Identity

Passkeys Solve Authentication — Not Identity Governance

Passkeys can strengthen sign-in, but organisations still need lifecycle, entitlement and accountability controls around every identity.

Passkeys improve an important part of the access journey: proving possession of a cryptographic credential without relying on a reusable password. That can reduce phishing exposure and make sign-in easier. It does not determine whether the account should exist, which access it should hold or whether that access remains appropriate.

Authentication is one control plane

Authentication answers a focused question: can this subject prove control of an accepted credential? Identity governance addresses a broader set of questions:

  • Who created and owns the identity?
  • Which roles and entitlements are justified?
  • What happens when responsibilities change?
  • Who reviews exceptional or privileged access?
  • When should access be removed?

A strong authenticator attached to an over-privileged or abandoned account simply provides strong access to the wrong permissions.

Design the complete lifecycle

Passwordless programmes work best when they are connected to authoritative identity data and lifecycle events. Joiner, mover and leaver processes should remain clear. Credential registration and recovery need policy. Device loss, account recovery and delegated administration require the same architectural attention as the primary sign-in ceremony.

Capability Primary question
Passkey authentication Can the user prove control of the credential?
Identity lifecycle Should the identity exist?
Access governance Should this identity have this access?
Privileged access Under what conditions can elevated access be used?

A joined-up architecture

Treat passkeys as part of an identity security system rather than a standalone feature. Connect registration policy, device posture, recovery, access reviews, privileged controls and monitoring. Use risk-based exceptions without allowing temporary workarounds to become permanent architecture.

Better authentication reduces one class of risk; governance prevents access from becoming unjustified over time.

Measure the right outcomes

Useful measures should cover more than enrolment. Consider the reliability of recovery, the reduction of weak authentication paths, the removal of dormant access and the time required to revoke credentials after a lifecycle event.

This demonstration article is an architectural overview. It intentionally avoids vendor-specific claims and should be updated with current official standards and platform guidance before being treated as implementation advice.

Notes

Technology capabilities, security guidance and vendor features may change over time. Validate all recommendations against current official documentation and your organisation's requirements.

Imthiaz Ahmed

About the author

Imthiaz Ahmed

Principal Solutions Architect writing about identity, cybersecurity, enterprise architecture and responsible AI.

Explore Identity Architecture

Related reading

Continue exploring.

← All articles