Passwordless rollout

Removing the password is a programme, not a switch

Almost nobody eliminates passwords in one move. What works is shrinking the surface where people see one — application by application, population by population — until what remains is small enough to handle deliberately.

Rollouts stall for three reasons

None of them is the authentication technology, which is the part that already works.

The business case is usually not security

Most organisations start this because of the service desk queue and the user experience, and argue phishing resistance later, when a mandate arrives. A programme justified on cost gets measured on cost.

Some applications only speak passwords

The system that cannot be changed, the appliance with a hardcoded login, the third-party portal outside your control. Ignore them and you produce a hybrid state nobody planned.

Recovery is where the attacks go

Enrolling a passkey is easy. Losing the phone is not. The strongest credential in the world is worth what its recovery path is worth, and that path is usually designed last.

A passwordless programme is mostly an enrolment and recovery programme wearing a different name. Plan it that way and the authentication part takes care of itself.

The sequence

Four phases, in this order

The order matters more than the content. Phase 01 without phase 00 means doing the work once per application; phase 03 without phase 02 means a strong front door and an open window.

  1. Put something in front

    Single sign-on ahead of the applications, so authentication stops being a per-application decision. Nothing is passwordless yet; everything is now changeable from one place.

    What you stop doingConfiguring authentication separately in each application

  2. Take the password off the screen

    Strong, phishing-resistant credentials for the populations and applications that justify them first. Behind the access layer, systems that still expect a password never show one to the user.

    What you stop doingAsking people to remember anything for the systems they use daily

  3. Solve enrolment and recovery

    Getting credentials onto devices at scale, and defining what happens when a device is lost or replaced — with assurance that matches the credential being restored.

    What you stop doingLetting the service desk improvise identity verification over the phone

  4. Close the remaining cases

    The legacy application, the shared workstation, the contractor on an unmanaged device. Each gets a deliberate answer rather than a permanent exception nobody revisits.

    What you stop doingMaintaining a password policy for the whole organisation because of four systems

The part nobody plans

Recovery is a flow, so design it like one

A lost phone on a Monday morning is not an edge case, it is a weekly event at any real size. When the answer is a phone call to a service desk that has no way to verify the caller, every passkey in the estate is worth exactly one convincing conversation.

Because recovery is a journey like any other, it can be given its own verification steps, its own thresholds and its own audit trail: a manager approval, a document check, a credential from a wallet, a wait state — chosen deliberately rather than improvised under pressure.

  • Lost deviceRe-enrol with assurance equal to the credential being replaced
  • Replaced deviceMigration path that does not fall back to a password
  • Service desk requestVerification the agent cannot skip, and a record that they did not
  • Executive exceptionThe most targeted population gets the strictest path, not the loosest
How Monokee approaches it

The journey decides the factor

Method chosen per population

Enrolment, sign-in, step-up and recovery are flows on one canvas. Changing which group gets which method is an edit to a diagram, not a release in every application.

The access layer absorbs the legacy

Applications that cannot be modernised sit behind single sign-on. The user authenticates once, strongly, and never meets the password the old system still wants.

Progress you can measure

What share of authentications are passwordless, for which populations, against which applications — so the programme finishes on evidence rather than on somebody declaring it finished.

Bring us the application that is blocking the rollout

There is usually one, and it is usually older than the programme. We'll tell you honestly whether it has to be solved first.

Talk to an expert