Research Project - Identity Controls
PASSWORD-LESS TECHNOLOGY 1
EC-Council University
Password-less Technology:
Microsoft Leadership in Future Secure Platforms with Password-less Protection Technology
Fernando Michel Alves Andreazi
PASSWORD-LESS TECHNOLOGY 2
Table of Contents Abstract ........................................................................................................................................................ 3
Introduction ................................................................................................................................................. 4
Problem statement ...................................................................................................................................... 5
Objectives ................................................................................................................................................ 6
Results ...................................................................................................................................................... 6
Online Resources and Passwordless Technology ..................................................................................... 7
Evolving Passwordless Technology ......................................................................................................... 11
Lowered secondary costs .......................................................................................................................... 13
Why enterprises are interested in going Password-less ......................................................................... 14
Benefits of password-less authentication ............................................................................................ 15
Stumbling Blocks To Passwordless Organizational Future: Legal Issues ........................................... 17
Legacy authentication .......................................................................................................................... 17
Hardware Requirements ...................................................................................................................... 18
Windows 10 is a testing ground for Microsoft Password-less technology ........................................... 18
The new FIDO2 password less technology ............................................................................................. 19
Microsoft Azure ........................................................................................................................................ 20
Microsoft 365 Password-less technology ................................................................................................. 22
Biometric Password-less authentication devices .................................................................................... 24
Summary .................................................................................................................................................... 25
Reference ................................................................................................................................................... 27
PASSWORD-LESS TECHNOLOGY 3
Abstract
Enterprises often struggle with balancing security and ease-of-use trade-offs.
Passwordless solutions enhance the user experience, but also enhance security of the computer
system as compared to previous security mechanisms. When companies transition to
passwordless solutions, they considerably reduce their exposure to data breaches. Contrary to
companies that store their customers’ passwords on their servers, passwordless solutions require
no personal information to be stored for authentication purposes. When authentication is
performed on the user side, no personal information is transmitted over the internet, making
man-in-the-middle attacks virtually impossible. With the authentication data, such as the
biometrics of the user, kept on the user device, there is no single collection point for cyber
criminals to get access to a customer biometric dataset: this dataset does not exist. As a result,
the risk probability of online fraud and identity theft is greatly reduced. There are down-sides,
too: should users lose their authenticator, for instance if it is tied to a physical device, resetting
access can be more cumbersome than a password reset. Better end-user security. As criminals
and computers have become more effective at stealing and guessing passwords, password
hygiene rules have developed exponentially. Recognizing that these rules were difficult to
enforce, an inflexion point was reached recently with experts calling to simplify password
management protocols. When using passwordless solutions to authenticate, there are no
passwords for cyber criminals to steal out of a platform server. There is no information stored by
companies that could be leveraged by hackers to infer or brute force a password. Users are hence
better protected.
PASSWORD-LESS TECHNOLOGY 4
Introduction
While it is critical to build out a long-term strategy for authentication, experts concur that
the next digital breakthrough will be passwordless authentication, primarily for security and
identification reasons. Passwordless authentication offers four key advantages over traditional,
knowledge-based authentication. First, it makes sense financially: it increases revenues and
lowers costs. Second, it makes sense from a customer perspective, provides a better user
experience. Third, from a strategic point of view, it can help redefine competition by unlocking
value from interoperability. Fourth, as already mentioned, it greatly improves security.
Cybersecurity has been traditionally perceived as a cost centre, so the financial consideration is
perhaps the most notable reason why companies should consider transitioning to passwordless
authentication. Not only does it lower costs associated with password management and data
breaches, it actually improves revenues through increased productivity and customer ratings.
From an economic point of view, employees worldwide spend an average of 11 hours each year
entering or resetting their password. For a company of 15,000 employees, on average, this
represents a direct productivity loss of $5.2 million. There will be costs associated with
transitioning to a passwordless ecosystem but they are expected to be rapidly offset by the
productivity boost alone. With standards such as the ones developed by the FIDO Alliance,
which allow for most of the authentication to be performed on the user side, password
administration is significantly simplified. System administrators and call centre operators are
going to have a much better experience liaising with employees and customers and this will
indirectly improve company reputation and customer ratings.
A convenient, seamless user experience is essential to widespread acceptance and use of
authentication. The experience economy will be more important than price. Approximately 86%
PASSWORD-LESS TECHNOLOGY 5
of customers are indeed ready to pay a premium for more user-friendly experience. This means
that if a platform’s authentication experience is subpar, some customers will prefer a platform
with inferior services but a better authentication experience. Passwordless authentication is
seamless. It emulates the way in which human beings have recognized each other for millennia:
by looking for either identifying belongings or personal traits, such as uniforms, height or body
shape. In other words, passwordless authentication is becoming a competitive differentiator, and
a key consideration for digital transformation leaders. It is the entry door to an online service.
