Subscribe to the Non-Human & AI Identity Journal
Home Glossary Identity Beyond IAM Passkey Enrolment Fraud
Identity Beyond IAM

Passkey Enrolment Fraud

← Back to Glossary
By NHI Mgmt Group Updated August 15, 2026 Domain: Identity Beyond IAM

Passkey enrolment fraud happens when an attacker gains temporary access to an account and registers their own device or authenticator as trusted. After enrolment, the attacker can authenticate legitimately because the system believes the new binding is valid. The weakness is not the passkey itself, but the governance around who can bind it.

Expanded Definition

passkey enrolment fraud is an identity-binding abuse pattern, not a flaw in passkeys themselves. It occurs when an attacker uses a brief foothold to add a new device, authenticator, or platform credential to an account, then relies on the legitimate trust relationship created by that enrolment. In practice, the security failure sits in the enrolment workflow: weak step-up authentication, poor recovery governance, overbroad help desk authority, or missing approval checks can allow an attacker to create a durable new sign-in path. The concept is closely related to credential lifecycle controls and should be read alongside the expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls, especially where authentication, change control, and access enforcement intersect.

Definitions vary across vendors on whether the term includes only phishing-enabled enrolment or also insider-assisted and support-channel abuse. NHI Management Group treats it more broadly as any fraudulent trust establishment event that results in an attacker-controlled authenticator being bound to a legitimate identity. The most common misapplication is treating it as a passkey weakness, which occurs when teams assume cryptographic phishing resistance automatically protects the enrolment step.

Examples and Use Cases

Implementing enrolment protections rigorously often introduces extra friction at account setup and recovery, requiring organisations to weigh user convenience against stronger binding assurance.

  • An attacker phishes a password and session token, then uses the logged-in window to add a new passkey before the victim notices.
  • A help desk agent bypasses stronger verification during recovery and resets the account onto an attacker-controlled device.
  • A privileged administrator approves self-service device registration without a second independent check, creating an unauthorised trust binding.
  • An organisation allows recovery flows to skip step-up proofing, which lets a threat actor convert temporary access into persistent access.
  • Security teams compare enrolment controls against guidance in NIST SP 800-63 Digital Identity Guidelines to ensure binding strength matches the account’s assurance needs.

These scenarios are especially relevant in environments that rely on SSO, device trust, and self-service recovery, because a single successful enrolment event can outlast the original compromise. The risk increases when enrolment is treated as an administrative convenience rather than a security-sensitive identity event.

Why It Matters for Security Teams

For security teams, passkey enrolment fraud matters because it shifts the attack from password theft to trust creation. Once a fraudulent authenticator is enrolled, the attacker no longer needs to repeat the original compromise to regain access. That changes incident response, because revocation must address the binding itself, not just the original session or secret. The issue also intersects with NHI governance where device registrations, API clients, or agentic workflows are allowed to establish trust autonomously, making enrolment controls part of broader identity lifecycle management.

This is where policy, detection, and recovery need to line up: proofing standards, enrolment approvals, audit logging, and anomaly monitoring should all be explicit. Guidance from NIST SP 800-63 Digital Identity Guidelines and NIST SP 800-53 Rev 5 Security and Privacy Controls helps teams frame enrolment as a control point, not a user convenience feature. Organisations typically encounter account takeover persistence only after an incident review, at which point passkey enrolment fraud becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63IAL/AAL/FALDefines identity proofing and authenticator assurance relevant to secure enrolment.
NIST CSF 2.0PR.AAAuthentication and access authorization guidance applies to fraudulent authenticator binding.
NIST AI RMFGovern and manage AI-enabled identity workflows that can create or approve bindings.

Set enrolment assurance to match account risk and require stronger proofing for high-value bindings.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org