Credential theft is now one of the fastest-growing cyber threats, making phishing-resistant, passwordless authentication essential for modern organizations.
Recent research shows that,
67% of organizations report an increase in credential theft and misappropriated secrets Thales Data Threat Report 2026), confirming that compromised identities have become a primary attack vector across cloud environments.
At the same time, phishing has emerged as the #2nd most common cyberattack affecting organizations worldwide (Thales Data Threat Report 2025).
With deep-fake-driven misinformation on the rise and cloud environments remaining primary targets, attackers can more easily capture credentials through phishing and social engineering. As AI behaves like an insider with the ability to discover and access large volumes of data, weak authentication further increases the risk of unauthorized access and sensitive data exposure. In this context, traditional password-based security is no longer sufficient. Organizations must adopt modern, phishing-resistant authentication approaches that eliminate shared secrets and prevent credential-based attacks at their source.
Thales FIDO2 security keys deliver strong phishing resistant authentication that helps organizations close critical security gaps. Built on FIDO2 and WebAuthn standards, these hardware-based devices eliminate passwords and protect against credential theft and phishing attacks. They work seamlessly across clouds, on premises, and hybrid environments, providing a fast and consistent login experience for users. With enterprise grade scalability and simplicity, Thales FIDO2 keys strengthen compliance, reduce risk, and secure access to sensitive systems without adding friction.
Explore our Thales FIDO2 keys that eliminate passwords and protect against today’s most sophisticated threats.
What Are FIDO2 security keys and How Do They Work?
FIDO2 security keys are physical devices that enable users to log in without passwords. They rely on public key cryptography, ensuring that the user’s credentials can’t be intercepted or reused by attackers.
FIDO (Fast Identity Online) is the umbrella term for FIDO Alliance's newest set of specifications.
The FIDO2 standard is made up of two key components:
- WebAuthn (Web Authentication API): allows web apps to register and authenticate users with a cryptographic key
- CTAP2 (Client to Authenticator Protocol): let external authenticators like USB keys or NFC devices interact with browsers and operating systems
How it works:
- A private key is generated and stored securely on the device.
- When logging in, the site sends a challenge.
- The user interacts with the key (touch, tap, or fingerprint), which signs the challenge locally.
- The signed challenge is sent back and verified using the public key. No password ever travels over the network.
FIDO2 security keys support all major platforms and browsers, and work through USB-A, USB-C, NFC, or biometrics.
- Phishing-resistant
- Fast and user-friendly login
- No shared secrets, no passwords
Why Enterprises Choose FIDO2 Authentication for Strong Authentication
Modern organizations choose FIDO2 authentication to secure remote and on-site access, deliver seamless passwordless login experience, and reduce the risk of security breaches. Built on phishing-resistant MFA and open security standards, FIDO2 offers a future-proof solution for enterprise authentication.
Phishing-Resistant MFA
FIDO2 uses asymmetric public key cryptography to bind each private key to a verified service domain. If the service is fraudulent, authentication fails instantly, protecting against phishing attacks and credential theft.
User-Centric Passwordless Authentication Method
Users can log in quickly without passwords by tapping a FIDO2 security key or using a fingerprint. This passwordless authentication method increases adoption, improves user satisfaction, and eliminates the burden of remembering credentials.
Flexible Form Factors for Every Environment
FIDO2 is available as USB-A keys, USB-C security keys, NFC-enabled keys, biometric tokens, and smart card authentication options. These formats support contactless and traditional login, enabling authentication from mobile devices, desktops, and shared workstations.
Phishing-Resistant MFA
FIDO2 uses asymmetric public key cryptography to bind each private key to a verified service domain. If the service is fraudulent, authentication fails instantly, protecting against phishing attacks and credential theft.
User-Centric Passwordless Authentication Method
Users can log in quickly without passwords by tapping a FIDO2 security key or using a fingerprint. This passwordless authentication method increases adoption, improves user satisfaction, and eliminates the burden of remembering credentials.
Flexible Form Factors for Every Environment
FIDO2 is available as USB-A keys, USB-C security keys, NFC-enabled keys, biometric tokens, and smart card authentication options. These formats support contactless and traditional login, enabling authentication from mobile devices, desktops, and shared workstations.
