What is FIDO2?
FIDO2 is a set of open authentication standards that enables passwordless, phishing-resistant authentication using public-key cryptography instead of reusable passwords or shared secrets. FIDO2 combines the W3C WebAuthn standard with the FIDO Alliance Client to Authenticator Protocol (CTAP), enabling websites and applications to authenticate users with passkeys and FIDO security keys.
FIDO authenticators can be built into a device or provided as external hardware. Thales delivers hardware FIDO2 keys designed for enterprises, regulated industries, and complex authentication environments.
67 %
of organizations report an increase in credential theft and misappropriated secrets. Phishing has emerged as the #2 most common cyberattack affecting organizations worldwide.
Traditional passwords and MFA are no longer sufficient.
Source: Thales Data Threat Report
Why enterprises choose FIDO security keys
Organizations are adopting hardware FIDO2 devices and security keys to reduce reliance on passwords, strengthen phishing-resistant authentication and give users secure ways to access applications and devices across a wide range of work environments.
Passwordless convenience
Replace passwords with simple authentication using a FIDO security key and local user verification such as a PIN, touch or biometric. This simplifies sign-in while reducing users' reliance on passwords that must be created, remembered and reset.
Phishing-resistant by design
FIDO2 uses public-key cryptography and binds authentication credentials to the legitimate service. A fraudulent domain cannot use a credential created for another service, helping protect users against phishing attacks.
Protect credentials with hardware
With hardware FIDO security keys, private cryptographic keys remain protected by the authenticator instead of being transmitted to the online service, reducing exposure to credential theft and man-in-the-middle attacks.
Authenticate anywhere
Support different users and work environments with FIDO devices available in USB-A, USB-C, NFC, smart card and biometric form factors for laptops, mobile devices and shared workstations.
Built on open standards
FIDO2 uses open authentication standards supported across modern browsers, operating systems and online services, helping organizations extend phishing-resistant authentication across diverse environments.
Flexible for enterprise use cases
Use FIDO security keys for different workforce requirements, including privileged users, frontline employees, shared-device environments and users who need portable authentication across multiple systems.
Thales FIDO2 security keys benefits
Thales FIDO2 devices and security keys support multiple authentication requirements across the enterprise. Depending on the selected authenticator, organizations can combine FIDO2, WebAuthn and PKI to secure access to modern cloud applications, legacy resources and physical environments.
The right key for every user
Choose the form factors that fit how your teams work - whether they are on mobile, laptops, shared desktops, or in air-gapped environments.
With a single key, seamlessly combine physical access with digital access to both modern cloud and legacy resources.
Decades of technology innovation, built into every key
Phishing resistance is just the starting point. Thales backs every key with over 40 years of enterprise cybersecurity expertise, security-by-design engineering, and highly secure global supply chain, from manufacturing to delivery.
Roll out at scale without hassle
End users receive FIDO keys ready to use. This reduces setup errors and simplifies onboarding, allowing you to deploy phishing-resistant MFA across global teams in days.
Full lifecycle control
Manage FIDO keys throughout their life cycle, from activation to revocation, thanks to Thales Authenticator Manager Suite, management tools that let you configure, register, unlock and revoke keys instantly.
Eliminate the overhead of managing a physical fleet at scale and ensure the right key is used by the right user to access the right data.
Security that carries your brand
Reinforce organisational trust from day one. Deliver custom-branded security keys and packaging that match your corporate identity, improve user adoption, and make secure authentication feel like a native part of your workspace experience.
Sustainability without compromise
Protect your data while protecting the planet. Directly support your corporate ESG goals with security keys delivered in plastic-free packaging and lower impact material.
Meet global compliance standards with certified keys
Find the best FIDO2 security keys for your needs
Thales offers a broad range of FIDO2 devices, security keys, and authenticators designed for different passwordless authentication journeys, user populations, devices, and enterprise requirements.
Go passwordless with SafeNet eToken FIDO series
Compact, tamper-evident USB tokens supporting FIDO2, available in USB Type-A, USB Type-C, and optional NFC models. Ideal for organizations replacing passwords with FIDO-based authentication across web applications, network domains, and shared-device environments.
