Passwordless authentication is any way of signing in that doesn’t ask the user to type a password. Instead, the user proves who they are with something they have, such as a phone, laptop, security key or smart card, usually unlocked with a fingerprint, face scan or PIN, or with a one-time link or code sent to them. The goal is to remove the password as the thing attackers steal and users forget, though how much security improves depends heavily on which method you choose.
At a glance
- An umbrella term covering several methods: passkeys, hardware security keys, certificate-based smart cards, device sign-in with biometrics, and emailed or texted links and codes.
- Methods based on public-key cryptography, such as passkeys and smart cards, resist phishing far better than passwords.
- Link- and code-based methods remove the password but can still be phished or intercepted.
- Passwordless is not automatically multi-factor: a passkey unlocked by biometric or PIN is generally treated as multi-factor; an email link is not.
- Account recovery and legacy apps are the usual places where passwords linger.
What problem it solves
Passwords cause two persistent problems. Security-wise, they are guessed, reused across sites, leaked in breaches and typed into fake login pages during phishing attacks. Operationally, they generate help desk tickets, lockouts and frustrated users, especially when combined with MFA prompts.
Passwordless authentication tackles both. With strong methods, there is no shared secret for an attacker to steal from a server or trick a user into revealing, and sign-in is often quicker: a fingerprint or PIN on a device the user already holds. Fewer passwords also means fewer resets.
How it works
Public-key methods. Passkeys, FIDO2 security keys and smart cards all rely on a key pair. The private key stays on the user’s device or security key, or in an encrypted credential manager; the service holds only the public key or a certificate containing it. At sign-in, the service sends a challenge, the device signs it after the user unlocks it with a biometric or PIN, and the service checks the signature. Passkeys and security keys bind each credential to the website or app it was created for, which is why they resist phishing. Certificate-based smart cards use public key infrastructure (PKI) and are common in government and regulated settings.
Device sign-in. Operating systems let users sign in to a managed computer with a biometric or PIN backed by a key in the device’s secure hardware, and that sign-in can carry through to cloud apps via the identity provider.
Links and one-time codes. The service emails or texts a link or code that the user enters or clicks. This removes the password but relies on the security of the inbox or phone number, and codes can be relayed by a fake login page.
Push approval. Some authenticator apps sign the user in with a phone prompt instead of a password. Number matching and context help, but push methods can still be abused through repeated prompts or relayed sessions.
Most organizations enable these methods through their identity provider (IdP), which sets which methods are allowed for which users and apps.
When it matters for buyers
- When strengthening MFA. Moving staff to passkeys or security keys is a common path to phishing-resistant MFA.
- When choosing an identity provider. Supported methods, policy controls and recovery options differ between platforms and license tiers.
- When managing devices. Device-based sign-in usually depends on managed, reasonably current laptops and phones.
- When reducing help desk load. Password resets are a common ticket category; passwordless can cut them, provided recovery is well designed.
- When some apps can’t support it. Older applications may still need passwords, sometimes kept in a password manager during the transition.
Questions to ask vendors
- Which passwordless methods do you support, and which of them do you consider phishing-resistant?
- Can we require specific methods for administrators or sensitive applications?
- How are credentials registered, and how do you prevent an attacker from registering their own?
- What does account recovery look like when a user loses every registered device?
- Which of our applications can use passwordless sign-in through you, and which still need passwords?
- What device or operating system requirements apply, and does this feature cost extra?
How it differs from multi-factor authentication (MFA)
MFA is about how many independent factors a sign-in uses; passwordless is about whether one of them is a password. The two overlap: a passkey or smart card unlocked by a PIN or biometric is both passwordless and multi-factor, and is generally considered phishing-resistant. A password plus a text-message code is MFA but not passwordless, and an emailed sign-in link is passwordless but single-factor. When evaluating options, ask both questions, and also whether the method resists phishing. For managing the devices that hold these credentials, see our unified endpoint management overview.