Thales FIDO2 Security Keys benefits
Thales multi-factor authentication devices use current and emerging protocols to support multiple applications at the same time. Use one security key that combines FIDO2, WebAuthn, U2F, and PKI to access both physical spaces and logical resources.
Best in class security
Thales controls the entire manufacturing cycle and develops its own FIDO crypto libraries, which reduces the risk of being compromised.
Support for multiple use cases
- Combine FIDO, PKI and physical access in a single device
- Experience a strong authentication from mobile endpoints
User convenience for better adoption
- Support for biometric (fingerprint on smart card)
- Sensitive presence detector on USB FIDO key
Compliant with high security market standards
- U2F and FIDO2 certified
- Compliant with US and EU regulations for phishing-resistant authentication
- Manufacturing in Europe and Trade Agreement Act (TAA) compliancy in option
- FIPS and CC certified for PKI operations
Robustness & Scalability for a long-life duration
- Hard molded plastic, tamper evident USB FIDO keys
- No damage to USB ports thanks to sensitive presence detector
- Support for firmware updates for better maintenance and upgradability
Enterprise FIDO Ready
- Comply with FIDO2.1 specifications
- Benefit from Thales FIDO Enterprise features
- Use SafeNet FIDO key Manager for free
Thales FIDO Security Keys and Devices
Thales offers a range of FIDO2 security keys to meet the needs of diverse enterprise environments. From mobile and frontline workers to high assurance use cases, all keys are designed for seamless integration.
FIDO USB Tokens
Secure access to web applications and devices using FIDO
SafeNet eToken FIDO series
- Ideal solution for organizations to go passwordless
- Compact, tamper-evident USB tokens, available in type A and C
- Presence detection sensor to confirm human presence
- Ideal for privilege users, frontline and temporary workers
- Quick access for employees to any shared device such as PC or tablet
FIDO + Biometric
Simplify user adoption.
SafeNet IDPrime FIDO Bio Smart Card
Combining biometrics and NFC, the innovative SafeNet IDPrime FIDO Bio Smart Card allows end users to authenticate from multiple types of devices securely and easily, with just a fingerprint instead of a password.
FIDO + PKI Smart Cards
Extend modern FIDO authentication to PKI use cases.
SafeNet IDPrime FIDO Smart Cards series
- New generation of PKI smart cards
- Facilitates cloud migration and authentication modernization
- Support FIDO and PKI use cases: authentication, digital signature, and file encryption
- One single badge for securing access to legacy apps, network domains and cloud services
- Use on multiple devices from desktops to tablets thanks to NFC
- Help organizations to meet their market regulations
FIDO + PKI USB Tokens
Extend modern FIDO authentication to PKI use cases.
SafeNet eToken Fusion Series
- New generation of PKI USB Tokens
- Facilitates cloud migration and authentication modernization
- Support FIDO and PKI use cases: authentication, digital signature, and file encryption
- One single token for securing access to legacy apps, network domains and cloud services
- Use on multiple devices from desktops to tablets thanks to NFC option
- Help organizations to meet their market regulations
- “Enterprise FIDO ready” in option to help organizations control their life cycle
FIDO + physical access
Combine digital access with physical access.
Thales offers organizations smart cards combining physical access with digital PKI/FIDO authentication. Converged Badge is an ideal solution for organizations who need to protect access to secure areas and sensitive digital resources. Cost of badge deployment and fleet management are significantly reduced and the adoption by employees is facilitated.
Manage FIDO Keys
Control your FIDO keys’ life cycle thanks to Thales FIDO Enterprise Features.
Thales FIDO enterprise features allow organizations to manage their FIDO keys securely and easily throughout their life cycle. They add an administration layer and configuration policies to help IT teams deploy, administer, and support the end user. Beyond the FIDO Alliance FIDO2.1 specifications, Thales FIDO enterprise features offer organizations:
- Better security - enforcing user verification during authentication from any device, managing the minimum PIN length and protecting the PIN policy set, preventing data in fido keys from malicious or non-intentional deletion
- Appropriate usage of organization assets - limiting the usage of the FIDO authenticators to a list of preferred services
- Reduced IT costs & better User Experience - unblocking the FIDO key without resetting all key data, allowing end users to set and change their PIN code in self-service
Learn more about Thales FIDO Enterprise Features supported by SafeNet FIDO Key manager, Versasec Credential Management System and OneWelcome FIDO Key Lifecycle Management Solution.
