Join our Newsletter — 33% off our NHI Course
Home FAQ NHI Lifecycle Management What breaks when organisations manage PKI certificates and…
NHI Lifecycle Management

What breaks when organisations manage PKI certificates and FIDO2 passkeys in separate workflows?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: NHI Lifecycle Management

Separate workflows often break lifecycle consistency. Administrators can lose track of which device holds which credential, registrations can drift between systems, and revocation may happen in one directory but not the other. That creates user friction, support overhead, and a wider window where lost or departed-user credentials can still authenticate somewhere in the environment.

Why Separate Workflows Create Identity Drift

PKI certificates and fido2 passkeys solve different problems, but organisations often let them live in different operational silos. That separation makes it easy for lifecycle state to diverge: one system says a device is enrolled, another says it is revoked, and neither view is complete enough for confident access decisions. The result is not just admin overhead, but inconsistent trust.

This is especially risky because identity assurance depends on knowing what credential exists, where it is bound, and whether it is still valid. NIST’s NIST Cybersecurity Framework 2.0 and NIST SP 800-63 Digital Identity Guidelines both reinforce that identity controls need consistent issuance, binding, and revocation practices. When certificate management and passkey management are disconnected, those practices become harder to enforce across the full credential estate.

NHIMG research on machine identity shows how quickly visibility gaps become operational risk: only 38% of organisations have automated certificate lifecycle management in place, and 57% lack a complete inventory of their machine identities, according to the Critical Gaps in Machine Identity Management report by SailPoint.

In practice, many security teams discover the mismatch only after a lost device, failed offboarding, or expired credential has already disrupted access.

How Lifecycle Consistency Works in Practice

The practical fix is to manage certificates and passkeys as part of one identity lifecycle, even if the underlying technologies remain distinct. That means enrollment, binding, renewal, rotation, suspension, and revocation should follow the same authoritative workflow and source of truth. The goal is not to make PKI and FIDO2 identical. The goal is to make sure both are governed by the same identity state.

For certificates, that usually means tracking subject, device binding, expiry, and revocation status. For FIDO2 passkeys, it means tracking registration, device association, authenticator type, and whether the key is still trusted for the user or workload. When these records are unified, administrators can deprovision a user once and propagate that action across all authenticators, rather than hoping separate teams remember separate systems.

A mature workflow typically includes:

  • One authoritative identity record for user and device state.
  • Automated issuance with policy checks at enrollment time.
  • Shared offboarding and revocation triggers across all authenticators.
  • Continuous reconciliation to detect orphaned certificates or passkeys.
  • Clear ownership for recovery, renewal, and exception handling.

For certificates, this aligns with the lifecycle emphasis in the Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs. For operational teams, the real test is whether revocation is enforced everywhere the credential is accepted, not just in the directory that issued it. These controls tend to break down in hybrid environments where PKI, mobile device management, and identity governance are owned by different teams because revocation state is not reconciled fast enough.

Where Separate Workflows Usually Fail First

Tighter credential governance often increases administrative overhead, requiring organisations to balance security gain against user friction and support load. The failure modes are usually predictable, but they surface differently depending on environment maturity.

One common edge case is device replacement. If a user gets a new laptop or phone, the passkey may move cleanly while the certificate remains tied to the old hardware, or the reverse. Another is emergency access: if help desk workflows can reset one authenticator but not the other, recovery becomes inconsistent and the organisation creates a bypass path that bypasses policy rather than enforcing it.

There is also no universal standard for how tightly PKI and FIDO2 should be operationally unified. Best practice is evolving toward shared lifecycle governance, but the exact control model depends on whether the organisation prioritises workforce login, admin access, or device trust. For many teams, the most practical starting point is to standardise offboarding and continuous reconciliation, then extend that model into enrollment and renewal.

NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives is useful here because auditors rarely care which team owns the workflow; they care whether invalid credentials are actually removed. When separate workflows persist, stale trust accumulates fastest in mixed endpoint estates, contractors with multiple devices, and environments where certificate renewal is automated but passkey lifecycle is still manual.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03Credential lifecycle gaps are central when certs and passkeys drift.
NIST CSF 2.0PR.AC-4Separate workflows weaken access control consistency across authenticators.
NIST SP 800-63IAL/AAL/FALBinding and authenticator management must stay consistent across credential types.
OWASP Agentic AI Top 10A2Credential drift creates bypass opportunities similar to agent tool misuse and stale trust.
CSA MAESTROGOV-02Shared governance is required when multiple trust mechanisms affect one identity.

Treat every authenticator as a runtime trust input and remove stale credentials immediately.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org