TRACK: THREATS AND DETECTION

Phishing-resistant sign-in: passkeys, FIDO2 and assurance levels

SHORT ANSWER

A sign-in method resists phishing when it only works with the real site. Passkeys and FIDO2 security keys do that by design; passwords and one-time codes do not, because a fake page can relay them in real time.

Editorial assessment · Desk research from public vendor material · Reviewed 2026-09-29

3 min read

Most attacks on workforce identity start at sign-in. A password can be guessed, reused from another breach or typed into a fake page. Adding a one-time code helps against guessing and reuse, but not against a well-built fake page: in adversary-in-the-middle phishing, the page relays the password and the code to the real site as the victim types them, and captures the session that comes back.

Why passkeys resist it

Passkeys and FIDO2 security keys replace the shared secret with a key pair. The private key stays on the device or security key, or is synced between a person's own devices, and it signs a challenge from the site. The signature is tied to the site's real address, so a fake page at a different address receives nothing it can use. There is no code to relay.

What assurance levels mean

NIST SP 800-63B-4, published on 31 July 2025, sets out three authenticator assurance levels and supersedes the previous edition of SP 800-63B. Higher levels require stronger authenticators and more protection against attacks such as phishing. When a vendor says a method meets a level, it is making a claim against this document, and the claim usually depends on configuration.

Okta, for example, states that FastPass meets NIST requirements for AAL3 on properly configured devices. NewCore scores every authenticator on a live strength scale from 1 to 10 mapped to NIST levels, and its just-in-time access requires a verified strength.

What the vendors on this site publish

  • Microsoft Entra lists Windows Hello for Business, platform credential for macOS, synced passkeys, FIDO2 security keys, passkeys in Microsoft Authenticator and certificate-based authentication as phishing-resistant methods.
  • Okta FastPass is passwordless and uses device trust and biometrics.
  • Google Cloud Identity supports MFA including Titan Security Keys, and passkeys.
  • Ping Identity includes passwordless with FIDO in its Plus plan; JumpCloud sells passwordless authentication as an add-on.
  • NewCore publishes passkeys and Visual MFA, in which a visual challenge replaces number matching.

Where to start

  1. Require phishing-resistant methods for administrators first.
  2. Make passkeys available to everyone, and track how many people use them.
  3. Find sign-ins that still accept a password alone, and applications reached without single sign-on.
  4. Remember that a stolen session or token skips sign-in entirely. The next lesson covers that.

See workforce IAM platforms compared

Related pages

Sources

NEXT LESSON

Token theft, replay and forgery

3 min read