Passkeys Gain Enterprise Momentum as Sophos Reports 20% Adoption Rate

Close-up of a young woman’s face with an overlaid glowing red grid pattern, illustrating facial recognition or facial mapping technology used for biometric identification or analysis.

Passkeys have emerged as a leading alternative to traditional passwords, leveraging public-key cryptography and the Web Authentication (WebAuthn) standard developed by the FIDO Alliance. The authentication method uses a cryptographic key pair system, with private keys stored on user devices and public keys maintained by service providers, eliminating the need to transmit shared secrets during authentication.

Modern operating systems and browsers now include native passkey support, with companies like Microsoft reporting login times three times faster than traditional multi-factor authentication (MFA) methods. Enterprise adoption continues to grow across sectors, as organizations implement passkeys to enhance data protection, reduce IT support requirements, and strengthen zero trust security frameworks.

Sophos exemplifies this trend through its Sophos Central platform, where passkey authentications now exceed 20 percent of total logins since implementation in November 2024. The company has discontinued legacy MFA methods like SMS, requiring users to transition to either Time-based One-Time Password (TOTP) or passkey-based MFA solutions, following a broader industry shift away from SMS-based authentication due to security vulnerabilities.

Consumer applications of passkeys feature credential synchronization across multiple devices, with Google leading implementation efforts on Android and developing automatic password-to-passkey conversion capabilities. The shift raises important questions regarding private key management and verification, particularly in regulated sectors such as banking, where institutions like ANZ Bank are planning complete password elimination by 2025.

“Passkeys allow users to sign in using the same method they use to unlock their device, such as biometrics, a PIN, or a screen pattern,” says Alejandro Leal of KuppingerCole. “This makes passkeys inherently resistant to phishing and credential theft.”

While passkeys enhance authentication security, device theft protection remains crucial, especially given emerging threats like the PoisonSeed phishing campaign that targets FIDO authentication systems. Security best practices include implementing strong, unique passphrases alongside MFA and password managers. Rather than scheduled password changes, experts recommend immediate credential updates only when compromise is suspected, such as after data breaches, unusual login attempts, or device loss.

In enterprise environments, swift response protocols for lost devices or employee departures are essential for access control. Security teams monitor for potential compromise indicators, including unexpected MFA prompts or device access to critical accounts, with many organizations adopting comprehensive device management solutions to maintain security.

The technology continues to evolve, with the FIDO Alliance reporting significant enterprise adoption momentum despite implementation challenges. Ongoing focus areas include improving user understanding, maintaining private key integrity, and expanding system compatibility across diverse technological environments.