FB pixel

Advancing digital security with passwordless MFA

The global push for cybersecurity without compromise is clear
Categories Access Control  |  Biometrics News
Advancing digital security with passwordless MFA
 

Recent announcements from Yubico, OneSpan, Amazon Web Services (AWS), and the New York Department of Financial Services (NYDFS) highlight an industry-wide commitment to a frictionless digital future that will see emerging cyber risks addressed.

Yubico passwordless enrollment suite for Microsoft users

Yubico has introduced the Yubico enrollment suite designed to simplify passwordless onboarding for Microsoft environments, including Yubico FIDO [re-reg and the company’s new YubiEnroll. These systems integrate with Microsoft’s Entra ID for organizations looking to create stronger cyber resilience with a Zero Trust model.

The turnkey tool aims to mitigate vulnerabilities associated with traditional passwords for organizations to implement phishing-resistant authentication. The enrollment suite integrates with Microsoft Azure active directory and leverages FIDO2 technology.

“Microsoft and Yubico have collaborated for years to ensure that businesses worldwide can protect their identities from increasingly sophisticated cyber threats like phishing,” says Nitika Gupta, partner group product manager at Microsoft.

“With the integration of Yubico enrollment suite and Microsoft Entra ID’s FIDO provisioning, we empower our customers to create phishing-resistant users and fully secure the employee lifecycle, from onboarding to authentication and account recovery. Our customers can now achieve the security and flexibility they need to protect their enterprise resources with phishing-resistant YubiKeys.”

Microsoft partners elsewhere are utilizing Entra ID with biometrics, FIDO2, and MFA integration.

Yubico and Okta unveiled the industry’s first tool for pre-registering YubiKeys with Yubico FIDO Pre-Reg, tailored for Okta users. As a result, Yubico is now extending the capability to Microsoft customers through the Yubico enrollment suite, offering limited early access for organizations using Microsoft Entra ID.

OneSpan, Ping Identity forge frictionless digital experiences

Meanwhile, OneSpan has partnered with Ping Identity on digital workflows with streamlined identity verification and multi-factor authentication (MFA). The collaboration integrates OneSpan’s adaptive, FIDO-enabled authentication technology with Ping Identity’s single sign-on platform, reducing friction while maintaining security measures.

“OneSpan is excited to join forces with Ping Identity to enhance the security landscape by delivering the most secure and user-friendly authentication solutions that protect our customers against today’s evolving cyber threats,” says Giovanni Verhaeghe, senior vice president of corporate and business development at OneSpan.

“By partnering with Ping Identity, we’re making it easier for organizations to leverage high assurance hardware-based authentication with Ping Identity’s market-leading identity management solutions.”

AWS expands centralized security controls for MFA compliance

In a parallel development, AWS has bolstered its centralized security controls to meet expanding multi-factor authentication (MFA) requirements. This initiative aligns with the platform’s “secure by design” ethos, offering tools like AWS Identity and Access Management (IAM) to enforce MFA policies across multiple accounts.

AWS says in a written blog post that “We also guard against setting weak passwords, never suggest default passwords for users to use, and when we detect unusual sign-in activity for customers who haven’t yet enabled MFA, we validate the sign-in with one-time PIN challenges to their primary email address. Despite these measures, passwords alone remain inherently risky.”

Starting in Spring 2025, AWS will require customers to enable multi-factor authentication (MFA) for root users in member accounts under AWS Organizations to access the AWS Management Console, unless central root access management is already in place.

DFS highlights role of MFA in combating AI-driven cyber threats

Adding to the dialogue, the New York state Department of Financial Services (DFS) has issued new guidance addressing the cybersecurity risks posed by artificial intelligence (AI), urging entities under its regulation to bolster their defenses. A key recommendation includes the deployment of Multi-Factor Authentication (MFA) systems to combat the rising tide of AI cyber threats, such as deepfake-driven social engineering attacks.

DFS underscores MFA as a critical measure to mitigate these threats. By requiring users to authenticate their identities using at least two of three factors, knowledge (password), inherence (biometric), and possession (security token), MFA reduces the likelihood of unauthorized access.

From November 2025, DFS will mandate that all regulated entities implement MFA across their systems, covering employees, contractors, and third-party service providers. The guidance urges organizations to adopt well-rounded MFA technologies capable of resisting AI attacks, such as digital certificates, physical security keys, and biometrics enhanced with liveness detection.

Related Posts

Article Topics

 |   |   |   |   |   |   |   | 

Latest Biometrics News

 

Certification becoming trust signal for procurement and market positioning

One consequence of the explosion of synthetic media and AI-generated identities is that trusted identity infrastructure has become strategically valuable…

 

IAD testing set to take off as QTSP deadline passes, EUDI Wallet onboarding begins

Independent assessments of biometric injection attack detection (IAD) are about to become significantly more prominent, with the deadline for Qualified…

 

UK’s proposed OS-level age verification could eliminate part of DVS market

The UK government is mooting device-level restrictions on nude images that could usher in a new era of a kid-friendly…

 

UK promises age assurance for social media, device-level child safety controls

How many times can a head of government pledge to do something about harmful social media platforms before they’re obligated…

 

Aware upgrades biometric orchestration platform with ROC, Mitek integrations

Aware has added ROC and Mitek as biometric technology partners for its digital identity orchestration platform, Awareness, as part of…

 

Appeals board upholds 4 FaceTec biometric liveness detection patents

The U.S. Patent Trial and Appeal Board (PTAB) has ruled in a fight over intellectual property for biometric liveness detection between…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events