TL;DR: Passwordless authentication is being positioned around passkeys, biometrics, device trust, and adaptive access, but RSA Security and KuppingerCole’s webinar notes that legacy systems, hybrid environments, secure recovery, and phishing resistance still determine whether deployments work at scale. The real test is whether identity programmes can replace passwords without creating new recovery and trust gaps.
Editorial analysis by NHI Mgmt Group, based on content published by RSA Security: “Adopting Passwordless Authentication for Modern Enterprises”.
Key questions
Q: How should security teams implement passwordless authentication without creating new recovery risk?
A: Security teams should remove passwords from both primary login and recovery paths, then require stronger proofing for reset workflows than for normal sign-in.
Q: Why does device trust matter for passwordless access?
A: Passwordless access is safer when it is tied to a managed device, because the organisation can verify both the user and the endpoint state.
Practitioner guidance
- Map recovery paths before expanding passwordless Identify every account recovery flow, including help desk resets, backup codes and identity proofing exceptions, then compare each one to the assurance level of primary passwordless sign-in.
- Tie access decisions to device trust signals Require device posture and enrollment status to participate in access policy so a valid passkey or biometric is not treated as sufficient on its own.
- Catalogue legacy applications that force fallback Separate applications that support phishing-resistant authentication from those that still depend on older protocols, transitional tokens or weaker recovery methods.
Bottom line: Passwordless authentication changes the access experience, but it does not remove the need for strong recovery, device assurance and application compatibility.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passwordless authentication does not eliminate identity risk, it relocates it. The access decision moves from shared secrets to recovery workflows, device trust and federation boundaries. That means IAM programmes must stop treating passwordless as a single control and start treating it as a control plane with multiple failure points. The practical conclusion is that the strongest sign-in method can still fail if its exception handling is weak.
A few things that frame the scale:
- eBay's passkey data shows 55-60% of passkey adoption happens on mobile, against around 20% on desktop.
A question worth separating out:
Q: Should organisations view passwordless as a replacement for Zero Trust controls?
A: No. Passwordless can strengthen the authentication step, but Zero Trust still depends on continuous evaluation of device, user and context. If passwordless is deployed without those surrounding controls, it becomes a better login method rather than a broader trust model.
👉 Read our full editorial: Passwordless authentication still depends on recovery and device trust