Join our Newsletter — 33% off our NHI Course

Enterprise Passkey

An enterprise passkey is a phishing resistant FIDO2 credential designed for organisational use rather than consumer convenience. It is typically device bound, centrally governed, and intended to support both workstation and application authentication while preserving enterprise control over lifecycle, recovery, and assurance.

Expanded Definition

An enterprise passkey is a FIDO2-based authentication credential issued and governed for organisational use, not personal convenience. It is designed to reduce phishing risk while giving security teams control over enrolment, device binding, recovery, and revocation. In practice, the term is used to distinguish centrally managed passkeys from consumer passkeys that live outside enterprise policy. That distinction matters because enterprise use cases often require auditability, support workflows, and identity assurance that align with NIST Cybersecurity Framework 2.0 and broader access governance expectations.

Definitions vary across vendors on whether a synced passkey can qualify as enterprise grade, or whether true enterprise passkeys must be hardware bound and tightly administered. NHIMG treats the operational question as governance first: who can issue it, where it can be used, how it is recovered, and what happens when an employee leaves or a device is lost. The most common misapplication is treating a consumer-managed passkey as an enterprise control, which occurs when organisations allow unmanaged enrolment but assume they still have lifecycle and policy enforcement.

Examples and Use Cases

Implementing enterprise passkeys rigorously often introduces enrolment and recovery overhead, requiring organisations to weigh phishing resistance against user support complexity.

  • Workforce login to laptops and SaaS applications with centrally issued passkeys, so IT can revoke access when a role changes or a device is lost.
  • Privileged admin access where a passkey replaces passwords for console authentication, reducing the impact of credential phishing and reuse.
  • Hybrid environments where passkeys are paired with conditional access and device posture checks, then mapped to zero trust policy decisions.
  • Recovery workflows that require help desk validation and step-up verification before re-enrolling a replacement credential.
  • Policy design informed by NHIMG research on identity sprawl and compromise risk, especially where Ultimate Guide to NHIs — Why NHI Security Matters Now shows how access failures often begin with weak lifecycle control.

For implementation detail, the FIDO Alliance guidance on passkeys and the NIST Cybersecurity Framework 2.0 help teams position the credential within broader authentication and recovery design.

Why It Matters in NHI Security

Enterprise passkeys matter because authentication control is only as strong as the lifecycle around it. If issuance, recovery, and revocation are weak, the organisation may remove passwords but still inherit unmanaged access pathways. That creates a governance gap similar to NHI sprawl: credentials can persist beyond their intended scope, especially when onboarding and offboarding are inconsistent. NHIMG research shows that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, and the same lifecycle discipline is what keeps enterprise credentials from becoming persistent attack paths.

This is why enterprise passkeys should be understood as part of broader identity control rather than as a standalone login upgrade. Their value increases when paired with least privilege, device trust, and rapid recovery procedures. Ultimate Guide to NHIs — Why NHI Security Matters Now highlights how weak identity governance amplifies exposure across the enterprise, and that lesson applies directly to passkey programs. Organisations typically encounter the cost of weak passkey governance only after a lost device, a failed recovery, or a user offboarding event, at which point enterprise passkey control becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Agentic AI Top 10 Phishing-resistant auth and credential lifecycle are core identity protections in agentic environments.
OWASP Non-Human Identity Top 10 NHI-01 Enterprise passkeys mirror NHI governance needs for issuance, scope, and lifecycle control.
NIST SP 800-63 AAL2 Passkeys are a strong authenticator pattern aligned to digital identity assurance guidance.
NIST Zero Trust (SP 800-207) AC-6 Zero trust depends on verified authentication and least privilege after login.
NIST CSF 2.0 PR.AA-01 Identity proofing and strong authentication support secure access outcomes.

Use phishing-resistant credentials with strict recovery controls for any agent or user path that can invoke tools.