By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: YubicoPublished October 9, 2025

TL;DR: Organisations face evolving AI-driven phishing pressure as passwordless authentication becomes more available, according to Yubico’s 2025 Global State of Authentication survey, which draws on responses from 18,000 employed adults and pairs that data with updates on device-bound passkeys, PIN enhancements, and expanded delivery options. The bigger issue is not whether passwordless authentication is available, but whether identity programmes can make phishing-resistant access usable, deployable, and governable at scale.


At a glance

What this is: This is a product-and-research update on passkeys and phishing-resistant authentication, with survey findings and event sessions focused on enterprise adoption.

Why it matters: It matters because IAM teams need to translate phishing resistance into workable rollout, lifecycle, and assurance decisions across human identity programmes.

By the numbers:

👉 Read Yubico's authentication survey and passkey update for 2025


Context

Passwordless authentication matters when phishing remains the dominant way human identities are compromised. The practical question for IAM teams is not whether passkeys exist, but whether they can be deployed consistently, supported across user populations, and governed alongside broader access and assurance controls.

This update combines survey findings, product changes, and event sessions. That makes it useful as a signal of where authentication programmes are heading, especially for organisations trying to reduce password dependence without creating usability or rollout failures.


Key questions

Q: How should organisations roll out passkeys without disrupting existing login flows?

A: Start by adding passkeys alongside current authentication methods, then use adoption and recovery data to decide when to reduce password dependence. The rollout should be phased by user group and application risk, with clear fallback and support paths so users are not forced into brittle recovery journeys.

Q: Why do passkeys improve security but not eliminate identity risk?

A: Passkeys remove the shared secret that attackers usually steal, guess, or phish, which is a major improvement. But identity risk shifts into device trust, account recovery, enrolment, and fallback. If those controls are weak, an attacker can still gain access without ever defeating the passkey cryptography itself.

Q: What should IAM teams measure when moving to passwordless authentication?

A: Measure how much access still depends on replayable credentials, how many high-risk flows remain on OTPs, and whether the enrolled devices can be revoked and recovered cleanly. Those indicators show whether passwordless is reducing attack surface or simply adding another layer on top of old trust assumptions.

Q: How do security teams keep phishing resistance consistent across global locations?

A: Standardise enrollment, replacement, and support rules across regions, then validate whether local delivery and recovery processes match policy. Global consistency matters because authentication assurance breaks down when issuance and support vary by geography or business unit.


Technical breakdown

Device-bound passkeys and phishing resistance

Device-bound passkeys bind the authenticator to a device and rely on public key cryptography, which removes reusable secrets from the login flow. That matters because phishing works best when users can be tricked into revealing something that can be replayed elsewhere. Passkeys shift the threat from credential theft to device and registration assurance, which changes the control stack around enrollment, recovery, and attestation.

Practical implication: treat passkeys as an authentication architecture change, not a simple replacement for passwords.

PIN and usability controls in passkey rollout

A passkey programme fails if users cannot register, recover, and use the authenticator reliably. PIN protections and usability improvements are part of that equation because they affect both assurance and adoption. In practice, the strongest authentication control can still produce weak security outcomes if operational friction pushes users toward unsafe workarounds or shadow recovery paths.

Practical implication: model usability, recovery, and support flows as part of the identity control design.

Enterprise delivery and lifecycle coverage for security keys

Phishing-resistant authentication at scale depends on more than the token itself. Delivery, replacement, inventory, and lifecycle governance determine whether device-bound credentials stay available to the right users at the right time. Once organisations span many geographies, the operational risk shifts to provisioning delays, regional coverage, and consistency of issuance and decommissioning.

Practical implication: align authentication rollout with lifecycle operations, not just procurement and enrollment.


NHI Mgmt Group analysis

Phishing-resistant authentication only works when it is operationally reachable. The strongest authentication model still fails if users cannot get a usable authenticator when and where they need one. That is why delivery coverage, enrollment support, and recovery design matter as much as cryptographic assurance. For IAM teams, the real control question is whether the authentication method can survive enterprise scale without turning into a bottleneck.

Passkeys change the risk model, but they do not remove identity governance. Moving away from passwords reduces replayable secret exposure, yet organisations still have to govern enrollment, device trust, recovery, and exception handling. That keeps authentication in the IAM and lifecycle domain, not in a narrow security-tools domain. The programme challenge is to make phishing resistance compatible with broad enterprise adoption, not just high-assurance pilots.

