Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Passkeys beyond login: what it means for IAM and approvals


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19630
Topic starter  

TL;DR: Passkeys are increasingly being used beyond login for signing, digital wallets, and high-value approvals, while post-quantum prototypes and crypto-agility work show where the authentication stack is heading, according to Yubico. The governing challenge is no longer password replacement alone, but whether identity controls can support possession, intent, and selective disclosure without expanding trust in the wrong places.

NHIMG editorial — based on content published by Yubico: The path from passwords to passkeys and beyond

By the numbers:

Questions worth separating out

Q: How should organisations deploy passkeys for enterprise access?

A: Use device-bound passkeys for privileged and sensitive access, and treat synced passkeys as a consumer convenience rather than an enterprise assurance baseline.

Q: When do passkeys improve security but still leave governance gaps?

A: Passkeys improve security when they replace reusable secrets, but governance gaps remain if fallback authentication, recovery, or exception handling still relies on passwords or OTPs.

Q: How should security teams prepare identity systems for post-quantum cryptography?

A: They should start with a complete inventory of where cryptography underpins authentication, federation, signing, and encrypted transport.

Practitioner guidance

What's in the full article

Yubico's full post covers the product and standards detail this analysis intentionally leaves aside:

  • Keynote context from FIDO Authenticate on the current direction of passkeys and post-quantum authentication
  • Technical explanation of how security keys support signing flows inside a standards-based digital wallet
  • Prototype details for post-quantum signatures, including the hardware constraints and standards gaps
  • The collaboration example behind wwWallet and why verifiable credentials and passkeys are being positioned as complementary

👉 Read Yubico's analysis of passkeys, digital identity, and post-quantum prototypes →

Passkeys beyond login: what it means for IAM and approvals?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19221
 

Passkeys are becoming an identity control surface, not just a password replacement. The article shows the category moving from login into approvals, wallets, and selective disclosure. That widens the governance surface from authentication assurance to action authorization and identity proofing. Practitioners should treat passkeys as part of the identity lifecycle, not as a one-time MFA upgrade.

A few things that frame the scale:

  • The ratio of non-human to human identities now exceeds 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, which shows how quickly non-human governance lags behind usage growth.

A question worth separating out:

Q: How do passkeys relate to digital wallets and verifiable credentials?

A: Passkeys prove control of the authenticator, while verifiable credentials prove something about the person or subject. The two are complementary when the wallet preserves selective disclosure and the identity programme separates proof of possession from proof of attributes.

👉 Read our full editorial: Passkeys are moving beyond login into digital identity



   
ReplyQuote
Share: