Google has added support for physical security keys as a second login factor for Windows devices managed through Google Workspace, giving businesses a stronger option than app-based codes for protecting staff accounts.
- What it is: The Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant security keys, meaning staff can tap a physical key to verify their identity when logging into a Windows PC, not just when signing into Google apps.
- Who is affected: Businesses using Google Workspace with Windows devices managed through GCPW.
- The benefit: Physical security keys are harder to phish than SMS codes or authenticator apps, closing off a common way attackers get into business accounts.
- What to do: This is an optional feature administrators need to enable and roll out. It is not turned on automatically.
We recommend businesses handling sensitive data consider hardware security keys for their most exposed accounts, such as finance and admin roles. Get in touch if you would like help assessing whether this fits your environment.