AuthPoint Passkeys: Strengthen MFA with Phishing-Resistant Passkeys

Recent incidents have shown that cyberthreats are no longer limited to password theft. Organizations are increasingly being asked by cyber insurers, auditors, and regulatory authorities whether their authentication systems can genuinely protect against phishing.

In some situations, Multi-Factor Authentication (MFA) alone may not provide sufficient protection—especially when attackers can create fake login pages designed to trick users into entering their passwords or one-time verification codes.

AuthPoint Passkeys address this challenge by bringing traditional MFA and phishing-resistant authentication together on a single platform. Organizations do not need to change providers, migrate existing systems, or purchase an additional premium license.

In this article, BMSP explains how AuthPoint Passkeys work, how they differ from traditional MFA, and how they can strengthen the security of high-risk user accounts while improving readiness for compliance requirements and cyber insurance assessments.

Table of Contents

What is a Passkey, and How Does It Prevent Phishing?

A passkey is a login method that allows users to authenticate using a fingerprint, facial recognition, or a security device that supports the FIDO2 standard instead of entering a password or one-time password.

The key advantage is that a passkey is cryptographically bound to the legitimate website or service. When a user is tricked into visiting a fraudulent website, the authentication system will not provide the information required to complete the login.

This means attackers cannot intercept a password, OTP, or verification code and reuse it to access the account because there is no reusable code to steal in the first place.

However, passkeys are not designed to replace every form of MFA. Instead, they provide an additional layer of protection that organizations can deploy for high-risk accounts and critical systems while continuing to use traditional MFA as the foundation for general users.

Two Authentication Methods on One Platform

The two authentication methods complement each other, with each serving different risk levels and usage requirements.

Category

AuthPoint Traditional MFA

AuthPoint Passkey Authentication

Login method

Password combined with push notifications, QR codes, or TOTP

Fingerprint or facial recognition without passwords or OTPs

Protection

Protects against attacks that rely on compromised account credentials

Protects against phishing by binding authentication to the legitimate website

Supported use cases

VPN, desktop, SAML, OIDC, and RDP

FireCloud, Microsoft Entra ID, and OIDC applications

Recommended users

Suitable for general users and devices across the organization

Recommended initially for executives, administrators, and privileged accounts

Supported devices and platforms

Windows, macOS, Android, and iOS

Apple iCloud Keychain, Google Android and Chrome, Windows Hello, and YubiKey FIDO2

AuthPoint Passkeys currently support FireCloud, Microsoft Entra ID, and OIDC applications. Support for SAML integrations is planned for a future release.

Start with High-Risk Accounts

Organizations do not need to enable passkeys for every user at the same time. Authentication controls can be introduced according to the risk level of each user group. For example:

  • General users can continue using traditional MFA.
  • Executives and administrators can use synced passkeys.
  • Highly regulated systems can use hardware-bound passkeys through YubiKey.


This approach allows organizations to strengthen security progressively without creating unnecessary complexity for the entire workforce.

Available Without Additional Licensing Costs

AuthPoint Passkeys are included with AuthPoint MFA, Total Identity Security, and Zero Trust Bundle licenses at no additional cost.

Deployment is also designed to be straightforward. Administrators can enable passkey authentication for individual resources through a simple configuration option. Users can then register their own passkeys in less than one minute, without requiring any new infrastructure.

For organizations already using AuthPoint, adding passkeys does not require a completely new identity security project. It is an extension of the existing platform that helps the organization respond to increasingly sophisticated threats.

Improve Cyber Insurance and Compliance Readiness

Cyber insurance providers and auditors are placing greater emphasis on phishing-resistant MFA because some traditional MFA methods can still be compromised through fraudulent login pages or push-notification approval attacks.

According to WatchGuard documentation, AuthPoint Passkeys align with phishing-resistant MFA requirements and guidance from CISA, NIST SP 800-63-4, and OMB Memorandum M-22-09.

For organizations operating in regulated industries, enabling passkeys can strengthen readiness for audits, cyber insurance renewals, and executive-level security reviews.

Differentiate Your Security Services

IT service providers and managed security providers can incorporate passkeys into tiered security offerings without introducing products from an additional vendor.

Some identity providers charge extra for passkey functionality or require customers to upgrade to a higher-tier license. AuthPoint, by comparison, includes this capability within eligible existing licenses. This creates a clear advantage in terms of both cost and ease of management.

Passkeys also strengthen the identity verification layer of a Zero Trust strategy. They can work alongside endpoint security services such as EPDR and network security services such as FireCloud, all within an environment that administrators already manage.

Strengthen Your Security Readiness with BMSP

During your next cyber insurance renewal, compliance audit, or security review, you may be asked whether your organization has implemented phishing-resistant MFA.

Preparing in advance enables your organization to respond confidently to these requirements without changing platforms, migrating systems, or launching an entirely new identity security project.

WatchGuard AuthPoint Passkeys build on traditional MFA, which continues to protect users across the organization, by adding phishing-resistant authentication for high-risk individuals and access points. These may include executives, administrators, and privileged accounts. Both authentication methods can be managed through the same platform.

The solution aligns with phishing-resistant MFA requirements and guidance from CISA, NIST SP 800-63-4, and OMB M-22-09. It also supports Apple iCloud Keychain, Google platforms, Windows Hello, and FIDO2-enabled YubiKeys.

AuthPoint Passkeys are included with AuthPoint MFA, Total Identity Security, and Zero Trust Bundle licenses at no additional cost.

Getting started is simple. Administrators can enable passkeys for individual resources with a single configuration selection, while users can register their passkeys independently in less than one minute. No new infrastructure investment is required.

At BMSP, we help organizations across ASEAN transform phishing-resistant MFA from a compliance requirement into a practical security advantage.

Our services cover every stage of implementation, from assessing business and security requirements to developing an authentication strategy, deploying the solution, and managing it according to each organization’s risk profile and existing infrastructure.

We also provide flexible monthly payment options to help reduce upfront investment. This enables organizations to plan expenses more effectively, maintain greater control over their budgets, and access enterprise-grade security technologies without waiting for approval of a large initial investment.

Strengthen your identity protection and prepare for increasingly sophisticated phishing attacks and security requirements.

Get started with WatchGuard AuthPoint Passkeys through BMSP today.

Contact BMSP

Contact BMSP to discuss practical cybersecurity solutions for your organization.

Share

Related Content

Get in touch with us. We’re here to assist you.

08. Home Bottom (EN)

Learn how we helped 100 top brands gain success