The Conventional Wisdom
Security leaders often hear that passkeys will eliminate passwords, stop phishing, and provide seamless authentication. The FIDO Alliance promotes this vision, and with Dashlane implementing FIDO Credential Exchange on Android, it seems inevitable.
The common belief is simple: deploy passkey support, watch adoption rise, and declare victory over credential theft. Every major platform supports FIDO2, and browser vendors are on board. The technology works. So why aren't passwords obsolete yet?
The Missing Piece
Here's what's overlooked: passkeys don't fail due to technology; they fail due to migration challenges.
You can't just switch 300 million user accounts from passwords to passkeys overnight. You need a reliable way to transfer existing credentials between systems. Otherwise, users will create passkeys on one device and get locked out when switching to another. The industry spent years solving password sync across devices. Now, we're asking users to start over with a new system.
FIDO Credential Exchange addresses this issue. It's not about making passkeys more secure, they already resist phishing. It's about making them portable enough for everyday use. Dashlane's implementation on Android is significant because it acknowledges that adoption depends on practical migration, not just technical superiority.
Passkeys are not just a security upgrade; they're a distribution challenge.
The Evidence
What actually blocks passkey rollouts in enterprises? It's not technical capability. Major identity providers support FIDO2, and users have compatible devices. The protocol works.
The real barrier is the user experience gap between password-based and passkey-based workflows. Consider when your team tries to authenticate from a new laptop or a shared kiosk. With passwords, they type and move on. With passkeys, they need the private key tied to a specific device.
FIDO Credential Exchange offers a secure way to transfer these private keys between password managers and platforms. It's not perfect, you still need to trust the receiving system, but it's the first standardized solution for using passkeys on new devices.
Dashlane's quick implementation shows that consumer password managers are ahead of enterprise IAM vendors. Consumer tools depend on user adoption, while enterprise IAM can enforce methods through policy. Dashlane had to solve portability first, or users would stick with passwords.
This is the gap in the "passkeys replace passwords" narrative. Replacement requires migration tools, not just better cryptography. Without FIDO Credential Exchange, users would have to re-enroll passkeys on every device, ensuring they'd stick with passwords.
What to Do Instead
If you're planning a passkey rollout, rethink your approach. Don't start with enabling FIDO2 authentication. Start with how users will move their credentials.
First, audit your current credential portability. Can users export passwords from your corporate password manager? Can they import them into a personal one? What happens if they lose their phone or laptop? Your answers will show if you're ready for passkeys, as these questions become harder with them.
Second, check if your identity provider or password manager supports FIDO Credential Exchange. If not, find out when they will. This isn't optional; it's crucial for scaling passkey adoption.
Third, design your rollout as a hybrid strategy, not a replacement. You'll run passwords and passkeys in parallel for years. Plan for it. Ensure your systems handle both credential types, your campaigns review both, and your reports track adoption without penalizing users who haven't migrated.
Fourth, focus portability testing on scenarios that break: new device enrollment, account recovery, cross-platform authentication, and contractor onboarding. These are where password workflows are weakest and where passkey adoption can thrive. But they're also where portability is key.
Treat FIDO Credential Exchange as the enabler it is. The security benefits of passkeys are known. The migration path determines if you'll realize them.
When the Conventional Wisdom Is Right
The conventional wisdom is right about one thing: phishing-resistant authentication is worth the migration cost.
If your threat model includes credential phishing, passkeys eliminate that risk. No amount of training stops sophisticated phishing. FIDO2 does, as the private key never leaves the device and binds authentication to the origin.
It's also right that now is the time to start. Platform support is widespread, users are familiar with biometric authentication, and standards are stable. FIDO Credential Exchange is the final piece for enterprise adoption.
Where the wisdom fails is in assuming migration is easy. It's not. But don't wait. Plan for portability from the start, choose vendors with full FIDO Credential Exchange support, and design your rollout around user workflows, not just security needs.
Passkeys will replace passwords, but only if we solve import first.




