# SP-033 Passkey Authentication

Status: active. Release 26.02. Modified 2026-02-07. Licence: CC BY-SA 4.0.

Scope: Deep-dive pattern for implementing phishing-resistant passwordless authentication using FIDO2 WebAuthn and passkeys. Covers platform authenticators, roaming authenticators, synced passkeys, credential lifecycle, and enterprise deployment strategies.
Use when: This pattern is indicated for any organisation seeking to eliminate phishing as a viable attack vector against their users. It is particularly relevant for: financial services organisations facing sophisticated phishing campaigns, organisations subject to regulatory requirements for phishing-resistant MFA (US Executive Order 14028, PCI DSS v4.0 requirement 8.4.2), organisations with high-value accounts requiring...
Not when: Organisations whose user base primarily uses devices that do not support WebAuthn (legacy browsers, very old operating systems) cannot deploy passkeys without first upgrading the device estate.

## Controls (28, NIST SP 800-53 ids)
- Critical (7): AU-02, IA-02, IA-05, IA-12, SC-12, SC-13, SC-23
- Important (14): AC-01, AC-03, AC-06, AC-12, AU-03, AU-06, CA-02, CM-06, CP-02, IA-04, SA-08, SC-08, SC-17, SI-07
- Standard (7): AC-07, AC-14, AT-02, AU-09, IA-06, PL-02, PM-12

## What each critical control mitigates (7)
- AU-02 Event Logging: T-PA-006, T-PA-009
- IA-02 Identification and Authentication (Organizational Users): T-PA-001, T-PA-004, T-PA-007
- IA-05 Authenticator Management: T-PA-004, T-PA-005, T-PA-006
- IA-12 Identity Proofing: T-PA-006, T-PA-009
- SC-12 Cryptographic Key Establishment and Management: T-PA-002, T-PA-003, T-PA-005, T-PA-008
- SC-13 Cryptographic Protection: T-PA-002, T-PA-005, T-PA-008
- SC-23 Session Authenticity: T-PA-001, T-PA-007

## Threats and the controls that mitigate them (10)
- T-PA-001 Phishing attack redirecting to credential harvesting site: SC-23, IA-02, SC-08
- T-PA-002 Server-side credential database breach: SC-12, SC-13, AU-09
- T-PA-003 Credential cloning from compromised authenticator: SI-07, SC-12, AU-06
- T-PA-004 MFA fatigue/bombing attacks on push notification: IA-02, IA-05, AU-06
- T-PA-005 SIM swapping to intercept SMS-based MFA: IA-05, SC-12, SC-13
- T-PA-006 Recovery process exploitation for account takeover: IA-12, IA-05, CP-02, AU-02
- T-PA-007 Adversary-in-the-middle real-time phishing proxy: SC-23, SC-08, IA-02
- T-PA-008 Platform sync mechanism compromise exposing synced passkeys: SC-12, SC-13, CM-06, AC-01
- T-PA-009 Rogue authenticator registration by insider or social engineering: IA-12, AU-02, AC-03, PM-12
- T-PA-010 Downgrade attack forcing fallback to phishable authentication: AC-01, CM-06, SA-08, AU-06

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-033/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-033/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 29 KB: /api/v1/patterns/SP-033
- Page for people: /patterns/sp-033/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
- Related: SP-010 Identity Management Pattern; SP-029 Zero Trust Architecture; SP-032 Modern Authentication

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
