The people who know passkeys best are still typing passwords

Yubico and Okta asked 1,890 technology and security professionals across nine countries how they sign in to work accounts. The most common answer was a username and password, at 43%, from a group in which 87% said they were familiar with passkeys.

passkey adoption

High familiarity with modern authentication (Source: 2026 Global State of Authentication Report)

The password comes with the laptop

Half of respondents were issued a username and password when they started their current role. The report’s authors argue that whatever IT hands out on day one is what people keep using. On their personal accounts, these professionals lean on passwords first and text-message codes second. Text-message codes carry their own risk: an attacker who talks a mobile carrier into moving a phone number gets the codes too.

“When legacy login habits persist, enterprises remain vulnerable to modern attack vectors,” said Charlotte Wylie, SVP Deputy CSO at Okta.

The respondents rate their own employers generously anyway. Most described their enterprise as secure, a verdict that sits next to the 43% still signing in with a password. Researchers call that optimism bias, the belief that expertise protects you from bad outcomes.

Experts misread the test emails

Respondents supplied the phishing numbers themselves. Forty-four percent said their organization suffered at least one successful AI-driven phishing attack in the past year. About as many said they had none, and the rest weren’t sure. Treat that figure as what respondents believe happened at their companies, not a measured breach rate.

The researchers also ran a test. They showed respondents two HR emails announcing an updated employee handbook, one written by a person and one generated by AI, and asked which was which. Only 36% correctly picked the human one. Most of the rest thought AI had written it, and a few weren’t sure.

If you take one thing from that test, it is how little a careful reader can learn from the text of an email. A phishing-resistant login moves the check from the reader’s eye to the key, which confirms the site’s domain before anything is sent. A fooled employee still can’t hand over a working credential.

What the companies want changed

Yubico and Okta want phishing-resistant authenticators issued to new hires during onboarding, so strong login starts at the first sign-in, and enforced through application sign-on policies. They also call for device health checks before a session opens and ongoing risk checks after it. That includes a key touch or biometric scan before an AI agent carries out work on a person’s behalf.

The IT desk that sets up a new hire’s laptop makes the first call, and for 52% of these respondents, it handed over a password.

Download eBook: Identity-First Threat Intelligence

Don't miss