ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Passkeys are going mainstream. What comes next?

The argument for replacing passwords with passkeys is becoming increasingly difficult to ignore. The more interesting question is what happens once organisations actually deploy them.

 

New figures from the FIDO Alliance estimate that five billion passkeys are now in use worldwide. Its State of Passkeys 2026 research found that 75% of consumers have enabled one on at least one account, while 68% of organisations have deployed, are piloting or are rolling out passkeys for employee authentication.

 

The growth reflects a significant security advantage. Unlike passwords, passkeys use public-key cryptography and are tied to the legitimate website or application, making them resistant to conventional credential phishing. There is also no reusable password stored by the service for an attacker to steal.

 

But wider adoption is exposing another issue: replacing the password at login does not necessarily remove weaker authentication elsewhere.

Microsoft warned on World Passkey Day that organisations need to remove phishable credentials and strengthen recovery processes alongside passkey deployment. An account protected by a passkey can still be exposed if an attacker is able to bypass it through a weaker fallback or account recovery mechanism.

 

Managing the credentials themselves also becomes important at scale. Passkeys can be device-bound or synchronised between devices, creating different considerations around portability, device loss and control. Microsoft’s current guidance recommends considering those differences when deciding which form of passkey is appropriate for different users.

 

There is also the question of lifecycle management. Microsoft notes that passkeys in Entra ID do not currently expire automatically, meaning organisations need processes for monitoring their creation and use, as well as removing credentials that are no longer required.

 

None of this weakens the case for passkeys. They remove one of the most exploitable elements of authentication and make traditional credential phishing considerably harder. The latest adoption figures suggest they are moving rapidly from an emerging technology towards a normal part of identity infrastructure.

 

The next stage is therefore less about convincing organisations to adopt passkeys and more about ensuring the systems surrounding them are equally difficult to bypass. A phishing-resistant login offers considerably less protection if account recovery, fallback authentication or credential management provides an easier route in.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543