign the user in with a phone prompt instead of a password. Number matching and context help, but push methods can still be abused through repeated prompts or relayed sessions.

Most organizations enable these methods through their identity provider (IdP), which sets which methods are allowed for which users and apps.

When it matters for buyers

  • When strengthening MFA. Moving staff to passkeys or security keys is a common path to phishing-resistant MFA.
  • When choosing an identity provider. Supported methods, policy controls and recovery options differ between platforms and license tiers.
  • When managing devices. Device-based sign-in usually depends on managed, reasonably current laptops and phones.
  • When reducing help desk load. Password resets are a common ticket category; passwordless can cut them, provided recovery is well designed.
  • When some apps can’t support it. Older applications may still need passwords, sometimes kept in a password manager during the transition.

Questions to ask vendors

  • Which passwordless methods do you support, and which of them do you consider phishing-resistant?
  • Can we require specific methods for administrators or sensitive applications?
  • How are credentials registered, and how do you prevent an attacker from registering their own?
  • What does account recovery look like when a user loses every registered device?
  • Which of our applications can use passwordless sign-in through you, and which still need passwords?
  • What device or operating system requirements apply, and does this feature cost extra?

How it differs from multi-factor authentication (MFA)

MFA is about how many independent factors a sign-in uses; passwordless is about whether one of them is a password. The two overlap: a passkey or smart card unlocked by a PIN or biometric is both passwordless and multi-factor, and is generally considered phishing-resistant. A password plus a text-message code is MFA but not passwordless, and an emailed sign-in link is passwordless but single-factor. When evaluating options, ask both questions, and also whether the method resists phishing. For managing the devices that hold these credentials, see our unified endpoint management overview.

Frequently Asked Questions

Is passwordless authentication more secure than passwords?
It depends on the method. Passkeys, security keys and certificate-based smart cards are much harder to phish than passwords. Emailed links and one-time codes remove the password but can still be phished or intercepted, so they offer a smaller improvement.
Is passwordless the same as MFA?
Not necessarily. A passkey unlocked with a fingerprint or PIN combines something you have with something you are or know, so it is usually treated as multi-factor. An emailed sign-in link is passwordless but is a single factor.
Are passkeys the same as passwordless authentication?
Passkeys are one passwordless method, based on FIDO standards. Passwordless authentication is the broader category, which also includes security keys, smart cards, platform sign-in with biometrics, and one-time links or codes.
Can we go fully passwordless?
Many organizations can get most users to sign in without passwords day to day, but legacy applications, shared devices and account recovery often still involve a password or another fallback. Plan for those cases rather than assuming they disappear.
What happens if a user loses their device?
They use a backup method, such as a second registered key or synced passkey, or go through account recovery. Recovery is a common weak point, so it should require strong identity checks rather than a simple help desk call.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.