Passkeys have made real progress in reducing phishing risk, but they do not tell an organisation much about the device being used to create a credential – whether it was issued by the company, or simply bought independently by an employee and registered without oversight. HID’s Enterprise Attestation, now available across its Crescendo range of FIDO2-certified smart cards and security keys, is designed to close that gap.

The capability, built on the FIDO Alliance’s WebAuthn and CTAP specifications, works at the point of passkey registration. When a device attempts to enrol, the system checks for a certificate that ties it to a known, company-issued authenticator. If that certificate is absent or unrecognised, enrolment is blocked by policy. If it passes, the user sees no change to their login experience – the governance layer operates entirely in the background.

That last point matters. The friction introduced by security controls is a persistent adoption barrier, and one that Enterprise Attestation appears to have deliberately designed around. According to the FIDO Alliance’s own deployment research, strict regulatory requirements are cited by around a fifth of organisations as a significant obstacle to enterprise passkey adoption. Removing the ability to distinguish a company-issued authenticator from a personal one purchased independently by an employee does not help that situation.

Enterprise Attestation is supported by identity platforms including PingOne, and operates within standard FIDO workflows rather than requiring proprietary authentication flows or application changes. For security teams, the result is a verifiable, auditable record of every device granted access at registration – without locking into a non-standard implementation.

The capability is relevant across regulated sectors including financial services, healthcare and critical infrastructure, and aligns with compliance frameworks such as the EU’s NIS2 Directive and DORA, as well as Zero Trust architecture requirements. HID is an active participant in the FIDO Alliance Enterprise Deployment Working Group, which continues to develop the standards underpinning this area.


More

ID TECH: FIDO Alliance Brings Authenticate Conference to Asia-Pacific With Singapore Event Focused on Passkeys and Digital Credentials

The FIDO Alliance is expanding its flagship Authenticate conference series to the Asia-Pacific region with…

Read More →

Biometric Update: Regulatory clarification sets stage for major FIDO biometrics uptake in South Korea

South Korea has eliminated a significant barrier to the usage of the FIDO protocol for…

Read More →

Financial IT: HYPR and Yubico deepen partnership to secure and scale passkey deployment through automated identity verification

For years, HYPR and Yubico have stood shoulder to shoulder in the mission to eliminate…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.