World Passkey Day: Passkeys as the key to the secure Agentic Enterprise

May 7 is World Passkey Day - a global event to drive the transition from passwords to secure login methods. Sven Kniest, VP Central & Eastern Europe at Okta, explains why passkeys are more important than ever in the age of autonomous AI agents - and what companies need to do now.

Okta VP Sven Kniest drives Passkeys security forward. Source: zvg

Credential-based attacks are responsible for 60 percent of all security incidents and 88 percent of web application security breaches, according to Okta's latest annual Business at Work report. While cyber criminals are increasingly using autonomous AI agents for their attacks, replacing traditional passwords with passkeys is becoming more urgent.

Why passkeys are more secure than passwords

Passkeys offer a powerful combination of increased security and improved user experience compared to traditional passwords. They are resistant to phishing because they are cryptographically bound to the domain of a specific website and cannot be used on fake or malicious websites. According to the Fido Alliance, logins with passkeys are on average 20 percent faster than with passwords. What's more, there are no more passwords that can be stolen, recorded by keyloggers, stolen in the event of a data breach or cracked using a brute force attack.

In combination with single sign-on and secure credential managers from various providers, passkeys can also be automatically synchronized on all devices - which considerably simplifies the login process for users.

Two variants, one goal: secure identity

Passkeys are basically available in two variants. Synchronized passkeys are synchronized between a user's devices via a cloud service - for example, an operating system ecosystem or a password manager. The same passkey can therefore be used across multiple devices in a specific ecosystem. Device-bound passkeys, on the other hand, never leave the device on which they were generated. These are suitable for FIDO security keys, for example, including those with security certification.

For companies that rely on maximum security, we recommend a provider of modern identity security that supports both variants and covers the central requirements of a customer identity platform in the areas of authorization, user management, customer journey, user experience and identity security.

AI agents need managed identities

The AI transformation towards the agentic enterprise poses a new challenge: autonomous AI agents act as digital entities in the network and - just like human users - require a managed identity with clearly defined access rights. Companies that internalize this principle and rely on AI governance that supports simple and secure login methods and protects AI agents from threats such as prompt injection are taking the decisive step towards an agentic enterprise.

Further information on passkeys and identity security can be found on the blog of Octa.

(Visited 97 times, 1 visits today)

More articles on the topic