By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: DescopePublished May 9, 2025

TL;DR: The 2025 FIDO report shows 75% of global consumers now know about passkeys, 48% of the top 100 websites already support them, and nearly half of consumers have abandoned purchases after forgetting passwords, according to Descope. Passwordless adoption is no longer a UX experiment; it is becoming a customer IAM control and conversion issue at the same time.


At a glance

What this is: This is an analysis of the 2025 FIDO report showing that passkeys are moving from novelty to mainstream consumer authentication.

Why it matters: It matters because customer IAM teams now have to treat passwordless authentication as both a security control and a revenue-protection decision, not just a login preference.

By the numbers:

👉 Read Descope's analysis of the 2025 FIDO passkey report and passwordless adoption


Context

Passwordless authentication is now a practical customer IAM issue, not a future-state idea. The article argues that passkeys reduce friction, improve security, and help recover revenue lost to password resets and abandoned sessions, while consumer awareness and website adoption both continue to climb.

For identity teams, the question is no longer whether passkeys exist, but where they belong in the authentication journey and how to support fallback, device compatibility, and phased rollout. That makes this a governance and design decision for human identity programmes, especially where account takeover, conversion loss, and support load intersect.

The starting position is typical for consumer-facing organisations that still depend on passwords as the default authentication path.


Key questions

Q: How should organisations roll out passkeys without breaking customer login flows?

A: Start with journeys that already tolerate fallback, such as signup, account recovery, and step-up authentication. Keep passwords or other alternatives available during transition, but define when they apply and who owns exceptions. That lets teams prove value through measurable improvements in sign-in success, user experience, and support load before expanding passkeys more broadly.

Q: When do passkeys reduce risk enough to replace passwords as the default method?

A: They make the most sense when phishing resistance, reduced account takeover exposure, and lower friction all matter at once. If the user population is device-capable and the recovery design is mature, passkeys can become the default. If fallback and support are weak, they may shift risk rather than reduce it.

Q: What do security teams get wrong about passwordless authentication?

A: The most common mistake is treating passwordless as a user-experience upgrade instead of an identity control change. Teams often focus on the login screen and ignore recovery, lifecycle governance, and fallback authentication, which is where many of the real risks emerge.

Q: How do you know if passkeys are actually improving customer IAM?

A: Look for higher login completion, fewer password resets, reduced abandonment, and lower takeover signals in the same reporting cycle. If passkey adoption rises but recovery friction or support volume also rises, the programme is not yet stable. Success means both security and customer experience improve together.


Technical breakdown

Why passkeys reduce both takeover risk and login friction

Passkeys use public-key cryptography, so the server stores a public key while the private key remains on the user’s device. That means there is no reusable password to steal, replay, or phish. Authentication is tied to possession of the device and local user verification such as biometrics or PIN. In practice, this removes the credential stuffing path that drives many account takeover events while also shortening the sign-in workflow.

Practical implication: treat passkeys as a primary authentication path for customer accounts where phishing resistance and lower abandonment both matter.

How passkeys fit into customer IAM and MFA design

Passkeys can act as a single-action strong authentication method because the cryptographic factor and device-bound factor are combined in one flow. That does not eliminate the need for step-up controls in higher-risk cases, but it does change the baseline from password-first to possession-first. For customer IAM, this means policy decisions must account for device compatibility, fallback paths, and how assurance levels are maintained when passkeys are unavailable.

Practical implication: define when passkeys satisfy baseline authentication and when additional step-up checks are still required.

Why rollout strategy matters more than passkey support alone

Support for passkeys is not the same as operational adoption. Enterprises need to decide whether to A/B test authentication journeys, track conversion impact, and provide alternate methods for devices that do not support WebAuthn. The article highlights that this is as much a product and governance exercise as a technical one, because user experience, fraud prevention, and support burden all change together.

Practical implication: measure passkey success by adoption, completion rate, and reduced support demand, not by feature availability alone.


NHI Mgmt Group analysis

Passwordless authentication is now a customer IAM control, not just a convenience feature. The article shows that passkeys are being evaluated against abandonment, support cost, and account takeover exposure at the same time. That shifts the conversation from login preference to identity risk management, because the authentication method now affects both fraud surface and conversion loss. Practitioners should treat passwordless design as part of IAM architecture, not as a user-experience experiment.

Passkeys narrow the credential replay problem, but they do not eliminate authentication governance. A phishing-resistant method changes the attack economics, yet organisations still need fallback paths, device coverage, and recovery design. The hard part is no longer proving that passwords are weak; it is governing the exception paths that keep passwordless usable at scale. The implication is that customer IAM policies must define the boundary conditions for passkey use before rollout expands.

