Cisco Duo debuted its long-awaited passwordless authentication today at Cisco Live.

The new security feature is infrastructure agnostic, and it allows users to log into cloud applications with one click using security keys or platform biometrics such as fingerprint or facial recognition built into smartphones and laptops. Duo passwordless authentication will be available for public preview this summer and generally available by the end of the year as part of Cisco’s zero-trust platform.

“For 60 years, we’ve been stuck with the password as the first, and oftentimes the last, line of defense, and everyone hates the password,” said Wolfgang Goerlich, advisory CISO at Cisco’s Duo Security. “So finally, we’re getting to the point where the technology is good enough to replace that factor and radically increase the authentication workflow or the trust for every single authentication.”

No one likes passwords — and they’re not that great at security, either. They are easily compromised, and Cisco says password management costs enterprises billions of dollars annually while password reset requests comprise the bulk of IT help desk tickets. This results in lost productivity for users and more support costs for businesses.

However, simply getting rid of passwords is only one step in the process, Goerlich said. “We are going to absolutely take that forward in terms of increasing trust and authentication, and providing a greatly simplified experience to our users,” he said. “So we are looking at this from a multi-factor perspective, which has better security properties and meets audit compliance requirements.”

Duo Passwordless Authentication

Duo passwordless authentication uses the Web Authentication (WebAuthn) standard, based in asymmetric cryptography. It enables biometrics to be securely stored on and validated by the device, locally, as opposed to a centralized database. Duo helped drive WebAuthn’s ratification as an official web standard and adoption across platforms as a member of the World Wide Web Consortium (W3C) working group.

The vendor’s first passwordless use case involves allowing access to cloud applications protected by Duo single sign-on (SSO) and third-party SSO and identity providers by leveraging security keys and platform biometrics such as Apple FaceID and TouchID, and Windows Hello.

“A typical enterprise today is running around 300 SaaS apps. And that number jumped up when we all went to remote work,” Goerlich said. “So, if we wait for all the SaaS vendors to enable passwordless individually, we’re going to have a similar experience to what we already have with passwords — everyone’s going to have to remember a different way of doing things, and there’s a lot of overhead. Plus what happens when people leave, and you’ve got an account still standing out there?”

Pairing passwordless authentication with Duo SSO enables organizations to consolidate hundreds of passwords and authentications into one login for users to cloud applications, Goerlich explained. “We can passwordless provision any application we can talk to over SSO, and with Duo SSO, we support effectively every application out there,” he said.

In addition to passwordless authentication, users can add extra layers of security with Duo’s secure access services such as device health and behavior monitoring controls, which further reduce risk in the event a biometric is stolen or not effective.