Interview with Ashley BURKLE from Identiv AI: Between Potential and Uncertainty
Read more

HID Enables Enterprise Passkey Governance Without User Friction

  • Published: May 10, 2026
  • Read: 3 min
  • Source:

    Logo HID

Share:

HID Enables Enterprise Passkey Governance Without User Friction
HID Crescendo smart card used for secure passkey authentication and enterprise device verification. Source: HID

Enterprise Attestation in HID Crescendo FIDO authenticators gives organizations policy-level control over which devices can register passkeys — while keeping the user experience unchanged.

Passkeys Strengthen Login Security

HID has announced the availability of Enterprise Attestation in its FIDO authenticator portfolio, including HID Crescendo smart cards and security keys. The capability enables organizations to verify whether a passkey is being registered on a trusted, company-issued authenticator before the credential is accepted.

Passkeys are widely seen as a major step toward phishing-resistant authentication. They verify the user and reduce dependency on passwords. For enterprises, however, one important question remains: Can the organization trust the device that creates the passkey?

Enterprise Attestation Verifies the Device

Enterprise Attestation addresses this challenge. It allows companies to confirm the provenance of an authenticator at the point of enrollment. If the device cannot provide valid attestation data, registration can be blocked automatically by policy. If the device is recognized as company-issued and trusted, the passkey can be registered without additional steps for the user.

This gives security teams greater control over passkey governance, device traceability and authenticator lifecycle management. At the same time, employees continue to use passkeys in the normal way, without changes to the login experience.

Built into HID Crescendo Authenticators

The capability is built into HID’s FIDO2-certified Crescendo authenticators and is supported by identity platforms such as PingOne. It is based on FIDO Alliance standards, including WebAuthn and the Client to Authenticator Protocol, CTAP.

This standards-based approach enables organizations to strengthen authenticator governance without relying on proprietary authentication flows or changing application workflows.

HID Crescendo
W
ID Media

HID Crescendo

HID Crescendo secures enterprise access by replacing passwords with scalable, phishing-resistant authentication solutions.

Designed for Regulated Industries and NIS2 Requirements

For regulated sectors such as financial services, healthcare and critical infrastructure, Enterprise Attestation can support requirements around auditability, device provenance and lifecycle control. It also gives organizations operating under security frameworks and regulations such as the EU NIS2 Directive a practical way to strengthen authentication governance at the device level.

In a Zero Trust security model, access decisions should not only verify the user identity, but also the trustworthiness of the device involved. Enterprise Attestation supports this approach by helping organizations ensure that only approved, company-issued authenticators can be used to register passkeys.

EU NIS2 Directive Mandates Cybersecurity for Networked Systems
W
Story

EU NIS2 Directive Mandates Cybersecurity for Networked Systems

The NIS2 Directive institutes comprehensive, enterprise-wide cybersecurity obligations that integrate IoT systems, wireless technologies, edge devices, and supply chains into a cohesive, secure operational architecture.

Preventing the Use of Unmanaged Authenticators

A typical use case is an organization that wants to restrict passkey registration to approved authenticators. Without Enterprise Attestation, a personal security key could potentially be registered by an employee, even if it is not managed or issued by the company.

With Enterprise Attestation, the system checks whether the authenticator can present a certificate linking it to a known, company-issued device. If this proof is missing or unrecognized, enrollment is blocked.

Global Availability

HID Crescendo authenticators with Enterprise Attestation support are available globally now. Further information is available at: https://www.hidglobal.com/product-mix/crescendo

Want to learn how HID Crescendo authenticators with Enterprise Attestation can support secure passkey deployment in your organization?

Contact HID to discuss your requirements and find the right solution for enterprise authentication, device trust, passkey governance and compliance with security frameworks such as NIS2.


Contact and Company information

Released by
HID
Contact:
Richard Aufreiter