Extend modern FIDO authentication to PKI use cases with SafeNet eToken Fusion series
Support both FIDO and PKI-based authentication for modern and legacy applications, network domains, digital signatures, and file encryption. NFC support enables use across multiple device types, while certifications help organizations address regulatory requirements.
Extend modern FIDO authentication to PKI use cases with SafeNet IDPrime FIDO Smart Cards
Support both FIDO and PKI use cases for secure access to modern and legacy applications, network domains, digital signatures, and file encryption. NFC support enables use across desktops and tablets, with certifications that help meet regulatory requirements.
Combine digital access with physical access with SafeNet IDPrime FIDO Smart Cards series
Thales offers organizations smart cards combining physical access with digital PKI/FIDO authentication. Converged Badge is an ideal solution for organizations who need to protect access to secure areas and sensitive digital resources. Reduce the cost of badge deployment and fleet management while increasing employee adoption.
Boost FIDO adoption with biometric authentication
Enable users to authenticate securely and easily across devices using a fingerprint instead of a password or PIN. Choose from biometric smart card and USB token options designed to simplify the user experience while strengthening phishing-resistant authentication.
Simplify FIDO Deployment at Enterprise Scale
With Thales Enterprise Edition security keys in combination with dedicated management tools, Thales allow organizations to manage their FIDO keys securely and easily throughout their life cycle. They add an administration layer and configuration policies to help IT teams deploy, administer, and support the end user.
Manage your FIDO keys throughout their lifecycle
While the FIDO standard delivers strong authentication, enterprises also require centralized lifecycle management, policy enforcement, and operational control. The Thales Authenticator Manager Suite helps organizations deploy, manage, unlock, and revoke FIDO credentials across the enterprise.
SafeNet FIDO Key Manager
Ideal for decentralized small- and mid-sized deployments, enabling users and administrators to manage FIDO credentials with ease.
Thales Authenticator Lifecycle Manager
Designed for large-scale, centralized deployments that require enterprise-wide visibility and control.
Secure access to Microsoft 365 and Windows devices
Thales and Microsoft partner to provide Microsoft 365 customers with FIDO and certificates-based authentication (CBA). Thales FIDO security keys provide organizations with a hardware-based option for deploying phishing-resistant authentication across supported Microsoft Entra ID and Windows environments.
With the Entra ID, Microsoft customers can use Thales X.509 certificate-based Tokens, Smart cards, and FIDO authenticators for all their identity protection needs.
We chose Thales for their long-standing experience in strong authentication as well as for the richness of their authentication key management tools.”
Recommended resources
Explore KuppingerCole’s Passwordless Authentication Leadership Compass Reports
See why KuppingerCole named Thales a Leader in both the Enterprise and B2C Passwordless Authentication Leadership Compass reports, and learn how a portfolio-based approach can help organizations scale passwordless authentication across workforce, partner, and customer identity journeys.
What is a FIDO2 security key?
A FIDO2 security key is a portable hardware authenticator that enables passwordless, phishing-resistant access to supported websites, applications, and devices. It uses FIDO2 standards developed by the FIDO Alliance and W3C, relying on public-key cryptography instead of reusable passwords or shared secrets.
FIDO2 security keys can be available in form factors such as USB tokens and smart cards, with options including NFC and biometrics. They are commonly used by enterprises to strengthen authentication for workforce users, privileged accounts, shared devices, and other high-assurance access scenarios.
How does FIDO2 authentication work?
FIDO2 authentication lets users sign in without relying on a reusable password. Instead, the user authenticates with a FIDO authenticator, such as a security key or passkey, and confirms their presence or identity with a touch, PIN, or biometric.
Behind the scenes, the authenticator uses public-key cryptography to respond securely to the service requesting authentication. Because the private credential remains protected by the authenticator and authentication is bound to the legitimate service, FIDO2 helps protect against phishing and credential theft.
How do you use a FIDO2 security key or token?
Using a FIDO2 security key is designed to be simple. When prompted by a website, application, or identity service, the user connects or presents the security key and confirms the authentication request.
For a USB security key, this may mean inserting the key into a USB port, touching the presence sensor, and entering a PIN if required. With an NFC-enabled or biometric authenticator, the user may instead tap the key or smart card against a compatible device and confirm their identity with a fingerprint.
