CISO Whitepaper

The Passkey Was Never Broken.

Why passkeys are not secure unless they are tied to dedicated biometric hardware

A live campaign against Microsoft Entra users is not defeating FIDO2. It is defeating the process around it. The attacker calls an employee, collects a password, signs in to the real account, and registers a new passkey on hardware the attacker owns. Microsoft accepts that credential because it was created through the genuine enrollment flow.

Phishing resistant authentication did not create phishing resistant enrollment. If a weaker identity path can authorize a stronger credential, the weaker path sets the actual security of the system.

This whitepaper walks the attack stage by stage, then shows what changes when the credential is bound to dedicated biometric hardware, a live fingerprint, and physical proximity.

What the whitepaper covers

  • The nine stages of the Entra passkey enrollment campaign, from the fraudulent portal to persistent attacker access.
  • Why the passkey itself was never compromised, and why that distinction changes the remediation.
  • How device bound biometric hardware changes the trust model: no export, no cloud sync, no remote approval.
  • Where Token stops the attack cold, including the registration action the attacker cannot complete.
  • A side by side comparison of passkey security with and without dedicated biometric hardware.
  • Why enrollment, replacement, recovery, and help desk restoration must all run the same standard.

Written for CISOs, identity teams, and risk leaders. Seven sections. Primary reporting listed at the end. August 2026.