How can enterprises prevent passkey sharing across devices?

How to Stop Passkey Sharing Across Devices

As more organizations move toward passwordless authentication, many face a critical question: how can we prevent passkeys from being shared across personal or unmanaged devices? This concern is especially relevant for enterprises securing workforce access, where passkey portability could introduce compliance risks or unauthorized access.

Secfense addresses this challenge directly with Mobile-Bound Passkeys. This approach ensures that each credential is cryptographically bound to a single device and cannot be exported or reused elsewhere.

What Is a Mobile-Bound Passkey?

A mobile-bound passkey is a FIDO credential that is created and stored within a Trusted Execution Environment (TEE) on the user’s mobile device. Unlike syncable passkeys which can be backed up or transferred across platforms Secfense’s Mobile-Bound Passkeys are locked to a specific hardware component. This prevents unauthorized duplication or use on secondary devices.

What Security Guarantees Does Secfense Provide?

Secfense Mobile-Bound Passkeys provide four key assurances:

  1. Private key is generated within a secure environment.
    On Android, this uses the hardware-backed keystore; on iOS, it uses the Secure Enclave. The Trusted Execution Environment ensures that private key material is isolated from the main operating system.
  2. Private key never leaves the device.
    The key is non-exportable by design. It cannot be backed up, copied, or migrated—even by the end user.
  3. Device authenticity is verified.
    During registration, the device undergoes verification using WebAuthn attestation, which confirms that the key originates from genuine, trusted hardware.
  4. Credential integrity is tied to the Secfense Authenticator app.
    Beyond standard WebAuthn attestation, Secfense adds a layer of application-level integrity verification. This is achieved using platform-specific APIs:
    Play Integrity API on Android
    App Attest on iOS
    These APIs confirm that the credential originates from a legitimate, untampered version of the Secfense Authenticator app installed on a genuine device. A signed component of the WebAuthn registration flow is transmitted out-of-band and validated server-side before the credential is trusted.

These security controls are enforced during the credential creation ceremony and validated server-side, ensuring a consistent and verifiable trust model.

How Does WebAuthn Attestation Support This?

Secfense explicitly requests attestation during the WebAuthn credential registration process. Depending on the device:

  • On Android, we request the android-key format.
  • On iOS, we request the apple attestation format.

The attestation object is embedded in the WebAuthn response and includes device and key metadata. This data is validated by Secfense backend systems to ensure the key was generated on a verified device using supported secure hardware.

Why This Matters for Enterprises

For organizations adopting passkeys for workforce authentication, it is critical to:

  • Prevent credentials from being reused on unmanaged devices.
  • Maintain control over identity assurance levels.
  • Ensure that only verified, compliant devices are used for access.

Secfense enables this with minimal impact on existing infrastructure, though verifying credential integrity relies on integration with the Secfense Authenticator app and platform-specific attestation APIs. Mobile-Bound Passkeys from Secfense integrate seamlessly into existing identity flows while providing strong assurance and full policy enforcement.

Want to Learn More?

We’re happy to share more implementation details under NDA.

→ Contact a Secfense expert to discuss mobile-bound passkeys
→ Watch how BNP Paribas Bank rolled out passkeys at scale in just 3 months

Antoni takes care of all the marketing content that comes from Secfense. Read More

Testimonials

We are faced with new challenges every day. We must always be one step ahead of the attackers and know what they are going to do before they do it. We are convinced that the User Access Security Broker will bring security to a new level, both for those working at the office and from home. For us, working with Secfense is an opportunity to exchange experience with developers who put great value on out-of-the-box thinking.

Krzysztof Słotwiński

Business Continuity and Computer Security Officer

BNP Paribas Bank Poland

As part of the pre-implementation analysis, we verified that users utilize a wide range of client platforms: desktop computers, laptops, tablets, smartphones, and traditional mobile phones. Each of these devices differs in technological advancement, features, and level of security. Because of this, and also due to the recommendation of the Polish Financial Supervision Authority (UKNF), we decided to introduce additional protection in the form of multi-factor authentication mechanisms based on FIDO. As a result, users of our applications can log in safely, avoiding common cyber threats such as phishing, account takeover, and theft of their own and their clients’ data.

Marcin Bobruk

CEO

Sandis

We are excited to partner with Secfense to enhance our user access security for our web apps. By integrating their User Access Security Broker, we ensure seamless and secure protection for our applications and systems, delivering superior security and convenience to our customers.

Charm Abeywardana

IT & Infrastructure

Visium Networks

Before investing in Secfense, we had the opportunity to talk to its existing clients. Their reactions were unanimous: wow, it’s so easy to use. We were particularly impressed by the fact that implementing their solution does not require the involvement of IT developers. It gives Secfense a huge advantage over the competition, and at the same time opens the door to potential customers who so far were afraid of changes related to the implementation of multi-factor authentication solutions.

Mateusz Bodio

Managing Director

RKKVC

Even when the network and infrastructure are secured enough, social engineering and passwords can be used to gain control of the system by attackers. Multifactor authentication is the current trend. Secfense addresses this and allows you to build zero trust security and upgrade your current systems to passwordless applications within minutes, solving this problem right away,” said Eduard Kučera, Partner at Presto Ventures and cybersecurity expert – former Director in hugely successful Czech multinational cyber security firm Avast.

Eduard Kučera

Partner

Presto Ventures

One of the biggest challenges the world is facing today is securing our identity online. That’s why we were so keen to have Secfense in our portfolio. They make it possible to introduce strong authentication in an automated way. Until now, organizations had to selectively protect applications because the deployment of new technology was very hard, or even impossible. With Secfense, the implementation of multi-factor authentication is no longer a problem, and all organizations can use the highest standards of authentication security.

Stanislav Ivanov

Founding Partner

Tera Ventures