For example, with the SafeNet FIDO Bio Smart Card, a user can tap the card against a compatible NFC-enabled device while verifying with a fingerprint to complete authentication.
Is FIDO2 authentication phishing-resistant?
Yes. FIDO2 authentication is designed to resist phishing by using public-key cryptography and credentials that are bound to the legitimate service. A fraudulent website cannot successfully use a credential created for another domain.
With hardware FIDO2 security keys, the private key also remains protected by the authenticator rather than being transmitted to the online service. This helps protect users against phishing, credential theft, and man-in-the-middle attacks.
Cybersecurity authorities and standards bodies including NIST, ENISA, ANSSI, and the Dutch NCSC recognize phishing-resistant approaches based on public-key cryptography, including FIDO authentication and certificate-based authentication (CBA). These approaches avoid the reusable shared secrets that make traditional passwords and many legacy MFA methods vulnerable to phishing.
Are FIDO2 tokens compliant with regulatory standards?
Yes, FIDO2 tokens embrace the protection of personal data based on public key cryptography. FIDO2 meets the requirements of the US administration and the EU security agencies for strong MFA. Hardware FIDO security keys are evaluated AAL3 by NIST (Assurance Level 3 , the highest level of Assurance in Authentication according to NIST).
What are the benefits of using FIDO2 over traditional passwords?
There are different benefits of using FIDO2 over traditional passwords:
- Security: unique login credentials across every website which are never stored on a server, eliminating the risk of phishing and other forms of attacks.
- User experience: user login with simple built-in methods on the device or by leveraging easy-to-use FIDO2 security keys.
- Privacy: unique keys for each internet site that cannot be used to track users across sites. Biometric data, when used, never leaves the user’s device.
- Scalability: enable FIDO2 through simple API calls supported across all leading browsers and platforms.
What are passkeys in FIDO2?
Passkeys are FIDO credentials that replace passwords for signing in to websites and applications. They use public-key cryptography and are designed to provide phishing-resistant authentication without relying on reusable shared secrets.
Passkeys can be synced passkeys, which can be securely made available across a user's device ecosystem, or device-bound passkeys, which remain associated with a specific authenticator.
FIDO2 security keys vs. passkeys
FIDO2 security keys are portable hardware authenticators that can securely hold device-bound FIDO credentials. Unlike synced passkeys, which prioritize convenient access across a user's device ecosystem, hardware security keys keep credentials bound to the authenticator.
This can make security keys well suited for enterprise use cases involving privileged users, shared workstations, regulated environments, or users who cannot rely on a personal mobile device. Organizations may use both synced passkeys and hardware security keys based on user, risk, and operational requirements.
How can I choose the FIDO keys that fit my organization's needs?
To select the key that fits your needs, consider the devices used and their connection modes (contact, contactless), the operations run (signature, physical or digital access) and the way to authenticate (PIN or biometrics). Questions you need to answer:
- Are the devices equipped with USB ports or card readers? Do they support wireless NFC?
- Do all the accessed digital resources support FIDO? If not, do they support PKI certificate-based authentication?
- Do my end users need to sign digital documents, encrypt sensitive emails or files?
- Do my end users access secured areas that require physical access control?
- Should we consider offering usage of biometrics instead of a PIN to simplify the end user’s experience?
Can FIDO2 tokens be used with mobile devices?
Yes, FIDO2 tokens can be used with any mobile device. However, depending on the connector of the token (USB-C or USB-A), the user may need to use an adaptor. If the token and the device are compatible with NFC, the user can also use the NFC capability directly by tapping the token to the back of its mobile device.
How do I set up a FIDO2 token?
Thales FIDO2 devices are ready to use and require no software or driver installation. You can set up your FIDO2 token by registering it to an online service. Set-up instructions may differ from one service provider to another, so follow the instructions displayed on the user interface. Generally, the service provider asks you to define your login name, a PIN code and put a name to the registered FIDO2 Token. Alternatively, you can use SafeNet FIDO Key Manager to set up and change the PIN of your Thales FIDO2 Token.
Are FIDO2 tokens compatible with all online services?
FIDO2 tokens are compatible with all online services that support the FIDO2 standard.
You can look at our page of FIDO compatible services for more information.