Join our Newsletter — 33% off our NHI Course

Synced vs device-bound passkeys: where should each one be used?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Synced passkeys can meet AAL2 when the sync service is encrypted and itself protected by AAL2-grade MFA, according to Crayonic, but they SHALL NOT be used at AAL3 because the top assurance level requires a non-exportable private key. That boundary makes passkey placement a governance decision, not a default rollout choice.

Editorial analysis by NHI Mgmt Group, based on content published by Crayonic: “Synced vs device-bound passkeys: which one belongs where”.

Key questions

Q: How should security teams decide where to use syncable passkeys versus device-bound keys?

A: Use syncable passkeys where usability and scale matter most, but keep device-bound keys for privileged access, regulated workflows, and any application where the organisation must preserve a stronger device-to-credential binding.

Q: What breaks when passkey recovery is not governed properly?

A: The programme falls back to the weakest legacy recovery path, which attackers often target first.

Q: Why do privileged accounts usually need device-bound passkeys?

A: Privileged accounts need the strongest practical binding between the authenticator and the device or token carrying it.

Practitioner guidance

  • Segment users by assurance requirement Classify accounts into customer, workforce, privileged, shared-workstation, and restricted-device groups before assigning synced or device-bound passkeys.
  • Remove weak fallback methods Disable SMS, email links, and other phishable fallbacks for admin, critical-system, and regulated-access groups so recovery does not undercut passkey strength.
  • Treat recovery as authentication Require identity re-checks and a second authenticator before issuing replacement credentials, because recovery now functions as part of the login path.

Bottom line: Synced passkeys improve usability, but their assurance depends on the sync account, recovery path, and device trust boundary.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Passkey policy is now an assurance policy, not a login preference. The real decision is which roles can tolerate a recoverable private key and which roles require an uncompromisable authenticator. Synced passkeys increase usability, but device-bound keys preserve a stronger assurance boundary for privileged and regulated access. Practitioners should stop treating passkey rollout as a single enterprise standard and instead define assurance tiers by role.

A few things that frame the scale:

A question worth separating out:

Q: How do managed devices change passkey governance for the workforce?

A: Managed devices let identity teams pair passkeys with a known hardware and policy boundary, which makes synced credentials safer for some staff but still unsuitable for others. Once users operate on shared workstations, personal cloud accounts, or unmanaged endpoints, the passkey policy has to tighten or shift to device-bound authentication.

👉 Read our full editorial: Synced passkeys work for most users, but not every role



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.