Join our Newsletter — 33% off our NHI Course

Why do passkeys still need identity governance if they are phishing-resistant?

Because phishing resistance solves one failure mode, not the whole identity problem. Teams still need to govern enrolment, device binding, fallback access, account recovery, and assurance changes over time. Without those controls, passkeys can create a stronger authenticator that is still attached through a weak process.

Why This Matters for Security Teams

Phishing-resistant authentication reduces one class of credential theft, but it does not remove the governance problems around who can enroll, what device is trusted, how recovery works, or when assurance should change. That is why passkeys still sit inside identity governance, not outside it. NIST’s NIST Cybersecurity Framework 2.0 treats identity as an ongoing control surface, and NHIMG’s Ultimate Guide to NHIs makes the same lifecycle point for non-human identities: stronger credentials are still vulnerable if their provisioning and recovery paths are weak.

The practical risk is that passkeys can create a false sense of completion. If registration is loosely approved, if recovery can be abused by help desk workflows, or if a lost device can be re-bound without revalidation, the organisation has merely moved the attack from phishing to governance gaps. That is especially important where passkeys are adopted alongside broader identity modernization, because access reviews and assurance changes often lag behind the rollout. In practice, many security teams encounter passkey abuse only after account recovery or device enrolment has already been exploited, rather than through intentional governance review.

How It Works in Practice

Passkey governance should be treated as a full identity lifecycle, not a one-time enrollment decision. The authenticator itself is phishing-resistant, but the account it protects still needs controls for proofing, binding, recovery, revocation, and step-up verification. Current guidance suggests aligning passkey policy with identity assurance, device trust, and privileged access review so that a stronger authenticator does not sit on top of a weak account recovery process.

In practice, teams usually need to govern five points:

  • Enrollment: require verified identity proofing before a passkey is attached to an account.
  • Device binding: approve only managed or attested devices where risk warrants it.
  • Recovery: separate help desk recovery from ordinary reset workflows and log every exception.
  • Assurance changes: raise or lower assurance based on role, sensitivity, or device risk.
  • Revocation: remove passkeys quickly when a device is lost, reassigned, or compromised.

This is where identity governance, PAM, and lifecycle controls intersect. A phishing-resistant authenticator does not prevent social engineering against recovery teams, insider misuse of enrollment privileges, or weak fallback channels such as email or SMS. That is why Top 10 NHI Issues repeatedly emphasizes lifecycle oversight: the security outcome depends on how identities are issued, changed, and retired, not only on the credential type. NIST SP 800-53 Rev. 5 also reinforces this through identity, authentication, and access control requirements that extend beyond initial login. These controls tend to break down in large enterprise environments with shared help desk processes and inconsistent device posture signals because recovery becomes the easiest path around strong authentication.

Common Variations and Edge Cases

Tighter passkey governance often increases user friction and support load, requiring organisations to balance phishing resistance against recovery speed and workforce mobility. That tradeoff is real, especially for executives, contractors, and distributed teams that move between managed and unmanaged devices. Best practice is evolving, and there is no universal standard for every recovery design yet.

Some environments can accept simpler controls, but only when the account has low impact and the fallback path is tightly scoped. High-risk roles need stronger review for enrollment changes, multiple approvers for recovery, and explicit rules for when a passkey can be added from a new device. For organisations with broader NHI programs, the lesson carries over: 52 NHI Breaches Analysis shows that weak lifecycle control, not weak credentials alone, is what repeatedly drives compromise.

Passkeys also do not eliminate governance needs in hybrid identity estates. If the same user can authenticate with passkey, password, legacy MFA, or recovery email, policy drift can quietly reduce the actual assurance level. Security teams should define which authentication methods are acceptable for which risk tier, then review them on the same cadence as privileged access and joiner-mover-leaver controls. In environments with delegated admin, unmanaged devices, or aggressive self-service recovery, passkey governance becomes a control gap unless policy is enforced consistently at every edge.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC-1 Passkeys still require governed access assignment and verification.
NIST SP 800-53 Rev 5 IA-2 Strong authentication controls must be paired with lifecycle governance.
OWASP Non-Human Identity Top 10 NHI-01 Weak lifecycle handling can undermine otherwise strong authenticators.
NIST AI RMF Identity assurance for autonomous or adaptive systems must be continuously managed.
CSA MAESTRO Agentic systems still need lifecycle and recovery governance for identities.

Apply continuous governance to authentication methods, recovery, and assurance changes across the identity lifecycle.