Users are less likely to try to circumvent security measures when users are asked to remember
over 100 credentials and passwords, they naturally look for ways to reduce their burden and re-
use passwords, choose weak ones, or note them down on their phone, email account or below
their keyboard. A better user experience means that users are more likely to use the
authentication system as it is meant to be: reducing the number of rules improves user
endorsement which in turn, improves security. Ubiquity Passwordless authentication is
customer-centric (Tehranipoor et al., 2017). Passwordless authentication technologies leverage
fast and convenient solutions that work everywhere, relying on the same devices that many
people use every day such as smartphones.
Problem statement
The financial services industry is used as an example to demonstrate the forefront of
adoption of next-generation passwordless authentication technology. The financial industry note
that, passwordless technology will be driven by user experience improvement and security
(Bolotin, Lemelev, & Singer, 2018). The financial industry has recognized that password
authentication was a source of consumer dissatisfaction, impacting use of their digital services
and driving increasing operating costs. With millions of consumers, even a minor improvement
PASSWORD-LESS TECHNOLOGY 6
would have a significant impact on ROI. The new passwordless technology will aim at
increasing authentication success rate, improve convenience, save time, and increase the general
user experience.
Objectives
Describe the principles behind passwordless technology;
Determine the application of passwordless technology;
Demonstrate the efficacy of passwordless technology.
Results
Various embodiments described for passwordless technology provide methods, systems,
and devices for alternate and more secure ways for authenticating users to access both offline
and online resources, instead of entry of a username and password. As used passwordless
technology is not limited to an online resource may refer to any content that is accessible via a
network, such as web-based or cloud-based data, applications, and services. Examples of online
resources may include, but are not limited to, web-based or cloud based data storage services,
social networking applications, shopping services, microblogging accounts, payment services,
multimedia content delivery services and financial services. In particular, the passwordless
embodiments allow customers to sign-in or login to one or more accounts associated with online
applications or services using a trusted device (such as a mobile phone, a smartphone, a tablet, or
other portable electronic terminal) that has been previously registered or linked to the account(s).
For example, a visible code may be displayed on a desktop computer alongside (or instead of) a
password-based sign-in window that is typically used to access a customer account for a web-
based service. A mobile phone that has been previously registered with the same customer
account can scan the displayed code using its camera, and can send the scanned code to a web
PASSWORD-LESS TECHNOLOGY 7
server that provides the web-based service. In response to receiving the scanned code, the web
server can identify the mobile phone as being associated with the customer account based on the
prior registration, and can thereby authenticate the desktop computer for access to the web-based
service based on recognition of the scanned code (Dorfman, & Sengpiehl, 2018). Thus, the
desktop computer may be automatically signed-in to the web-based service based on recognition
of the mobile phone as a trusted device, without requiring the customer to enter his username and
password.
Online Resources and Passwordless Technology
Online resources benefit more from this technology. The online resources can be
accessed in accordance with embodiments allowing access using a web browser executing on a
computer, as well as with native applications executing on non-traditional computing devices,
such as televisions or external set-top boxes connected to a television. New and developing
Passwordless embodiments therefore can be integrated to allow an unregistered device to access
a customer account responsive to receiving authenticating information from a trusted device that
has been previously registered with the customer account (Kim, 2016). Accordingly, new
technology and passwordless embodiments in use today may reduce demands on the customer’s
aspect of remembering usernames and passwords as well as obviate many security risks as
compared to traditional password-based authentication methods.
Overall Architecture for Using a Trusted Device to Authenticate Another Device
Passwordless technology provides opportunity for using trusted devices to authenticate another
device. As shown in Fig 1, a block diagram of systems, devices, methods, and computer program
products for authenticating a customer for access to account-based online resources using a
trusted device, according to available passwordless technology. When describing the
PASSWORD-LESS TECHNOLOGY 8
functionality of passwordless technology, account-based online resource are designated to refer
to network-accessible data, applications, services, or combinations that require a customer
account or subscription to access the provided content or services. As shown in Fig 1. a
communications environment or system 100 may include a mobile electronic device 110 and
another electronic device 120 that are accessible to a user 101 and are configured for
communication via a network 140. The mobile device 110 (also referred to as "primary device"
associated with the user 101) may be a wireless communication terminal, such as a cellular
telephone, smartphone, electronic book reader, tablet, or other portable electronic terminal that is
configured to access the network 140 over a wireless connection, for example, via a base station
transceiver 108. The electronic device 120 (also referred to as a "secondary device" accessible to
the user 101) may be a wired or wireless communication terminal, such as a desktop computer,
laptop computer, smartphone, tablet, network-ready television, set-top box, and the like, and may
be configured to access the network 140 via a wired or wireless connection. The secondary
device 120 may be configured to access the network using a web browser or a native application
execution. In some embodiments, the mobile device 110 may have a physical size or form factor
that enables it to be easily carried or transported by a user 101, while the electronic device 120
may have a larger physical size or form factor than the mobile device 110.
