Step-by-step procedure and considerations for passkey deployment

Step-by-step procedure and considerations for passkey deployment

Source: YouTube · FIDO Alliance · published Feb 6, 2025 · 23:09

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Passkey deployment requires careful execution across planning, implementation, and operations to effectively balance enhanced phishing resistance with improved user usability. [00:45](#)

Key Takeaways:
• In the planning phase, accurately define ROI by comparing security and usability benefits against deployment costs, and evaluate whether to build in-house or use external services. [01:30](#)
• During implementation, improve usability by leveraging the WebAuthn Signal API to sync account data and using Related Origin Requests to enable single sign-on across varied domains. [05:20](#)
• Mitigate unique security risks such as credential sharing and provider compromise by utilizing device-bound passkeys, AAGUID verification, and step-up authentication. [08:10](#)
• Facilitate user adoption through phased rollouts, clear communication, support staff training, and a transition plan that securely phases out legacy passwords. [11:45](#)

Implementing passkeys is an ongoing commitment that requires continuous testing of new OS features and adapting to evolving industry standards. [14:00](#)

Sources:

  • [00:45](#) Introduction to passkey deployment phases
  • [01:30](#) Planning considerations: ROI and build vs. buy
  • [05:20](#) Usability implementation: Signal API and Related Origins
  • [08:10](#) Security implementation: Risks and mitigations
  • [11:45](#) User adoption, phased rollouts, and legacy transition

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

how you all doing excellent it's always good to get a bit of a response that's nice um so welcome to this track uh really appreciate your time want to say hi to all the folks online as well we're delighted to have you um we're going to get started in just a second I just want to take the opportunity to remind you if you add this session uh in your um app then you'll be able to do the online survey afterwards which is uh really helpful for everyone so please be constructive with your comments um but we do appreciate that feedback um we're not going to have the opportunity to take any questions in this particular session but itak kurang is going to make her contact details available so if you have followup please feel free to reach out to her directly afterwards um and with that I'm delighte…