AI-driven phishing raises the value of removing shared human failure points. As phishing content becomes more convincing and more scalable, password-based controls become harder to defend through training alone. Passkeys are therefore best understood as a structural reduction in attack surface for human identity, especially when paired with MFA and lifecycle controls that limit bypass paths. The question is no longer whether phishing resistance is desirable, but whether it is being implemented at pace.

Enterprise delivery scale is now part of authentication assurance. Coverage across 199 locations is not just a logistics detail. It illustrates that authentication programmes increasingly depend on distribution, replacement, and operational continuity. Security leaders should read that as a signal that identity resilience now includes the ability to issue and maintain trustworthy authenticators across a global workforce.

From our research:

  • The ratio of non-human to human identities now exceeds 100:1 in enterprise environments, according to Ultimate Guide to NHIs , Why NHI Security Matters Now.
  • From our research: 85% of organisations lack full visibility into their NHI credential estate, according to Ultimate Guide to NHIs , Key Challenges and Risks.
  • Forward-looking analysis: The same lifecycle discipline that governs workforce authentication should extend to machine and agent identities, especially where access is issued, rotated, and revoked at scale.

What this signals

As passwordless adoption grows, IAM programmes will be judged less by stated intent and more by whether they can eliminate brittle recovery and exception paths. That shift matters because phishing resistance only becomes durable when it is embedded into enrollment, support, and lifecycle operations, not treated as a point solution. The broader identity programme has to absorb that change or the controls will fragment.

Authentication reachability: If a user cannot obtain or replace a trustworthy authenticator quickly, the strongest control in the design collapses into an exception. That is the part practitioners should watch as passkey programmes scale.

This also widens the governance lens beyond the human login flow. Organisations that already struggle with secrets, tokens, and workload credentials should recognise the same pattern in identity operations: usable trust depends on controlled issuance, inventory, and revocation across every identity type.


For practitioners

  • Assess passkey readiness by user population and recovery path Map which employee groups can move to device-bound passkeys now, which need transitional support, and where recovery would fall back to weaker controls.
  • Define assurance requirements before broad rollout Decide what enrollment proof, device binding, and fallback conditions are acceptable before passkeys are made the default login method.
  • Track authenticator lifecycle operationally Inventory issuance, replacement, decommissioning, and support turnaround so authentication availability does not degrade as the programme scales.
  • Use phishing resistance as a programme metric Measure whether the organisation is reducing password dependence and shrinking recovery exceptions, not just adding another login option.

Key takeaways

  • Passkeys reduce replayable credential risk, but they only work when enrollment, recovery, and support are governed as part of the identity programme.
  • The survey scale suggests authentication decisions now affect global rollout planning, not just login experience tuning.
  • Security teams should treat phishing resistance as an operational lifecycle issue, because adoption without lifecycle control creates new exceptions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63BPasskeys and phishing-resistant authentication map directly to authenticator guidance.
NIST CSF 2.0PR.AA-1Authentication assurance and access control are central to this topic.
NIST Zero Trust (SP 800-207)Zero trust relies on strong identity verification and continuous assurance.

Use SP 800-63B to shape phishing-resistant enrollment, binding, and recovery requirements.


Key terms

  • Passkey: A passkey is a passwordless credential based on public key cryptography. A private key stays on the user’s device, while a public key is stored by the service. During login, the device signs a challenge after local unlock, which reduces phishing and eliminates shared secret reuse.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Authenticator Lifecycle Management: Authenticator lifecycle management is the governance of a credential from issuance to renewal, replacement, and retirement. For human identity programmes, it ensures that keys, smart cards, and certificates stay tied to the right user and are removed when the user, role, or device is no longer trusted.

What's in the full article

Yubico's full update covers the operational detail this post intentionally leaves for the source:

  • Survey breakdowns from 18,000 employed adults that can support internal awareness or executive messaging.
  • Specific passkey usability and PIN enhancements that shape deployment planning.
  • Global delivery and subscription coverage details for teams managing distributed authenticator rollout.
  • Session-by-session event listings for practitioners who want the implementation discussion directly.

👉 Yubico's full update covers the survey findings, passkey enhancements, and event sessions in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org