The devices 110 and 120 are configured to access online resources, including web-based or
cloud-based data, applications, and services, via the network 140. The network 140 may
represent one or more of a local area network (LAN), a wide area network (WAN), an Intranet or
other private network that may not be accessible by the general public, or a global network, such
as the Internet or other publicly accessible network. The network 140 provides communication
PASSWORD-LESS TECHNOLOGY 9
between the devices 110 and 120 and one or more online resource providers 150 (such as web
servers) configured to provide the aforementioned online data, applications, or services. The
online resource provider 150 may include a network transceiver, processor, memory, and or
other circuitry configured to coordinate and manage operations for delivering online resources to
the devices 110 and 120 via the network 140. While illustrated as a single entity in Fig 1, it will
be understood that, in some passwordless technology configurations the online resource provider
150 may represent one or more physical or virtual servers that are configured to deliver online
resources to the devices 110 and 120. Examples of the online resources provided by the online
resource provider 150 may include, but are not limited to, web-based or cloud based data storage
services, social networking applications, shopping services, microblogging accounts, payment
services, multimedia content delivery services such as online magazines, music, and video, and
financial services such as credit/banking services.
The online resource provider 150 may require a subscription or customer account in order to
access each of the different online resources provided thereby. As such, the system 100 also
includes a customer account store 135 that contains customer account information for one or
more customers, such as the user 101. The customer account store 135 may be embodied in
nonvolatile memory, such as flash, magnetic, or optical rewritable nonvolatile memory. The
customer account information stored in the customer account store 135 may include a listing of
customer accounts and online resources to which the accounts correspond. The customer
accounts may include information identifying each user or customer that has registered for each
online resource, such as the customer's name, mailing address, e-mail address, phone number,
payment. The customer account information may also include information that may be used to
verify or authenticate the customer to access the account. For example, for each customer
PASSWORD-LESS TECHNOLOGY 10
account, the customer account information may include a username and a password selected by
the customer to access the account. However, as noted above, such password-based
authentication may be cumbersome for a customer and may also be vulnerable from a security
standpoint.
PASSWORD-LESS TECHNOLOGY 11
Evolving Passwordless Technology
Security technologies tend to be short-lived and evolve rapidly. Whether operational one
year or 10 or more, cyber criminals are generally adept at finding ways to circumvent security
controls. Authentication technologies are no exception. It is consequently critical to build out a
long-term security strategy. While transitioning away from knowledge-based authentication is
long overdue, and passwordless authentication is the way forward for more secure platforms.
The following six principles are to be considered when building an authentication programme
capable of passing the test of time: security, privacy, sustainability, inclusiveness, scalability,
and user experience. Security logically comes first when building a strategy for an authentication
system. Security in an authentication system will be based on multiple considerations, from its
relative strength compared to other solutions, to its lifespan against known threats and the new
threats to which it exposes the system, along with the hardware and software vulnerabilities that
it solves and those that it introduces. The security of an authentication system will also depend
on its efficiency in reducing fraud and risk, and on the accountability that it allows through the
logs it records (Pikrammenos, Toils & Petrakis, 2019).
Passwords have been the source of numerous data breaches that have negatively impacted
privacy globally (Shin, & Kim2018). Acknowledging the various regulations and cultural aspects
needed to ensure privacy, future-oriented authentication technologies should be mindful of these
and, for global acceptance, ensure compatibility with the most stringent. While certain
authentication solutions may fall within the category of Privacy-Enhancing Technologies, others
will not. Sustainability is another key element to confirm that technological choices fit in a long-
term vision strategy. Transitioning to passwordless authentication cuts costs and potentially
increases revenues. The actual costs will depend on the size of the company. For some
PASSWORD-LESS TECHNOLOGY 12
companies, the sheer scale of their IT systems might call for a phased approach, which in turn
requires new and legacy authentication solutions to coexist. Along the same line, authentication
technologies are closely linked to identity and access management: ensuring that authentication
and identification systems are compatible is also key to a sustained advantage (Papadamou ., et
al 2019). The externalities of the authentication system must be considered when considering
sustainability. For example, utility costs and human resources costs must be considered as part of
the new passwordless technology sustainability.
Inclusiveness in the new era authentication systems are the entry points to digital
services, so making sure that they are inclusive – as opposed to discriminatory will be essential
for platform businesses. Such systems should strive to avoid discrimination of any kind, whether
due to age, culture, disability, language, name, nationality, medical condition, origin, religious
belief, sexual orientation, skin colour, among other factors. For example, authentication
technologies are increasingly using AI. Therefore, the machine learning biases must be addressed
when developing new authentication technologies.
