YouTube Video
Passwordless authentication and phishing-resistant authentication are not the same thing. Passkeys and FIDO keys can provide strong protection, but weaker fallback methods can undermine that protection.
Authentication policies need to enforce the intended strength rather than simply offering passwordless sign-in. Conditional access, compliant devices, sign-in-log monitoring, and controls around fallback authentication all matter. A stolen session or compromised recovery path can bypass an otherwise strong login.
Where does your authentication strategy become weakest when the primary control fails?
Subscribe to our podcasts: https://securityweekly.com/subscribe
#IdentitySecurity #Phishing #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec
Authentication policies need to enforce the intended strength rather than simply offering passwordless sign-in. Conditional access, compliant devices, sign-in-log monitoring, and controls around fallback authentication all matter. A stolen session or compromised recovery path can bypass an otherwise strong login.
Where does your authentication strategy become weakest when the primary control fails?
Subscribe to our podcasts: https://securityweekly.com/subscribe
#IdentitySecurity #Phishing #SecurityWeekly #Cybersecurity #InformationSecurity #AI #InfoSec