Extending phishing-resistant authentication to external users remains one of the most difficult challenges in identity security. While hardware keys and passkeys offer strong protection, practical barriers—such as cost, user adoption, and usability—often hinder widespread implementation.
This session will explore strategies for enabling phishing-resistant access for all users, including external identities, without compromising user experience or scalability. Using recent implementation experiences as a reference point, we’ll examine how modern approaches can reduce reliance on passwords and strengthen defenses against credential-based attacks.