Passkey adoption lags as security pros still use passwords
Security professionals who know passkeys well still mostly sign in to work accounts with a password, according to a new survey from Yubico and Okta.
The 2026 Global State of Authentication Report is based on answers from 1,890 technology and security professionals in nine countries. Asked how they log in to work accounts, 43% named a username and password, the most common answer. Yet 87% of the same group said they were familiar with passkeys, the login method that uses cryptographic keys instead of shared secrets.
Day-one credentials stick
Half of respondents said they received a username and password when they started their current job. The report's authors argue that the login method IT hands out on the first day tends to become the one employees keep using.
Personal accounts show a similar pattern. These professionals rely on passwords first and text-message codes second. SMS codes have a known weakness. If an attacker persuades a mobile carrier to move a victim's phone number, the codes go to the attacker. Like other one-time codes, they can also be phished through fake login pages.
"When legacy login habits persist, enterprises remain vulnerable to modern attack vectors," said Charlotte Wylie, SVP Deputy CSO at Okta.
Respondents were still generous when judging their own employers. Most described their organization as secure, even though 43% of them still sign in with a password. The researchers call this optimism bias, the belief that expertise protects people from bad outcomes.
Telling human from AI
The phishing numbers in the report come from the respondents themselves. 44% said their organization suffered at least one successful AI-driven phishing attack in the past year. Roughly the same share said there were none, and the rest did not know. The figure reflects what respondents believe happened at their companies. It is not a measured breach rate.
The researchers also tested the group directly. Respondents saw two HR emails announcing an updated employee handbook. A person wrote one, and AI generated the other. Only 36% correctly picked the human-written message. Most of the others thought AI had written it, and a few were unsure.
The result shows how little the text of an email reveals, even to a careful reader. Phishing-resistant authentication takes that judgment away from the reader. The key confirms the site's domain before sending anything, so an employee who falls for a lure still cannot hand over a working credential.
What Yubico and Okta recommend
The two companies want new hires to receive phishing-resistant authenticators during onboarding, so strong authentication applies from the very first sign-in. They want this enforced through application sign-on policies.
They also call for device health checks before a session opens and ongoing risk checks after it. That includes a key touch or biometric scan before an AI agent carries out work on a person's behalf.
In practice, the first decision falls to the IT desk that sets up a new employee's laptop. For 52% of respondents, that desk handed over a password.
Our Take
The survey suggests that the barrier to passkey adoption has less to do with awareness than with defaults. If security professionals keep the password they got on day one, it seems unlikely that less technical staff will switch on their own. Organizations that want passkeys used will probably have to issue them, not just allow them.
The HR email test also raises doubts about awareness training that depends on spotting suspicious wording. This matters most when attackers send lures from real accounts, as in the Nikkei incident where a hijacked account sent phishing emails. In those cases the sender looks legitimate, and the text gives readers little to go on.
It is worth watching whether companies move authenticator issuance into onboarding. Another open question is whether step-up checks for AI agents become a standard requirement as agentic tools spread through the enterprise.
