Security, Microsoft Sessions

T10 Phishing-Resistant Passwordless Deployment Best Practice

August 12th, 2025

3:00pm - 4:15pm

Level: Intermediate

Michael Epping

Senior Program Manager

Microsoft

Organizations are seeking to move from single factor authentication into their apps and systems to MFA, and then move on to passwordless authentication - especially phishing-resistant passwordless authentication methods. This transformation is being accelerated thanks to the proliferation of modern FIDO2 credentials, better known as passkeys. These credentials promise to be SAFE, EASY, and FAST - but enterprise adoption of passkeys is still in its early phases. Passkey safety is provided by being as easy to use as a password, but without the easily phishable aspects of passwords. Ease of use is provided through the use of PINs or biometrics already well used on most devices. Speed is provided by the simplicity of sync and elimination of annoying SMS or OTP codes. Ultimately, phishing-resistant passwordless credentials promise to transform enterprise authentication by bringing consumer-grade authentication experiences to the enterprise, while providing enterprises with the security they demand. In this session, we will discuss the prerequisites, considerations, and best practices for rolling out phishing-resistant passwordless authentication in an enterprise environment. This includes critical project steps like determining which authentication methods make sense for various user personas in your environment, assessing your device readiness, creating a credential rollout order of operations strategy, measuring progress of the rollout, and building confidence that you are ready to mandate the use of phishing-resistant credentials. This final step is critical in reducing and finally eliminating the use of passwords in the environment. This session will be informed by real world deployments working with strategic Microsoft customers, who have been working to deploy passkeys, Windows Hello for Business, security keys, and other methods. Attendees will leave with actionable Go-Dos for their own phishing-resistant passwordless journey.

You will learn:

  • Passwordless Deployment
  • Passkeys and FIDO
  • Identity and security hardening