The economics of new passwordless technology must be scalable. The world industrial
platform economy calls for solutions that scale. Employees and end-users are increasingly going
to authenticate across different platforms. It is therefore critical to consider authentication
solutions from the perspective of scale: when a platform reaches critical mass and starts
experiencing network effects, growth can be exponential. The performance targets of the
authentication system need to be planned long in advance, notably around reliability and
availability. Similarly, the “growth potential” of the solution will be important in subsequent
phases. For instance, off-the-shelf solutions may not allow for the expected level of
customization needed for a large company operating multiple IT environments. Elsewhere, the
PASSWORD-LESS TECHNOLOGY 13
user experience is no longer a nice-to-have, it has become a key differentiator: the quality of the
user experience determines user choice, preference and behaviour. As such, future authentication
should strive to offer a seamless user experience to ensure adoption.
Lowered secondary costs
The average global cost of a data breach in 2019 is $3.92 million – a 1.5% increase from
the year before. When there are no passwords to infer or to steal, this seriously hinders the ability
of criminals to access and exfiltrate data. Even password hashes are useful to criminals who can
brute force them without any limitation imposed by the authentication server. From a risk
management perspective, this implies that transitioning to passwordless authentication allows
companies to cut the budgets associated with their breach risk exposure by 4/5. This translates
immediately into lower cyber insurance premiums and password reset overhead savings. When it
comes to IT departments and call centres, companies spend on average 2.5 months resetting
internal passwords. Approximately 20% to 50% of all calls to the IT helpdesk concern password
resets, and the estimated cost of a single reset ranges from $30 to $70. LastPass, a well-known
password-safe company, estimates that companies spend on average $1 million per year in
staffing helpdesks alone to deal with password resets. A Fortune 500 US health insurance
company transitioned to passwordless authentication in 2018. In this type of sector, users log into
key services intermitted. Consequently, password resets and helpdesk congestion are common
around the time of customer re-enrolment. This type of business model and user experience
incurs spikes in costs and lowers overall authentication frequency for the customer.
PASSWORD-LESS TECHNOLOGY 14
Organizations observing the above-listed steps will be able to improve their security environment
even if password blocking is not possible. Constant use of voice calls or text messages for
confirmation of identities is also recommended.
Why enterprises are interested in going Password-less
Although passwords have played a critical role in human history to distinguish who could
enter a specific area, on the other hand, they also pose a lot of insecurity. Individuals have
witnessed the frustration of password forgetfulness to vital accounts. As a result, they have been
forced to go through a tedious process of redeeming the forgotten password or creating new
ones. The lengthy procedures and guidelines on how to create a secure password have resulted
in a complicated string of characters that can easily be forgotten the next time a person wants to
log into the system.
Also, an organization with crucial accounts that want to go online to conduct
transactions, including banking and donations, need authentication systems, that won't give
problems every time they want to make repeated purchases. That is the reason enterprises wish
to go password-less authentication. With password-less, the system allows users to implement a
different verification method that does not ask to remember an array set of characters. Also,
users can log in into their systems by simply scanning their finger and entering a passcode that
may be delivered via phone or authorizing their account through email (Atick et al., 1997).
PASSWORD-LESS TECHNOLOGY 15
Benefits of password-less authentication
1. Password-less authentication is a lot more secure
In the past few years, there has been the experience of vast cases of stolen or hacked
passwords. Owing to the aforementioned, passwords pose more problems than solutions to
keeping the user's information secure. Furthermore, many websites mandate users to create an
account where users have to juggle through multiple passwords to remember which one belongs
to each account. As a result, for users to remember the passwords, they have to choose
comfortable passwords such as a birthday. These similarities in passwords lead to more unsafe
accounts and easy guess for hackers to get access. The setbacks, as mentioned earlier, can better
be avoided by the use of passwordless authentication. Hackers will have more difficulty in
gaining access to individual or company's user's fingerprints, phones, or even email accounts.
Therefore, the user accounts will remain more secure compared with traditional password
protection. Notably, passwordless authentication creates another verification step that proves
users are who they are. Also, these methods pertain to a lesser likelihood of getting hacked by
fraudsters (Morijj, et al., 2017).
2. Password-less authentication is cost-effective and easy to implement
There is a misconception that password-less authentication is expensive and a non-viable
option. That is far from the truth because companies have a better chance of exploring password
fewer options. Companies who want to go password-less should locate providers that fit their
budget and of high quality. They should work with providers that make the implementation
process much smoother. They can do this best by attending workshops on how to use the
password-less tool. Organizations can go password less, by use of inexpensive tools available
that are easy to implement and start using.
