Create phishing-resistant users and accelerate your enterprise to passwordless
Download resourcesAbout this session
Jeff Frederick, Senior Director of Solutions Engineering for public sector at Yubico, argues that phishing-resistant authentication (PKI/smart card and FIDO) must be extended to the moments where it usually breaks down: onboarding, device registration and account recovery. His fix is the 'phishing-resistant user': admins pre-enroll a YubiKey before day one so a new hire never touches a phishable password-and-MFA flow. He walks through two products that do this, FIDO Pre-Reg (factory-provisioned, subscription-based, integrated with Okta today and Microsoft Entra ID in preview, cited in an Okta rollout of 6,000 keys across 42 countries) and YubiEnroll (an on-premise tool for smaller organizations to register keys locally), then shows how the same key can carry a PKI certificate for enterprises with internal certificate authorities. A long Q&A covers lost-key recovery, YubiKey durability and lifecycle, hardware versus software passkeys and attestation, resident credential limits, air-gapped and OT use with static passwords, government union pushback and Canada's LOA3 assurance requirement, and adoption strategies starting with privileged users and executives.
Passwordless authentication can significantly reduce the risk of breaches and phishing attacks by eliminating passwords altogether from the equation. And device-bound passkeys offer a way to accelerate to passwordless as more organizations consider the move away from passwords and broken MFA and towards enhanced security and operational benefits with phishing-resistant MFA. But modern organizations are increasingly thinking past phishing-resistant authentication as a technology and are instead laser focused on the user. Strong authentication and going passwordless starts and ends with the user and phishing-resistant users in turn create phishing-resistant enterprises that can accelerate to enhanced security and operational efficiency, all within a modern passwordless environment.
Key takeaways
- Extend phishing-resistant authentication to onboarding, device registration and account recovery, not just day-to-day login, since those are the moments attackers target most.
- Use factory or admin-side pre-enrollment (FIDO Pre-Reg or an on-premise tool like YubiEnroll) so a new employee's first login is already phishing-resistant, cutting help-desk setup calls.
- For high-security environments prefer attestable hardware keys over software/syncable passkeys, since only hardware attestation can prove the private key was generated on a genuine device.
- Check your assurance-level requirement (e.g. Canada's LOA3) before choosing an authenticator; SMS, push apps and most software passkeys fall below that bar.
- Roll out hardware keys first to privileged users, IT admins and executives to prove the workflow before a wider enterprise rollout.
Speakers

Jeff Frederick is the Director of Solutions Engineering for Public Sector at Yubico, Inc. Jeff has over 30 years of experience in the area of Identity, Credential, and Access Management (ICAM) with Public Sector organizations as well as Commercial… Read moreRead less
Jeff Frederick is the Director of Solutions Engineering for Public Sector at Yubico, Inc. Jeff has over 30 years of experience in the area of Identity, Credential, and Access Management (ICAM) with Public Sector organizations as well as Commercial customers. In addition, he has extensive experience in various Cybersecurity domains. In his current role, Jeff assists Public Sector customers in developing and implementing strong Multi Factor Authentication solutions to protect their Information Technology assets and data. He helps customers develop strategies for topics such as: Identity Proofing, Identity and Credential Lifecycle, Authentication, Authorization, and Compliance.
