Tanflow IAM Suite & PAM - enterprise identity and privileged access security for the modern enterprise. Get a Demo →

17 July 2025 · Site Administrator

Moving Beyond Passwords: FIDO2 and Passkeys in the Tanflow IAM Suite

Phishing defeats passwords and fatigues OTP users; FIDO2 removes the shared secret entirely. This article examines passwordless authentication with passkeys and hardware keys in the Tanflow IAM Suite, and how to phase adoption by risk.

Every password-based system, however well policed, shares one structural flaw: the secret is typed, and anything typed can be phished. Attackers no longer need to break authentication - they build a convincing login page and let users hand the credential over. One-time passwords narrow the window but not the principle: an OTP relayed to a real-time phishing proxy works exactly once, which is exactly enough. The industry's answer is architectural rather than incremental - remove the shared, typeable secret altogether.

The enterprise challenge: the phishable factor

Credential phishing remains among the most reliable initial-access techniques precisely because it attacks the user, not the system. Password complexity rules do nothing against it. Rotation does nothing against it. Even TOTP and SMS OTP - valuable against password-only replay - can be relayed in real time by a proxy that sits between the victim and the genuine site. And each mitigation layered onto passwords adds friction that users feel daily: rotations, resets, prompts, fatigue. The cost curve of defending the password rises while the security ceiling stays fixed.

Why FIDO2 changes the structure

FIDO2 authentication replaces the shared secret with public-key cryptography bound to the legitimate origin. The private key lives in the user's authenticator - a hardware security key or a platform passkey - and signs a challenge that is only valid for the genuine site. A fake login page receives nothing replayable, because the credential never exists as a typeable string and the browser will not exercise it for the wrong origin. This is what "phishing-resistant" means technically: not a stronger secret, but no interceptable secret at all.

The Tanflow approach: passwordless as a platform capability

The Tanflow IAM Suite includes Passwordless and FIDO2 as a first-class authentication capability - phishing-resistant passkeys and hardware security keys - alongside its broader MFA options of TOTP authenticator apps and email/SMS OTP. Because authentication is centralised at the identity layer and applications federate over SAML 2.0, OAuth2 and OIDC, going passwordless is a platform decision rather than a per-application project: a user who authenticates to Tanflow with a passkey is passwordlessly authenticated to every federated application at once.

The coexistence of factor types is the practical point. Enterprises do not flip to passwordless in a day; they phase it. Tanflow's factor range lets policy match assurance to risk - FIDO2 for administrators, finance approvers and users touching regulated data; TOTP for the general population during transition; OTP where nothing stronger is yet enrolled - all enforced at one layer, all visible in one audit trail that records which factor authenticated which session. Privileged access follows the same arc: Tanflow PAM supports FIDO2 keys on the gateway itself, so the strongest factor guards the strongest access.

A phased adoption pattern

  1. Anchor the high-risk populations: enrol administrators and sensitive-data users with hardware keys or passkeys first - smallest group, largest risk reduction.
  2. Let policy enforce the floor: require FIDO2 for the applications and roles where phishing impact is worst, while others continue on TOTP.
  3. Expand by cohort: as devices and users are ready, extend passkey enrolment outward; the central platform makes each expansion a policy change, not a rollout.
  4. Retire the password's role: with strong factors primary, the password recedes toward a fallback - and eventually, for ready populations, out of the flow entirely.

Enterprise scenario

Consider an enterprise IT environment that has suffered two credential-phishing incidents in a year despite OTP being enforced - both via real-time relay pages. Moving its administrator and finance cohorts to FIDO2 keys through the Tanflow platform closes that specific technique for those users: the fake page can no longer harvest anything the genuine site will accept. The help-desk sees a second-order benefit within a quarter - the cohorts using passkeys stop generating password resets, because they have stopped using passwords.

Security and audit implications

Strong, phishing-resistant authentication increasingly appears in assessment conversations across the frameworks Tanflow maps its controls to, and the platform's audit trail supplies the evidence dimension: which users are enrolled in which factors, and which factor authenticated each recorded session. For the security architecture, FIDO2 at the identity layer hardens the exact control point everything else federates to - the highest-leverage single upgrade available in most estates.

Conclusion

Passwords are not failing for lack of policy; they are failing by design, and the phishing economy is built on that design. The Tanflow IAM Suite makes the structural fix deployable - FIDO2 passkeys and keys enforced centrally, phased by risk, evidenced in one trail - so the enterprise's most attacked secret can finally begin its retirement.

← All posts

See the platform behind the posts

Tanflow IAM Suite and PAM - on your infrastructure, live in 2-4 weeks.