Making Your Passwordless Environment Fully Phishing-Resistant

 

Are passwords passé? Many organizations are considering the transition to passwordless authentication. However, not all passwordless options—specifically, passwordless phone sign-in—are fully phishing resistant. If your company is bidding goodbye to passwords, phishing resistance should be an integral of your plan.

As of this moment, more than 80% of Accenture’s 750K+ employees operate in a fully passwordless model, using Windows Hello for Business, Microsoft Authenticator passwordless phone sign-in, and FIDO2 tokens. Using Accenture as a use case, this session discusses strategies for replacing passwordless phone sign-in with Passkey as part of a plan to move to a posture of full phishing resistance. We’ll also discuss why that final leg of password removal is challenging, how to address setup and recovery tasks in a world without passwords, and what to do with the privileged access landscape—one of the last enclaves of high password dependence.

Slide Deck: https://www.semperis.com/wp-content/uploads/resources-pdfs/hipconf-2024/making-your-passwordless-environment.pdf