Skip to main content

Passkeys are advancing in the enterprise and challenging the traditional password

Phishing-resistant credentials are beginning to consolidate as an alternative to reduce password theft and access friction.

CybersecuritySeintec team2-3 min read
Passkeys are advancing in the enterprise and challenging the traditional password

News summary

The password has been the default access mechanism for decades and, at the same time, one of the most exploited points by attackers. Key reuse, phishing, leaks and weak passwords are part of everyday incidents. That is why passkeys are gaining ground as a simpler and more secure alternative for the user.

A passkey uses public-key cryptography. The secret required to authenticate remains on the user's device and is not shared with the remote service. This significantly reduces the usefulness of a fake page designed to steal a password and avoids the company having to store reusable secrets in the same way as in traditional systems.

In the corporate environment, deployment requires more planning than for a personal account. Decisions must be made on which devices can register credentials, how to recover access if a device is lost, what happens to employees who change roles, and how to integrate legacy applications that still rely on username and password.

The transition, therefore, will be gradual. Many organisations begin with high-risk groups, such as administrators, management, or personnel with access to sensitive information. They then extend the model to compatible applications while maintaining controlled contingency mechanisms for legacy systems.

The benefit is not just security. Fewer password resets also mean fewer incidents and a smoother user experience. The challenge lies in deploying it with a coherent identity strategy.

User experience will be decisive. If the new method introduces too many exceptions or confusing recovery processes, workarounds will emerge. It is advisable to test first with a small group, measure incidents, and document device loss, equipment replacement, and temporary access scenarios before scaling the deployment.

What is changing

For decades the password has been the default access mechanism and, at the same time, one of the most exploited points by attackers through credential reuse, phishing and data leaks. Passkeys are gaining ground as an alternative: they use public-key cryptography, so the secret needed to authenticate stays on the user's device and is never shared with the remote service.

This significantly reduces the usefulness of a fake page designed to steal credentials and means the company no longer has to store reusable secrets the way it does with traditional passwords.

What it teaches a mid-sized business

In a corporate environment the rollout needs more planning than on a personal account: the company must decide which devices can register credentials, how access is recovered if a device is lost, what happens to employees who change roles, and how legacy applications that still rely on usernames and passwords are integrated.

The transition will be gradual. Many organisations start with high-risk groups, such as administrators or management, then extend the model to compatible applications while keeping controlled fallback mechanisms for legacy systems.

What to review

Before expanding passkey use across the organisation, it is worth checking:

  • Which critical applications already support passkeys and which will still depend on passwords.
  • How access is recovered if the registered device is lost or replaced.
  • What happens to credentials when an employee changes role or leaves the company.
  • Whether the chosen pilot group allows incidents to be measured before widening the rollout.

Frequently Asked Questions

Do passkeys completely replace the password?
In compatible applications, yes; legacy systems usually keep controlled fallback mechanisms during the transition.
What does the company gain beyond security?
Fewer password resets, which reduces support tickets and improves the user experience.
Where should the rollout start?
With a small high-risk group, measuring incidents and documenting device loss or replacement before expanding further.

Concepts mentioned in this article: Phishing

Seintec can help you evaluate where it makes sense to introduce passkeys and phishing-resistant authentication in your organisation. Contact us and an expert will propose a roadmap compatible with your current systems.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.