Conversion and identity security are converging in the same control plane. The report’s strongest signal is that authentication quality now influences business outcomes directly, not indirectly. When nearly half of consumers abandon purchases after password friction, IAM teams can no longer isolate security decisions from customer journey metrics. That makes passkey governance a shared responsibility across security, product, and fraud teams.

Passkey adoption will expose weak recovery and fallback design faster than password migrations did. The real maturity test is not initial sign-in success, but what happens when a device is lost, unsupported, or shared. Legacy recovery flows often reintroduce the same weaknesses passwordless is meant to remove. Practitioners should expect the next governance gap to appear in account recovery and step-up design, not in the primary passkey flow.

PWless migration is an IAM lifecycle issue, not a one-time auth change. Once passkeys enter production, enrolment, replacement, revocation, and device loss handling become ongoing identity lifecycle tasks. That makes the programme closer to human identity governance than to a simple feature toggle. Teams that do not model those lifecycle steps will end up with inconsistent assurance and confusing user recovery paths.

From our research:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
  • For a broader governance lens, see OWASP NHI Top 10 for the control patterns that become relevant when identity begins to act dynamically.

What this signals

Passwordless adoption will keep moving from UX conversation to identity governance programme work. As consumer expectations rise, teams need to plan for enrolment, replacement, recovery, and step-up decisions as part of the same authentication policy set, not as separate projects.

Credential replay debt: The deeper issue is not whether passwords will disappear overnight, but how long organisations will keep carrying two identity models at once. That transition period creates policy drift, inconsistent recovery paths, and mixed assurance levels that security teams will have to manage explicitly.

If you are aligning customer auth work with broader identity standards, anchor the rollout to NIST AI Risk Management Framework only where AI-driven risk scoring is involved, and otherwise keep the focus on customer identity lifecycle and authentication assurance.


For practitioners

  • Define where passkeys are primary Map customer journeys and classify which account types can move to passkeys first, then reserve passwords for only the cases that genuinely need them.
  • Design fallback and recovery paths first Document how users recover access when devices are lost, unsupported, or shared so passwordless deployment does not recreate weak recovery patterns.
  • Measure business and security outcomes together Track passkey adoption, login completion, support ticket reduction, and account takeover signals in the same rollout dashboard.
  • Use staged rollout for different user segments A/B test passkeys against existing methods, compare conversion and fraud outcomes, and expand only where the data shows clear benefit.

Key takeaways

  • Passkeys are becoming a mainstream customer IAM control because they reduce phishing risk and login friction at the same time.
  • The operational challenge is no longer proof of concept, but recovery design, fallback coverage, and measurable rollout governance.
  • Teams that connect authentication design to conversion, support, and takeover metrics will be better positioned than those treating passwordless as a cosmetic change.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BPasskeys are a digital authenticator and fit identity assurance guidance.
NIST CSF 2.0PR.AC-1Passwordless authentication sits inside identity and access control design.
NIST Zero Trust (SP 800-207)Zero trust depends on stronger authentication and continuous verification.
ISO/IEC 27001:2022A.5.17Access authentication rules and credential handling are directly relevant here.

Map passkey rollout to PR.AC-1 and validate authentication policy across customer journeys.


Key terms

  • Passkey: A passkey is a passwordless credential based on public key cryptography. A private key stays on the user’s device, while a public key is stored by the service. During login, the device signs a challenge after local unlock, which reduces phishing and eliminates shared secret reuse.
  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Customer Identity And Access Management: Customer Identity and Access Management is the discipline of governing how external users sign in, recover access, and move through digital services. It combines authentication, profile management, and lifecycle control so organisations can deliver secure, low-friction experiences at scale.
  • Account Takeover: Account takeover is unauthorized use of a legitimate account after an attacker obtains valid access through stolen credentials, tokens, or trusted integrations. The key security problem is that the resulting activity often looks normal to logs and controls, which makes containment and attribution harder than in a forced-entry breach.

What's in the full article

Descope's full post covers the operational detail this analysis intentionally leaves for the source:

  • Passkey integration options across web and mobile authentication journeys
  • Low-code and no-code flow design for staged passwordless rollout
  • A/B testing approaches for comparing passkeys with other authentication methods
  • Fallback authentication handling for devices that are not WebAuthn-compatible

👉 Descope's full post includes the adoption signals, rollout examples, and customer journey details behind the passwordless shift.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 16, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org