PASSWORD-LESS TECHNOLOGY 16
3. Password-less protect companies along with their users
Since companies store information on the user's account, such as payment and much
more, the user database can be more vulnerable to the data breach. However, in the case of a data
breach, no amount of password protection can keep companies protected (Morijj, et al., 2017).
Cybercriminals can access the database by cracking the critical encrypted information the same
way they would break a password. Also, they can gain access by intruding internal accounts by
use of high-level permissions.
Furthermore, many accounts do not use secure credentials, thus easing the process for hackers
that one might think. That is the reason why companies should also ensure their employees adopt
passwordless authentication. A company can implement passwordless login into their internal
accounts so that employees do not need to deal with the hassle of creating and memorizing
complex passwords. By protecting the user's accounts on both fronts internally and externally for
employees, a more robust infrastructure is guaranteed.
In a nutshell, passwordless authentication does not only protect a company but its users. By
implementing more security internally, a company's vital information is better protected from
unauthorized or malicious users.
PASSWORD-LESS TECHNOLOGY 17
Stumbling Blocks To Passwordless Organizational Future: Legal Issues
Presently, over 80 percent of users can sign-in to networks without having to enter
passwords (Pikrammenos, Toils & Petrakis, 2019). According to Julisch, Microsoft is making it
easy for users to eliminate passwords across its organizations (2008). However, one of the key
stumbling blocks to passwords for the future is a legal compliance requirement in various
industry segments. Despite the directive, until the regulations are updated in technology, the
user's segment will continue using passwords. At the moment, to ease the issue, organizations are
recommended to create two user groups, for users in response to compliance restrictions and
another one for anyone using the systems.
Legacy authentication
Users that need to use usernames and passwords may be restricted by "legacy
authentication" protocols that use it, also referred to as basic authentication by Microsoft. This
hindrance poses a massive obstacle to eliminating passwords. However, many organizations
encounter challenges when attempting to disable their basic authentication. This is due to some
applications attached, such as Older Microsoft office apps, using specific email protocols such as
POP, IMAP, and SMTP, that are inherently connected to it. These apps and services might be
broken if the basic authentication gets detached or disabled (Tehranipoor et al., 2017).
Notably, only organizations solely using cloud computing services won't be affected by
the blocking of basic authentication (Tehranipoor et al., 2017). Furthermore, the process of
blocking or disabling authentication is tiresome, time-consuming, and complicated, especially
when it breaks services. If a company is already using cloud computing, it doesn't have to use
any legacy authentication, and password elimination is more natural. Moreover, another reason
for disabling basic authentication is its inability to support multifactor authentication MA, which
PASSWORD-LESS TECHNOLOGY 18
is a crucial component of Microsoft's password less for the future. Multifactor authentication is
an enhanced security.
Hardware Requirements
Microsoft prescribed various requirements that organizations need before implementing
password-less. The requirements state that all hardware devices should be upgraded to enable the
system to support biometric authentication. Examples are face scans via camera enabler and
fingerprint reader. Also, they should be updated to allow Trusted Platform Module 2.0 or FiDO2
support or any other newer versions.
Microsoft recommended organizations without passwords to use FiDO2 support for
Azure to test the use of USB thumb drives that allows them to sign in to Azure AD accounts
without the use of passwords. FIDO2, and FAST identity online 2.0, is a standard web
authentication for users without a password. However, those organizations that cannot eliminate
the use of passwords are asked to create a list of banned passwords using Azure Ad Password
Protection. Azure Ad is a service that allows disabling the use of similarity in passwords such as
12345, and other attackers that hackers are likely to guess (Microsoft to secure Windows 10 with
FIDO two-factor authentication including biometrics).
Windows 10 is a testing ground for Microsoft Password-less technology
Microsoft is on the move to introduce Windows 10 test build up with additional and
improved new features regularly. Recently the company launched Windows 10 build 18936 a
feature tester in the fast ring (Microsoft to secure Windows 10 with FIDO two-factor
authentication including biometrics). With the latest build-ups apps, all devices are made
password-less in the sign-in option via settings. Users can go to setting, then accounts, and
PASSWORD-LESS TECHNOLOGY 19
select sign in options, then turn on the password-less option. With Microsoft accounts on
windows ten devices, users can switch to hello face, or finder spring or PIN. The newly
launched test build is introduced in small portions, and they hope to go on with more.
Also, Microsoft announced publicly on Azure Active Directory, a preview of FIDO2,
where users can try the ability to deliver FIDO2 security keys, which authenticate users to
windows 10 Azure Active directory conjoined device. The build-in apps provide an option to
read a quick event from the taskbar by simply clicking on the date in the toolbar. Also, Microsoft
is expanding the enabling apps on the phone screens. The feature is available on Surface laptop,
Pro, 4, 5 6, and Surface book starting with Bild 18936 (Atick, 1997).
