Skip to main content
The state of ai impact assessment
Passkeys Won't Work Here: 5 Myths Blocking AdoptionFIDO & Passkeys
5 min readFor IAM Architects

Passkeys Won't Work Here: 5 Myths Blocking Adoption

You've read the NCSC announcement. FIDO2 credentials are more secure than traditional multi-factor authentication against common attacks. Your CISO forwarded the paper. Your board is asking questions.

So why haven't you started the transition?

Because myths persist. Some are rooted in outdated technical assumptions. Others stem from misunderstanding what FIDO2 actually requires. All of them keep organizations locked into authentication methods the NCSC now explicitly calls "inherently phishable."

Let's dismantle them.

Myth 1: "Passkeys are just another form of MFA"

Reality: When user verification is required during login, FIDO2 authentication constitutes multi-factor authentication on its own.

Traditional MFA stacks factors: something you know (password) plus something you have (Time-Based One-Time Password token) or something you receive (SMS code). Each factor can be intercepted separately.

FIDO2 changes this model. The cryptographic operation requires both possession of the private key and user verification (biometric or PIN). You're not adding factors; you're replacing the entire authentication process with a single phishing-resistant exchange. The server never sees a reusable secret, and the credential can't be relayed to another site. While session hijacking still requires separate controls, the authentication phase closes the door on credential reuse and real-time phishing.

If you're evaluating passkeys as "MFA option number seven," you're missing the point. They're not another layer. They're a different foundation.

Myth 2: "We can't implement passkeys until we retire passwords everywhere"

Reality: FIDO2 credentials work alongside existing authentication methods during transition.

Your Identity Provider doesn't force an all-or-nothing cutover. Most modern IAM platforms let you register FIDO2 credentials as an additional authentication method, then progressively phase out legacy flows. Users can authenticate with a passkey where supported and fall back to password plus Time-Based One-Time Password where not.

The NCSC's guidance reflects this: recommend passkeys wherever a service supports them, and two-step verification where it doesn't. That's a progressive rollout strategy, not a rip-and-replace mandate.

Start with high-risk populations: administrators, finance teams, anyone with access to sensitive systems. Require FIDO2 registration for these accounts, then expand. Your legacy authentication methods don't disappear overnight. They fade as adoption grows and you tighten Policy-Based Access Control rules to prefer phishing-resistant methods.

Myth 3: "Users will revolt because passkeys are too complicated"

Reality: FIDO2 removes steps from the user's perspective, not adds them.

Compare the ceremonies. Traditional MFA: enter username, enter password, wait for SMS code or open authenticator app, enter six-digit code, proceed. FIDO2: enter username, authenticate with biometric or device PIN, proceed.

You've eliminated the password memorization burden, the app-switching friction, and the code-expiry anxiety. Users don't manage secrets. They prove presence and verify identity in a single gesture.

The NCSC's sociotechnical research supports this. Passkeys offer "a more usable, secure replacement for passwords." Usability isn't a tradeoff here; it's a benefit. When security and convenience align, adoption accelerates.

Your communication strategy matters. Don't frame passkeys as "more security." Frame them as "faster login without passwords to remember." Users care about the outcome, not the cryptographic primitive.

Myth 4: "Passkeys lock us into specific vendors or devices"

Reality: FIDO2 is a standard, and synchronization is built into modern implementations.

The FIDO Alliance designed FIDO2 as an open standard to avoid vendor lock-in. Any FIDO2-certified authenticator works with any compliant relying party. You're not buying into a proprietary ecosystem; you're implementing a protocol.

Device lock-in was a legitimate concern with early hardware security keys. Lose the key, lose access. Modern passkey implementations solve this through secure synchronization across devices within the same platform ecosystem (iCloud Keychain, Google Password Manager, Windows Hello). The NCSC paper acknowledges this: credentials go through a lifecycle that includes synchronization and recovery.

Cross-platform portability continues to improve. Users can register multiple passkeys: one synced across their mobile devices, another stored on a Multi-Factor Cryptographic Device for high-security scenarios. Your IAM policy can require FIDO2 without dictating which authenticator type.

The standard gives you flexibility. Use it.

Myth 5: "We'll wait until passkeys are proven in the wild"

Reality: FIDO2 credentials are already more secure than what you're using today against attacks happening right now.

The NCSC's analysis focused on "the most common real-world attack techniques" including phishing, credential reuse, and session hijacking. Their assessment: all traditional MFA methods are inherently phishable. FIDO2 credentials are as secure or more secure against all common credential attacks observed in the wild.

Waiting for "more proof" means continuing to deploy authentication methods a national cybersecurity authority has publicly identified as vulnerable. You're not being cautious; you're accepting known risk.

The NCSC also notes that "large-scale attacks directly targeting correctly implemented passkeys are unlikely" because FIDO2 removes the ability to cheaply reuse or relay credentials. Attackers optimize for scale. When credential phishing stops working, they move to softer targets. Your organization doesn't need to be the last one holding reusable secrets.

What to do instead

Stop treating passkeys as a future-state aspiration. The NCSC will begin recommending them wherever supported. Your roadmap should reflect that shift.

Audit your IAM platform's FIDO2 support today. Most enterprise Identity Providers added it years ago; you may already have the capability dormant in your license. Identify applications that support FIDO2 authentication and prioritize them for pilot rollout.

Segment your user base by risk. Require FIDO2 registration for privileged accounts first. Measure adoption and friction. Iterate your enrollment process based on real feedback, not assumed resistance.

Update your authentication policy framework. Define "phishing-resistant authentication" as a distinct tier in your Policy-Based Access Control model. Map applications to required authentication strength. Enforce FIDO2 for anything touching financial systems, customer data, or infrastructure control planes.

Communicate the change as a usability improvement, not a compliance burden. Users don't care about the NCSC's threat analysis. They care that login takes three seconds instead of thirty.

The myths blocking passkey adoption aren't technical. They're organizational inertia dressed up as risk management. The NCSC just removed your cover. Act accordingly.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like