Skip to main content
Mallory
Mallory

Passwordless Authentication and Passkey Adoption for Fraud Prevention

passwordlesspasskeysauthenticationidentity spoofingphishingfraudsecurityFIDOuser educationbehavioral analyticsdeepfakescross-deviceadoptionprevention
Updated November 11, 2025 at 05:00 AM3 sources

Get Ahead of Threats Like This

Know if you're exposed — before adversaries strike.

Microsoft has begun rolling out support for syncing passkeys across Windows devices and its Edge browser, addressing a key barrier to widespread adoption of passwordless authentication. This phased rollout starts with Edge on Windows 10 and 11, with plans to expand to iOS, Android, and MacOS, aiming to make passkey management seamless for users and organizations. The move is expected to accelerate the shift away from traditional passwords, leveraging the FIDO Alliance's non-phishable passkey standard to enhance security and usability across platforms.

Industry experts highlight that passwordless authentication is not just a technological upgrade but a critical component in modern fraud prevention strategies. As organizations transition to passkeys and device-based authentication, they face challenges such as cross-device access and user education. Integrating behavioral analytics with passwordless systems is seen as essential for detecting sophisticated fraud attempts, including those involving AI-driven identity spoofing and deepfakes, ensuring both external and internal threats are mitigated effectively.

Sources

Related Stories

Corporate Security Risks and the Shift Toward Passwordless Authentication

A new report from password manager 1Password highlights that weak or compromised passwords remain a significant security risk for organizations, with employee password practices worsening despite increased awareness. Survey data from over 5,000 workers across multiple countries reveals that a majority of employees, including IT professionals, continue to reuse passwords, rely on default credentials, or share passwords via insecure channels, exacerbating the threat landscape for businesses. The report underscores that even as companies move toward passwordless authentication, the transition is gradual and current credential management practices are not keeping pace with evolving threats. In response to these challenges, technology vendors are accelerating the adoption of passwordless solutions. Microsoft has released Edge version 142.0, introducing cross-platform passkey synchronization, allowing users to securely reuse passkeys across devices and browsers. This feature, which requires a dedicated PIN for access, aims to enhance both security and usability, reducing reliance on traditional passwords. The move reflects a broader industry trend toward passkeys and multi-factor authentication as default options, with major platforms like Google and Meta also embracing passwordless technologies to mitigate the risks associated with password-based authentication.

4 months ago

Security Risks and Best Practices for Passkey Authentication in Enterprises

Passkeys are emerging as a modern alternative to traditional passwords, offering a more secure and user-friendly authentication method by leveraging cryptographic key pairs tied to user accounts. Unlike passwords, passkeys are resistant to phishing attacks and cannot be easily stolen or reused, as they are typically stored locally on a user's device and accessed through biometric or device-based authentication. Major organizations and technology providers, including those aligned with the FIDO Alliance, are promoting passkeys as a next-generation security solution. However, the implementation of passkeys introduces new considerations, particularly regarding how they are stored and synchronized across devices. There are two primary types of passkeys: device-bound, which remain on a single device or hardware security key, and synced passkeys, which are stored in consumer cloud services such as iCloud or Google Cloud and synchronized across multiple devices for convenience. While synced passkeys improve usability and account recovery for consumers, they introduce significant security risks for enterprises. If an attacker compromises a user's cloud account or abuses account recovery processes, they can authorize new devices and gain access to enterprise resources, undermining the integrity of the authentication system. Additionally, if employees use personal cloud accounts on corporate devices, passkeys may be inadvertently synced outside the organization's security perimeter, greatly expanding the attack surface. Attackers can also exploit help desk and account recovery workflows to copy protected keychains to unauthorized devices. Furthermore, adversary-in-the-middle (AiTM) attacks and malicious browser extensions can manipulate WebAuthn requests, force authentication fallbacks, and potentially leak credentials or one-time codes. Security experts and organizations such as the FIDO Alliance and Yubico recommend that enterprises mandate device-bound passkeys, preferably stored on hardware security keys, to maintain higher assurance and administrative control. Enterprises evaluating passkey deployments must carefully assess the risks associated with synced passkeys and implement policies that restrict their use in favor of more secure, device-bound alternatives. The adoption of passkeys should be accompanied by robust administrative controls, user education, and careful integration with existing identity and access management systems. Organizations must also review and strengthen their help desk and account recovery procedures to prevent attackers from exploiting these channels. As passkeys become more widely adopted, ongoing vigilance and adaptation of security practices will be essential to fully realize their benefits while minimizing new risks. The transition to passkey-based authentication represents a significant shift in enterprise security strategy, requiring both technical and operational adjustments. Ultimately, the effectiveness of passkeys in protecting enterprise assets depends on thoughtful implementation and a clear understanding of the associated risks and mitigations.

5 months ago

Windows 11 and Password Managers Expand Passkey Support

Microsoft has introduced a new Windows API that allows third-party applications, such as 1Password, to manage passkeys directly within Windows 11. This integration enables users to create, sync, and manage passkeys using their preferred password manager, leveraging Windows Hello for authentication. The update aims to simplify the user experience by allowing password managers to take over credential management from Windows, making it easier for users to adopt passkeys for secure authentication across devices and services. The shift towards passkey authentication is part of a broader industry move to replace traditional passwords with more secure, phishing-resistant credentials. Passkeys utilize cryptographic methods and can be managed by platform, virtual, or roaming authenticators, with password managers increasingly supporting software-only (virtual) authenticators. This approach addresses longstanding security issues associated with passwords, such as susceptibility to phishing and poor user password hygiene, and is expected to become the standard for online authentication as more services adopt passkey support.

4 months ago

Get Ahead of Threats Like This

Mallory continuously monitors global threat intelligence and correlates it with your attack surface. Know if you're exposed — before adversaries strike.