HID has announced the integration of Enterprise Attestation into its portfolio of FIDO authenticator smart cards and keys.
This capability, based on FIDO standards, allows organisations to enforce the use of company-issued passkeys during registration by verifying authenticator provenance before credentials are accepted. The aim is to bolster device trust and provide high-assurance authentication without complicating the user experience.
User login experience and device trust
Passkeys mitigate phishing risks, but enterprises also need to ensure that devices generating credentials are issued by them and are reliable. According to the FIDO Alliance's report on the State of Passkey Deployment in Enterprises, 20% of organisations find strict regulations a hurdle in adopting passkeys. Enterprise Attestation remedies this by making device trust and governance explicit and enforceable, ensuring that devices used for authentication are company-issued.
Without this feature, personal authenticators might be registered without the organisation's oversight. Enterprise Attestation confirms the device's issuance by the organisation, ensuring security teams maintain governance, traceability, and control without altering the user's login procedure.
Ensuring valid attestation data
Enterprise Attestation confirms the origin of the device at the registration stage of passkeys
Embedded in HID's Crescendo devices, which include FIDO2-certified smart cards and security keys, Enterprise Attestation confirms the origin of the device at the registration stage of passkeys. If a device lacks valid attestation data, policy blocks enrolment, streamlining the process without altering application workflows or adding user steps.
As part of the FIDO Alliance's WebAuthn and Client to Authenticator Protocol (CTAP), it ensures passkey governance adheres to established standards, avoiding proprietary authentication mechanisms and preserving standard user interactions.
Support for regulated industries
Enterprise Attestation is particularly beneficial for regulated sectors such as financial services, healthcare, and critical infrastructure. It aids compliance regarding auditability, device provenance, and lifecycle management. For organisations adhering to frameworks like the EU's NIS2 Directive, the Digital Operational Resilience Act (DORA), and Zero Trust, it offers a mechanism to enforce policies at the authenticator level.
Application in practice
Consider a scenario where a global retailer permits only specific approved authenticator models for passkey registration to exclude unauthorised hardware. This method lacks the ability to ensure the device is company-issued. Enterprise Attestation addresses this gap by requiring devices to present a certificate linking them to the company's known authenticator.
Missing or unrecognised certificates result in blocked enrolment. If a device is permitted, the user's login experience remains unchanged, but the organisation benefits from a verifiable and auditable record of device access granted during registration. HID's Crescendo authenticators equipped with Enterprise Attestation are now available worldwide.
HID, a global pioneer in trusted identity solutions, announces the availability of Enterprise Attestation in its FIDO authenticator portfolio of smart cards and keys, a FIDO standards-based capability that enables organisations to enforce only company-issued passkeys at registration, proving authenticator provenance before a credential is ever accepted.
By doing so, Enterprise Attestation helps organisations strengthen device trust, gain visibility into authenticator origin and support high-assurance authentication without adding friction for users.
User login experience
While passkeys address phishing, enterprises also need assurance that the devices creating those credentials are ones they have issued and trust. In the FIDO Alliance’s State of Passkey Deployment in the Enterprise report, 20% of organisations cite strict regulations as a key barrier to passkey adoption.
Enterprise Attestation addresses this gap by making device trust and authenticator governance explicit and enforceable. Without it, a personal authenticator could be registered to an employee, with no reliable way for the enterprise to distinguish it from a credential enrolled on a device the organisation controls, monitors and can revoke. Enterprise Attestation verifies that the device being registered was issued by the organisation. It gives security teams the governance, traceability and device control they need without changing the user login experience.
Valid attestation data
Built into HID’s Crescendo authenticators, including FIDO2-certified smart cards and security keys, and supported by identity platforms such as PingOne, Enterprise Attestation verifies authenticator provenance at the point of passkey registration. If a device cannot present valid attestation data, enrolment is blocked by policy, without requiring any changes to application workflows or additional steps for users.
Enterprise Attestation is part of the FIDO Alliance’s WebAuthn and Client to Authenticator Protocol (CTAP) specifications and is actively supported through the FIDO Alliance Enterprise Deployment Working Group. This standards-based foundation ensures organisations can enforce passkey governance without proprietary authentication flows, application lock-in or deviations from the standard user experience.
Healthcare and critical infrastructure
For highly regulated industries such as financial services, healthcare and critical infrastructure, the capability directly supports compliance requirements around auditability, device provenance and lifecycle control.
Global organisations operating under frameworks such as the European Union's NIS2 Directive, the Digital Operational Resilience Act (DORA, applicable to EU financial services organisations) and Zero Trust mandates gain a practical mechanism to enforce policy at the authenticator level.
Approved authenticator models
To understand what Enterprise Attestation adds in practice, consider a global retailer that currently restricts passkey registration to approved authenticator models. This approach filters unauthorised hardware, but it cannot confirm whether a specific device was actually issued by the company or sourced independently by an employee.
Enterprise Attestation solves that problem. When a device attempts to enrol, the system checks for a certificate that ties it to a known, company-issued authenticator. If that certificate is absent or unrecognised, enrolment is blocked. If granted access, the end user sees no change to their login experience, but the organisation gains a verifiable, auditable record of every device that has been granted access at registration. HID Crescendo authenticators with Enterprise Attestation support are available globally now.