Passkeys have been widely promoted as the future of authentication, offering stronger protection against phishing and password theft. But new security research reminds organizations that even the most advanced authentication methods aren’t immune to attack when endpoints become compromised.
Researchers from Palo Alto Networks’ Unit 42 have demonstrated several attack techniques against Google Password Manager’s implementation of synchronized passkeys. Importantly, the research does not break passkey cryptography itself. Instead, the attacks exploit weaknesses surrounding how credentials are stored, synchronized, and accessed after malware has already compromised a device.
For managed service providers, the takeaway isn’t that passkeys have failed—it’s that endpoint security, identity protection, and layered defenses remain just as important in a passwordless future.
Here are five key takeaways for MSPs.
1. Passkeys Are Strong—But They Don’t Eliminate Endpoint Risk
The research highlights an important distinction: attackers aren’t breaking passkeys themselves. Instead, malware running on an already compromised Windows system can abuse Google’s Password Manager implementation to access synchronized credentials. In the most severe scenario, malware may obtain the master secret protecting synchronized passkeys while it’s briefly available in memory.
MSP Action:
Continue promoting passkeys, but remind clients they are one layer of a broader security strategy—not a replacement for endpoint protection.
2. Malware Remains the Real Threat
Every attack described by the researchers requires malware to already be present on the endpoint.
That means organizations focusing only on authentication while neglecting endpoint detection, application control, patching, and user awareness are still leaving significant risk on the table.
MSP Action:
Prioritize EDR, continuous monitoring, vulnerability management, and rapid incident response alongside identity security initiatives.
3. Browser-Based Credential Storage Deserves Extra Attention
Many organizations trust browser-integrated password managers because of their convenience.
While Google Password Manager remains a valuable security improvement over reused passwords, browser-based credential storage should still be evaluated against business risk, especially for privileged users and executives. Some organizations may benefit from dedicated enterprise password managers or hardware-backed authentication for high-value accounts.
MSP Action:
Review where clients store privileged credentials and determine whether hardware security keys or enterprise password management platforms are appropriate for sensitive accounts.
4. Layered Identity Security Still Wins
One of the biggest takeaways is that modern identity security cannot depend on a single technology.
Passkeys significantly reduce phishing risk, but organizations still benefit from Conditional Access policies, device compliance, Zero Trust principles, risk-based authentication, and continuous monitoring.
Authentication should always be viewed as part of an overall identity security framework rather than a standalone solution.
MSP Action:
Help clients build layered identity strategies that combine passkeys with device trust, behavioral monitoring, privileged access controls, and strong endpoint security.
5. MSPs Can Turn This into a Client Education Opportunity
News headlines can easily create the impression that passkeys are suddenly unsafe.
The reality is much different.
The research demonstrates attacks against an implementation after malware has already compromised a system—not a weakness in the cryptography that makes passkeys significantly more resistant to phishing than traditional passwords.
For MSPs, this presents an opportunity to educate clients on the difference between authentication security and endpoint compromise rather than creating unnecessary concern.
MSP Action:
Use this news as a reason to review clients’ identity security strategies, reinforce the value of layered cybersecurity, and explain why endpoint protection remains critical even in a passwordless environment.
What This Means for MSPs
Google’s Password Manager research reinforces an important cybersecurity principle: no single security control is enough on its own. While passkeys represent a major advancement over traditional passwords, organizations still need strong endpoint protection, continuous monitoring, identity governance, and user awareness to defend against evolving threats. MSPs that help clients understand how these technologies work together—not as standalone solutions, but as part of a layered security strategy—will be better positioned to strengthen client security, build long-term trust, and deliver greater strategic value.






