Join our Newsletter — 33% off our NHI Course

Post-passwordless identity: what comes after passkeys and MFA?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Passwordless authentication, passkeys, and phishing-resistant MFA are accelerating, but the real challenge is scaling trust across platforms, privacy models, and future post-quantum requirements, according to OneSpan’s commentary on Gartner’s July 2025 Hype Cycle for Digital Identity. The important shift is that passwordless is now table stakes, not an end state, and IAM teams need to plan for what comes after it.

Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “Beyond passwordless: Preparing for what’s next in digital identity”.

Key questions

Q: What should IAM teams watch when rolling out passwordless login?

A: Watch enrollment assurance, recovery, device revocation, and exception handling.

Q: Why do passkeys not eliminate the need for continuous authentication?

A: Passkeys reduce phishing and credential replay, but they only prove the user at the point of login.

Q: When should organisations prioritise verifiable credentials over other identity upgrades?

A: When portability, privacy minimisation, and reusable identity claims are real programme goals, and when the relying-party ecosystem can support them.

Practitioner guidance

  • Map identity trust boundaries Inventory where passwordless, passkeys, and phishing-resistant MFA are actually enforced, then identify the platforms and applications that still rely on weaker fallback paths.
  • Design for cross-platform portability Check whether your authentication and identity proofing choices can travel across browsers, devices, and relying parties without forcing separate account silos.
  • Pilot continuous authorisation Use high-risk applications to test whether access should be re-evaluated during a session rather than only at login, especially where context shifts quickly.

Bottom line: Passwordless reduces authentication friction and phishing exposure, but it does not by itself solve the broader trust architecture problem.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Post-passwordless identity is a trust architecture problem, not an authentication feature problem. Passwordless removes a common attack surface, but it does not solve how identity is bound, reused, recovered, or governed across platforms. The market conversation has moved beyond login mechanics to the question of whether the surrounding trust model can scale. Practitioners should treat passwordless as one control layer inside a larger identity fabric.

A few things that frame the scale:

A question worth separating out:

Q: What should security teams prepare for after passwordless adoption becomes standard?

A: They should prepare for cryptographic transition, ecosystem interoperability, and identity governance that works beyond the login step. Passwordless reduces one class of risk, but it does not end the need to manage trust, recovery, privacy, or future authentication models such as post-quantum approaches.

👉 Read our full editorial: Post-passwordless identity still needs scalable trust controls


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.