The technology industry is undergoing a significant shift away from traditional passwords toward passwordless authentication methods, with major companies implementing new policies and solutions to enhance security. The transition builds on years of collaborative efforts through the FIDO Alliance to establish more secure authentication standards.
Microsoft has announced that beginning September 1, 2025, all logins to key Azure and Microsoft services must use Multi-Factor Authentication (MFA) or stronger authentication methods such as passwordless or passkey solutions. The deadline follows Microsoft’s earlier mandate for passwordless MFA implementation across Azure services in October 2024, demonstrating the company’s accelerating push toward enhanced security measures.
Passkeys, which leverage WebAuthn and FIDO2 standards, have achieved significant market penetration, now representing 62 percent of authentication challenges. Recent research into FIDO2 and synced passkeys has highlighted both the security advantages and potential considerations of these technologies. The U.S. National Institute of Standards and Technology (NIST) has updated its guidelines to require phishing-resistant MFA, including passkeys, for federal agencies starting in 2025. Implementation of passkey technology has expanded particularly in Australia and New Zealand, where approximately 30 million people can access services through government and enterprise platforms using this authentication method.
Industry analysis suggests passkeys will become the predominant online authentication method by 2027, superseding both traditional passwords and conventional MFA solutions. The prediction is supported by major developments from companies like RSA, which recently launched FIDO2-certified passwordless authentication capabilities, and Google Cloud’s integration of AI-powered authentication features into Workspace.
1Kosmos exemplifies this innovation trend, having secured $57 million in funding to expand its identity-first authentication solutions globally. The company’s platform combines biometric identity proofing with passwordless MFA, using blockchain technology and supporting various authentication standards across multiple operating systems. The company has also achieved certification under the UK’s Digital Identity and Attributes Trust Framework (DIATF), validating its security capabilities.
Artificial intelligence is emerging as a significant factor in identity and access security evolution, with 57.3 percent of Black Hat 2025 attendees identifying AI-driven identity validation and passwordless methods as crucial developments in the field. The trend matches broader industry movements, as demonstrated by recent innovations in AI-powered identity verification solutions designed to combat sophisticated threats like deepfake attacks.
Sources: Mobile ID World, Authsignal, SC World, Communications Today, SiliconANGLE