TL;DR: Passkeys are increasingly being used beyond login for signing, digital wallets, and high-value approvals, while post-quantum prototypes and crypto-agility work show where the authentication stack is heading, according to Yubico. The governing challenge is no longer password replacement alone, but whether identity controls can support possession, intent, and selective disclosure without expanding trust in the wrong places.
NHIMG editorial — based on content published by Yubico: The path from passwords to passkeys and beyond
By the numbers:
- The ratio of non-human to human identities now exceeds 25x to 50x in modern enterprises.
Questions worth separating out
Q: How should organisations deploy passkeys for enterprise access?
A: Use device-bound passkeys for privileged and sensitive access, and treat synced passkeys as a consumer convenience rather than an enterprise assurance baseline.
Q: When do passkeys improve security but still leave governance gaps?
A: Passkeys improve security when they replace reusable secrets, but governance gaps remain if fallback authentication, recovery, or exception handling still relies on passwords or OTPs.
Q: How should security teams prepare identity systems for post-quantum cryptography?
A: They should start with a complete inventory of where cryptography underpins authentication, federation, signing, and encrypted transport.
Practitioner guidance
- Define passkey assurance tiers Map passkey enrollment, recovery, and reauthentication requirements to business risk so login-only use and approval use do not share the same policy by default.
- Separate authentication from privileged approval Require distinct controls for high-risk actions such as code signing, KMS root rotation, and payment approval, even when passkeys are used for primary login.
- Build a crypto-agility inventory List every identity workflow that depends on a fixed signature algorithm, attestation format, or key size so migration work is visible before standards shift.
What's in the full article
Yubico's full post covers the product and standards detail this analysis intentionally leaves aside:
- Keynote context from FIDO Authenticate on the current direction of passkeys and post-quantum authentication
- Technical explanation of how security keys support signing flows inside a standards-based digital wallet
- Prototype details for post-quantum signatures, including the hardware constraints and standards gaps
- The collaboration example behind wwWallet and why verifiable credentials and passkeys are being positioned as complementary
👉 Read Yubico's analysis of passkeys, digital identity, and post-quantum prototypes →
Passkeys beyond login: what it means for IAM and approvals?
Explore further
Passkeys are becoming an identity control surface, not just a password replacement. The article shows the category moving from login into approvals, wallets, and selective disclosure. That widens the governance surface from authentication assurance to action authorization and identity proofing. Practitioners should treat passkeys as part of the identity lifecycle, not as a one-time MFA upgrade.
A few things that frame the scale:
- The ratio of non-human to human identities now exceeds 25x to 50x in modern enterprises, according to the Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, which shows how quickly non-human governance lags behind usage growth.
A question worth separating out:
Q: How do passkeys relate to digital wallets and verifiable credentials?
A: Passkeys prove control of the authenticator, while verifiable credentials prove something about the person or subject. The two are complementary when the wallet preserves selective disclosure and the identity programme separates proof of possession from proof of attributes.
👉 Read our full editorial: Passkeys are moving beyond login into digital identity