TL;DR: FIDO2 strengthens user authentication with phishing-resistant credentials, but it does not cover machines, email signing, or document signing, according to Axiad’s analysis. The practical issue is not password replacement alone, but closing the authentication gaps that remain across human, machine, and interaction identity.
At a glance
What this is: This is an Axiad analysis of why FIDO2 alone does not cover every authentication use case and why PKI fills the remaining machine and interaction gaps.
Why it matters: IAM teams need to treat passwordless as one layer in a broader identity architecture because machines, email, and documents still require separate authentication and trust controls.
By the numbers:
- 87% of large organizations already have adopted MFA solutions.
- 75% of IT leaders plan to increase MFA spending in the next year.
Context
Passwordless authentication solves one problem, but not the entire identity problem. In this article, the primary gap is not user sign-in alone. It is the mismatch between a human-focused authentication model and environments that also depend on devices, applications, email, and digitally signed documents.
Axiad frames PKI and FIDO2 as complementary controls rather than substitutes. FIDO2 addresses user authentication well, while PKI extends trust to machine identities and signed interactions that passwordless journeys do not cover.
For IAM leaders, the practical question is whether the authentication architecture covers all identity subjects that actually operate in the environment. If the programme stops at user login, it leaves material gaps in machine trust and interaction integrity.
Key questions
Q: How should security teams combine FIDO2 and PKI without creating overlap?
A: Use FIDO2 for strong human authentication and PKI for machine identities, email signing, encryption, and document trust. The two controls solve different problems. Teams should align each with the identity type and workflow they actually govern, then manage certificates and authenticators through separate but coordinated lifecycle processes.
Q: Why do passwordless programmes still leave identity risk behind?
A: Because passwordless adoption usually covers the easiest systems first, while legacy apps, shadow IT, and recovery workflows still rely on human-created credentials. Those remaining systems preserve inconsistent policy, weaker visibility, and higher social engineering exposure. The risk remains until the tail is governed, not just modernized.
Q: When should organisations add PKI to a passwordless strategy?
A: Add PKI when the environment depends on machine identity, signed communications, or document authenticity in addition to human login. If those use cases exist, passwordless alone is incomplete. The decision point is whether the business needs cryptographic trust for objects and interactions that outlive a user session.
Q: What should IAM teams review after rolling out FIDO2?
A: They should review whether the new login model has left certificate use cases, device authentication, or signed email outside governance. A successful rollout can still leave blind spots if machine and content trust were never mapped. The review should focus on identity subjects, lifecycle ownership, and assurance coverage.
Technical breakdown
Why FIDO2 stops at user authentication
FIDO2 is a phishing-resistant authentication standard built around device-bound credentials and public-key cryptography. It is designed to let a person prove possession of a private key on a registered authenticator, often without a password. That makes it strong for interactive user logins, including web and cloud access. But it is scoped to the user authentication problem, not to the broader trust model for machines, signed communications, or object-level assurance. In practice, that means it reduces reliance on passwords without replacing every other identity proofing or signing mechanism in the environment.
Practical implication: treat FIDO2 as a strong human authentication control, not as a universal trust layer for all identities and interactions.
How PKI extends trust to machines, email, and documents
Public key infrastructure issues certificates that bind a cryptographic identity to a device, application, or signing use case through a trusted certificate authority. That makes it suitable for authenticating machines, signing email, and signing documents. Unlike FIDO2, which focuses on interactive authentication, PKI can establish trust in non-human and transactional contexts where the subject is not a person at a keyboard. The article’s key point is architectural: these are different trust problems, so a single credential type does not close all of them.
Practical implication: map each identity subject to the correct assurance mechanism instead of forcing one login method to cover every workflow.
Why credential lifecycle management becomes the hidden constraint
PKI is often harder to operate because certificates require policy, issuance, renewal, and lifecycle governance. That operational burden is why many teams stop at user authentication and leave machine and interaction identity coverage incomplete. The article also notes that cloud delivery can reduce this complexity by centralising management, but the underlying issue remains lifecycle discipline: identities that sign, encrypt, or authenticate must be issued, tracked, and revoked with the same rigor as human access. Without that, the control exists in theory but not reliably in practice.
Practical implication: inventory certificate-bearing identities and govern their lifecycle before expanding passwordless beyond users.
Threat narrative
Attacker objective: The attacker seeks to impersonate users or trusted systems and exploit identity gaps that are not covered by passwordless authentication alone.
- Entry begins with password-based or weak user authentication that can be phished or reused across remote work environments.
- Credential abuse follows when attackers exploit the absence of machine trust, email signing, or document signing controls to impersonate legitimate actors or systems.
- Impact occurs when unverified devices, unsigned messages, or unauthenticated documents are used to move trust decisions outside the protection boundary.
Breaches seen in the wild
- Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Authentication completeness, not password replacement, is the real governance problem: This article shows that organisations often mistake passwordless login for full identity coverage. FIDO2 can harden user sign-in, but it does not resolve machine identity, signed communications, or document trust. The implication is that IAM programmes must define what each identity subject is actually proving, not just whether a password has been removed.
PKI fills the trust gap that human authentication standards cannot close: Certificates are not a substitute for FIDO2, but they govern different identity subjects and transactions. Machines, email, and documents need cryptographic proof that survives outside a user session, which is why PKI remains structurally relevant. Practitioners should read this as a reminder that identity architecture is multi-protocol by necessity.
Machine and interaction identities are the blind spots in many passwordless programmes: The article’s strongest operational lesson is that human login modernisation can hide unresolved trust debt elsewhere. When devices, applications, and signed communications remain outside the control model, the identity perimeter is incomplete. That means governance should be organised around identity subject types, not around a single authentication brand.
Ephemeral human access and persistent non-human trust are different control problems: FIDO2 is optimised for interactive access, while PKI supports longer-lived trust relationships for devices and signed content. Those lifecycles differ, so recertification, issuance, and revocation cannot be handled with one uniform process. Security teams should separate user authentication policy from machine and document trust governance.
Dynamic duo is a useful phrase, but the discipline is really control separation: The article’s pairing works because each mechanism covers a different assurance layer. The discipline for practitioners is to avoid collapsing them into one passwordless programme. Treat FIDO2 as one control in a broader identity architecture and PKI as the mechanism that closes the residual non-human and transaction gaps.
From our research library:
- 48% of organisations cite cloud-based services as a driver for PKI deployment, according to the 2023 State of Machine Identity Management report.
What this signals
Authentication architecture should be organised by identity subject, not by a single preferred method: Human sign-in, device trust, email integrity, and document signing are different assurance problems. When organisations collapse them into one passwordless initiative, they usually end up with a partial control plane that is strong at login and weak everywhere else.
PKI remains relevant because cryptographic trust for machines and transactions does not disappear when user passwords do. The practical programme question is whether the organisation can issue, track, and revoke certificates with the same discipline it applies to workforce identity.
The most durable model is a layered one: FIDO2 for interactive users, PKI for machine and interaction identity, and lifecycle governance that keeps both under control.
For practitioners
- Define identity subjects separately Map where your programme authenticates humans, devices, services, email, and documents, then assign the assurance method each subject actually needs.
- Use FIDO2 for interactive user access Apply phishing-resistant authentication to workforce sign-in where the primary requirement is strong human login, not machine or content assurance.
- Use PKI for machine and content trust Issue certificates for devices, applications, email signing, and document signing so non-human and transactional identities are cryptographically verifiable.
- Separate lifecycle governance by identity type Track issuance, renewal, and revocation for certificates and keys as their own lifecycle controls instead of folding them into user authentication policy.
- Review authentication coverage gaps Look for workflows that still depend on unverified devices, unsigned email, or manually signed documents after passwordless rollout.
Key takeaways
- FIDO2 strengthens user authentication, but it does not by itself secure every identity subject or trust workflow in the enterprise.
- PKI remains the control that extends assurance to devices, email, and documents, which passwordless login alone does not cover.
- IAM teams should separate human authentication from machine and content trust so that passwordless adoption does not create new blind spots.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article is about closing authentication gaps across human and non-human use cases. |
| NHI-05 — Overprivileged NHI | Machine and service credentials need scoped trust, not broad access implied by user sign-in controls. | |
| Recommendation — Use NHI-04 to review where authentication still depends on weak or incomplete assurance paths. Limit non-human credential scope so machine trust does not inherit unnecessary privileges. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential lifecycle and management are central to both FIDO2 and PKI governance. |
| Recommendation — Apply IA-5 to govern issuance, renewal, rotation, and revocation of authenticators and certificates. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is ultimately about assigning the right authentication and trust model to each identity subject. |
| Recommendation — Align authentication and trust controls to the identity subject and intended access path. | ||
| NIST Zero Trust (SP 800-207) | Identity and Access Control — Identity and Access Control | The article extends trust boundaries beyond user login into devices and signed interactions. |
| Recommendation — Treat identity assurance as a continuous trust boundary spanning users, devices, and transactions. | ||
Key terms
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
- Public Key Infrastructure: Public Key Infrastructure is the trust system that issues, manages, and revokes digital certificates used to prove identity. In practice it binds keys to entities and policies, making authentication, encryption, and non-repudiation possible across users, devices, and services.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Digital Signing Service: A Digital Signing Service is a cloud-based platform that provides document signing capability without requiring organisations to manage physical signing hardware. It is typically used to scale signing across teams and workflows, while still relying on certificates and cryptographic controls to preserve identity, integrity, and trust in the signed document.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org