TL;DR: Passkeys have crossed into mainstream use with more than 3 billion active credentials globally, but the hard work now sits in enrollment, recovery, platform variation, and phishing-resistant account lifecycle design, according to OneSpan’s report from FIDO Authenticate 2025. The security shift is no longer about proving passkeys work; it is about removing the fallback paths that quietly preserve password-era risk.
Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “FIDO Authenticate 2025: What I learned about passkeys at scale”.
Key questions
Q: How should teams implement passkeys without leaving legacy recovery risk behind?
A: Treat passkeys as part of the account lifecycle, not a standalone login project.
Q: Why do passkey rollouts fail even when users understand them?
A: Passkey rollouts usually fail because the surrounding identity operations are not ready.
Q: What signs show that an authentication programme is not truly phishing resistant?
A: Look for shared secrets, OTP dependence, push fatigue risks, and exceptions for privileged users.
Practitioner guidance
- Map the full passkey account lifecycle Document enrollment, device replacement, recovery, and deprovisioning paths before scaling deployment.
- Remove phishable recovery methods Eliminate SMS recovery, weak reset flows, and other fallback paths that preserve legacy attack opportunities.
- Segment adoption metrics by platform Track mobile and desktop enrollment separately, then compare completion rates, drop-off points, and support burden.
Bottom line: Passkeys improve authentication, but they do not close the broader account lifecycle problem that appears in enrollment, recovery, and device change.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Passkeys are not the finish line for identity security; they expose whether the account lifecycle was ever governed as a whole. The article shows that organisations can deploy stronger authentication while still preserving insecure recovery and fallback paths. That means the security outcome depends less on the credential format and more on whether the surrounding account journey has been rebuilt around phishing-resistant defaults.
A question worth separating out:
Q: What should identity teams do when passkeys coexist with password-era workflows?
A: Decide which legacy flows will be retired, which will be time-limited, and which will be prohibited entirely. Then align security, support, and product ownership so the default journey favours passkeys and the exception paths do not reintroduce phishable access.
👉 Read our full editorial: Passkeys at scale expose the real account lifecycle gap