Although many companies have been working hard to disable passwords options from
Windows 10 and its Microsoft Accounts. Microsoft has taken the next major shift to update to
windows 10. Soon, users will not be able to enable password-less sign-in for Microsoft on
Windows. All PCs will use windows hello face authenticating, fingerprint and Pin. The
password option will be disabled from the login screen for those using the new device password
less feature.
The new FIDO2 password less technology
The Fast Identity Online (FIDO2) is a new open authentication standard. The industry
lease with more than 250 company members that include Goggle, Facebook, Intel, PayPal,
Amazon, MasterCard, Visa, and Samsung. Its main objective is to open authentication
standards that assist in minimizing the world's reliance on passwords and as means of cyber
identity authentication. Its key agenda is to allow users to log in is without the use of
passwords. They do so by creating password-less flows or Strong MFA for users sign in and
PASSWORD-LESS TECHNOLOGY 20
long in websites. FIDO standard is not limited to other web applications with support coming
to Azure Active Directory and other native apps. The technology works by creating private
and public authenticating keys. They enable authentication to happen without a secret key
between the user and the Platform. The technology brings an array of benefits, such as a
comfortable and safe way to login in at the same time, making phishing attempts extremely
difficulty (Bole, et al., n.d)
FIDO protocol authentication work by use of public-key cryptography techniques to
provide a safer and more robust authentication. The user client registers with an online
service by creating a pair of new keys. The system work by retaining the private key and
registering the public key with the online service. The authentication process is done through
the client devices, which process the private key to the service by signing a challenge.
Notably, the client's private keys can be used only after the user device locks it out. The
local unlock done by the user-friendly and secure action like entering a Pin, swiping a finger,
of speaking on a microphone. Other attempts include inserting a second-factor device SFD,
or by pressing any button.
Microsoft Azure MFA
Microsoft Azure Multi-Factor authentication help organizations minimize risks by
providing an extra layer of authentication to the already existing ones in the user's account
credentials.
Organizations must still on increased data protection and data bleaching necessities by
addressing any threats to security at the same time embracing the digital transformation.
Presently, a lot of organizations are embracing the idea by shifting to cloud security service
PASSWORD-LESS TECHNOLOGY 21
providers. All IT-related businesses need an authentic, trusted partner, to process and build cloud
services to increase business agility, and securing enterprise data and other assets.
Microsoft Azure comprise of mitigations that provide an array of integrated services for
clients to protect and secure business assets while minimizing costs, management overhead, and
other complexities. Microsoft Azure builds a principle of security by providing a managed
service approach for enterprise to cover significant areas in data protection, security, workload
threat protection, and detection, identity and safety protection as well as infrastructure
management security. Clients may opt for various levels of security from the providers who take
care of them by administering their operations and help them improve their security for cloud
and hybrid assets.
Microsoft Azure works like any other could computing service provider. However,
Microsoft Azure is managed by Microsoft and is used to build, test, and execute and manage
applications through global online data centers. The entire Azure data structure involves server
operating at the data centers globally. It employs a virtualization technology where users can
have access or control of devices and virtual computers remotely. The azure feature is achieved
by Hypervisor software, which creates and runs virtual machines or databases. The devices are
compatible with any operating system, such as Windows and Linux. Also, Azure provides a set
of other services, which include Software as a service (SaaS), Infrastructure as a service (IaaS),
and Platform as a service (PaaS). All these provide support to Microsoft specific and third
parties, tools, and other framework systems (Bole, et al., n.d).
Microsoft Azure presently caters for 54 Regions and 140 Countries worldwide (Microsoft
to secure Windows 10 with FIDO two-factor authentication including biometrics). Each Azure
data center comprises of a variety of rack of servers. Every racker contains the Software referred
PASSWORD-LESS TECHNOLOGY 22
to as a Fabric controller. However, the Microsoft Azure fabric controller is an accessory of the
Microsoft Azure platform that monitors and manages services. Also, it assists in coordinating
resources for Software applications.
Microsoft 365 Password-less technology
Citizens and other public servants place their trust in government institutions. They trust
that the agencies representing their needs act in good faith in protecting their interests. These
interests include food, medications, information, Infrastructure, national security, as well as the
sustainability of the social contract. The government and its constituents, on the other hand,
requires the same trust from citizens to retain their public trust. Notably, for government
functions to run smoothly, there is a need for the flow of data on a massive scale. These include
sensitive information on public safety-critical Infrastructure and security (Microsoft to secure
Windows 10 with FIDO two-factor authentication including biometrics). The more attractive
the information is, the more data sensitivity and protection is required. Owing to such,
government systems, due to financial gain and political gain is subject to constant attempts of
attacks. Initially, the prevailing paradigm for the security system was to guard the perimeter or
to protect the network entry and exit point through firewalls, and virtual private networks (VPN)
(). However, this traditional method has become obsolete in the wake of innovations changes,
such as the expansion of mobile networks. The swift development in digital data, the rise of
cyber-attacks, and the proliferation of shadow It has effected advanced changes. Presently more
and more enterprises are shifting to zero trust models for their devices and user's security. The
default untrustworthy and default are applied to all users, devices, and all applications and data.