Where Thales FIDO2 Security keys Fits
Thales FIDO2 keys are versatile and adaptable, supporting multiple use cases across industries and access types.
Windows Logon
Secure access to desktops with just a fingerprint or a tap; no password needed.
Modern Web App Login
Authenticate enterprise apps from both desktops and mobile devices.
Benefits from the PKI usages
Secure, sign or encrypt sensitive documents and emails with the same security key
Physical Access
Secure, contactless access to buildings and restricted areas using the same FIDO security keys that protect digital logins unifying physical and digital access in a single credential.
Typical users : Where Thales FIDO2 Security keys Fits
Frontline Workers
Quick access to shared desktops with no PINs to remember
Employees
Simple and intuitive, no apps to install, no learning curve. Fingerprint-based authentication get users on board faster
VIPs & High-Sensitivity Roles
For those who demand premium, secure access to critical systems and data with biometric
Office & Mobile Workers
Whether in the office or on the go, users can
Main industries:
- Ideal for government, Manufacturing, BFSI sectors visuals for each
- Include internal links to industry-specific case study, e.g.: or blog on the industry
Compatibility and integrations:
- Compatible with multiple services such as Identity providers , online services , management system.
- Cloud IAM Integration: Works with Microsoft Entra ID, Okta, Ping, Google Workspace.
Pair seamlessly with SafeNet Trusted Access for cloud access control
Secure access to Microsoft 365 and Windows devices
Thales and Microsoft partner to provide Microsoft 365 customers with FIDO and certificates-based authentication (CBA).
With the Entra ID, Microsoft customers can use Thales X.509 certificate-based Tokens, Smart cards, and FIDO authenticators for all their identity protection needs.
All the Thales FIDO security keys (tokens or smart cards) are fully compatible and integrated with Microsoft Entra ID.
For more information about Thales FIDO2 Security Keys for Microsoft Environments, watch the Video Demo, read our Solution Brief and download the Installation Guide. Check our offer on Azure Marketplace.
Partner with an Identity Trailblazer
Awarded 2024 Identity Trailblazer by Microsoft Security, Thales is the sole vendor offering USB-C and USB-A FIDO security keys with Microsoft Security logo on one side. They are ideal for protecting cloud services and windows logon.
Enterprise Deployment: Centralized and Decentralized Key Management
Thales offers lifecycle management:
- Centralized: Enroll and issue FIDO keys on premise using oNE WELCOME KEY LIFECYCLE MANAGMENT or on the cloud with Authenticator Lifecycle Management
- Decentralized: Let users self-register and manage their PIN or credentials locally
Both models reduce IT friction while maintaining full lifecycle control. SafeNet FIDO Key Manager
Learn more about Thales FIDO Enterprise Features supported by SafeNet FIDO Key manager, Versasec Credential Management System and OneWelcome FIDO Key Lifecycle Management Solution, Authenticator Lifecycle Management.
Integration Guide & Compatibility and Ecosystem
Thales FIDO2 security keys integrate natively with major identity platforms and support all leading authentication standards.
- Browsers: Chrome, Firefox, Safari, Edge
- Platforms: Windows, macOS, Linux, Android, iOS
- IAMs: Okta, ENTRA AD, Ping Identity, ForgeRock, SailPoint
- Protocols: FIDO2, U2F, WebAuthn, CTAP
Recommended resources
Yes, they are compatible with major IAMs like Azure AD, Okta, and SafeNet Trusted Access.
You can re-issue a device or configure backup keys. Thales also offers key management tools for recovery.
Yes — several Thales keys meet FIPS 140-3 and other international standards.
- Consider adding more FAQs to hit long-tail keywords:
- “Are FIDO2 keys better than authenticator apps?”
- “Can I use a single key for multiple accounts?”
- “How secure are biometric FIDO keys?”
- Use FAQ schema markup for SEO