Microsoft, 365 is a new auto- authentication app, that is reliable and secure. It assists
government institutions and other private enterprises on their zero trust journey for
PASSWORD-LESS TECHNOLOGY 23
authentication. With the use of Microsoft 365, the government, as well as other private bodies,
can initiate the immediate steps towards zero trust as a security model. The Microsoft 365,
create the first step by creating a secure environment with an open verification of identity. Most
cyber attackers use phishing to break into unauthorized data. Phishing can lead to users with
sensitive information be compromised. Also, it can open doors for attackers to steal valuable
information. Cybercriminals like stealing sensitive data, but before they gain access, they need
an identity breach, which is a common tactic to gain access to data (Microsoft to secure
Windows 10 with FIDO two-factor authentication including biometrics).
The government and other private bodies by the use of Microsoft 365, password-less, is
their crucial initial step in the cybersecurity strategy of protecting identity and managing access
to unauthorized users. This new authentication method is safe until someone hacks it, and
whoever hacks, has to have access to all your passwords. The model utilizes additional security
layers. They include Microsoft secure score and the evolution of office 365 safe score. The
service provides enterprises with a report card for their security positions, alerting them to assess
where they need to make changes quickly. The changes include turning on Multifactor
authentication or email forwarding.
Microsoft is creating protections by this approach, and make it a new solution for
Microsoft 365 subscribers. Also, the strategy entails a combination of a range of services that
caters to both online and remote. Threat protection n are similar to email accounts, where users
Pcs, documents, and other Infrastructure can detect and mitigate attacks. Cybersecurity remains a
central issue in the digital age. Most Organizations daily take precious time and resources to
defend their assets against cyber attackers. They operate with dozens of complex tools, yet the
threat remains. Also, their security team struggles to keep update with skilled expertise.
PASSWORD-LESS TECHNOLOGY 24
Biometric Password-less authentication devices
Biometric password-less authentication devices are used for more security than
convenience. These devices assist businesses along with their partners to speedily take
advantage of the core technology and verify their identity with unique functionality. They do so
with the use of liveness detection across online through traditional voice, mobile devices, and
other physical access devices. The R&D technology has designed a unique approach to
biometric authentication that doesn't need to store any biometric data, called ID R&D' solutions
build up apps on biometric technologies (Sathiya & palanisamy, 2018 )
Engrained apps include voice, biometric, facial biometrics, behavior biometrics, and
liveness detection. The voice biometrics function by comparing the characteristics of the user's
voice and the stored voice known as voiceprint to determine the matching criteria. Facial
biometrics work by comparing the different patterns of the user's facial structure, excluding eye,
skin color, with those of stored template to determine the match. Behavioral biometrics, on the
other hand, utilize unique identifiable patterns in user's activity, such as keystroke dynamics or
how they type to verify their identity. Lastly, the liveness detection uses liveness identification
features such as presentation attacks, such as recorded voice, video, photos, computer-generated
voice, masks, and more impersonate authorized users.
Biometric authentication devices do not guarantee an alternative solution. Although they
do not provide security certificates which many enterprises need for their users, the advantages
outweigh the drawbacks, hence making it a security device that countless users use in existing
accounts (Williamson, 2006). The use of biometric authentication can address many issues:
PASSWORD-LESS TECHNOLOGY 25
Merits
▪ The method of scanning fingerprint is cheap, fast and relatively secure
▪ The devices use voice recognition, which is easy but ambiguous to manipulate for the
attackers.
▪ The use of feature deification like iris is very secure at the same time potentially more
convenient compared with the fingerprint.
▪ The model provides address security concerns among users at the same time ensuring the
security
Drawbacks
▪ The Software does not apply in all applications
▪ The cost to deploy the model is expensive
▪ The biometric support is limited in some platforms
▪ Some applications in biometrics are disabled
▪ The technology does not provide a silver bullet, and they still hold some insecurity; thus,
it can be compromised.
Summary
The research paper analyzed the password-less technology approaches, and its primary
purpose in Enterprise IT security. As such password-less technology and its application policies
are dependent on correctly identifying users requesting access and putting providing the identity
management the priority in defense of enterprise security. Notably, traditional password
authentication solutions are mostly considered as high friction, time-consuming hence
PASSWORD-LESS TECHNOLOGY 26
challenging to users. Organizations are presently considering a password-less strategy to
authentication that can improve user productivity while assuring security. Password
authentication entails three methods, namely voice print, biometric fingerprint, and other unique
behavior, which include encrypted tokens.
However, it is imperative to recognize that there exists no single way of authentications
that will be optimally secure and user-friendly in all cases. Most organizations opt for multiple
approaches and related costs. Although there is increased awareness of the value or importance
of providing low friction authentication, there exist vital inhibitors to the adoption of the
technology approaches. They include concerns about the complexity of the deployment of
authentication solutions and the costs. Nonetheless, many organizations are hesitant or reluctant
to embrace password-less authentication technology because they believe it might bring
disruption to business operations. The password-less technology providers should ensure the
viable solutions are included that support the "Fours Is" of password-less authentication, which
provides for intuitive, informative, intelligent, and integrated.
PASSWORD-LESS TECHNOLOGY 27
Reference
Atick, J. J., Griffin, P. M., & Redlich, A. N. (1997). . Human Detection and Positive
Identification: Methods and Technologies. https://doi.org/10.1117/12.265388
Banerjee, S. P., & Woodard, D. (2012). Biometric Authentication and Identification Using
Keystroke Dynamics: A Survey. Journal of Pattern Recognition Research, 7(1), 116-139.
https://doi.org/10.13176/11.427
Bolle, R., Pankanti, S., & Ratha, N. (n.d.). Evaluation techniques for biometrics-based
authentication systems (FRR). Proceedings 15th International Conference on Pattern
Recognition. ICPR-2000. https://doi.org/10.1109/icpr.2000.906204
Bolotin, L. M., Lemelev, A., & Singer, M. (2018). U.S. Patent Application No. 16/103,983.
Dorfman, S., & Sengpiehl, D. P. (2018). U.S. Patent No. 9,923,885. Washington, DC: U.S. Patent
and Trademark Office.
Gong, G., Xinxin, F. A. N., & Zhu, B. (2018). U.S. Patent No. 10,136,315. Washington, DC: U.S.
Patent and Trademark Office.
Julisch, K. (2008). Security compliance. Proceedings of the 2008 workshop on New security
paradigms - NSPW '08. https://doi.org/10.1145/1595676.1595687
Kelley, P. G., Komanduri, J. L., Maass, M., Mazurek, M. L., Passaro, T., Shay, R., Vidas, T.,
Bauer, N., & Cranor, L. F. (2012). How Does Your Password Measure Up? The Effect of
Strength Meters on Password Creation. 2012. USENIX Security,.
Kim, J. R. (2016). U.S. Patent No. 9,519,767. Washington, DC: U.S. Patent and Trademark Office.
Microsoft to secure Windows 10 with FIDO two-factor authentication including biometrics.
(2015). Biometric Technology Today, 2015(3), 1-2. https://doi.org/10.1016/s0969-
4765(15)30024-2
PASSWORD-LESS TECHNOLOGY 28
Morii, M., Tanioka, H., Ohira, K., Sano, M., Seki, Y., Matsuura, K., & Ueta, T. (2017). Research
on Integrated Authentication Using Passwordless Authentication Method. 2017 IEEE
41st Annual Computer Software and Applications Conference (COMPSAC).
https://doi.org/10.1109/compsac.2017.198
Papadamou, K., Zannettou, S., Chifor, B., Teican, S., Gugulea, G., Caponi, A., ... & Xenakis, C.
(2019). Killing the Password and Preserving Privacy with Device-Centric and Attribute-
based Authentication. IEEE Transactions on Information Forensics and Security.
Pikrammenos, I. A., Tolis, P., & Perakis, P. (2019). Authentication Mechanism Enhancement
Utilising Secure Repository for Password Less Handshake. International Journal of
Network Security & Its Applications (IJNSA) Vol, 11.
Sathiya, L., & Palanisamy, V. (2018). A Survey on Finger Knuckle Print based Biometric
Authentication. International Journal of Computer Sciences and Engineering, 6(8), 236-
240. https://doi.org/10.26438/ijcse/v6i8.236240
Shin, S. M., & Kim, M. (2018). PC User Authentication using Hand Gesture Recognition and
Challenge-Response. JOURNAL OF ADVANCED INFORMATION TECHNOLOGY AND
CONVERGENCE, 8(2), 79-87.
Tehranipoor, F., Karimian, N., Wortman, P. A., Haque, A., Fahrny, J., & Chandy, J. A. (2017).
Exploring methods of authentication for the internet of things. In Internet of Things (pp.
71-90). Chapman and Hall/CRC.
Williamson, G. D. (2006). Enhanced authentication in online banking. J. of Econ. Crime
Management, 4(2).