Google has rolled out a new option letting businesses require a physical security key to sign in to Windows devices through Google Workspace, adding a much stronger layer of protection than passwords or SMS codes.
- What it is: The Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant hardware security keys, plus passkeys stored on a nearby Bluetooth-connected phone, as a second factor at the Windows login screen.
- Who is affected: Businesses using Google Workspace to manage Windows PCs. The feature is rolling out gradually and is controlled by administrators; there is no setting for individual users to turn it on themselves.
- Why it matters: Hardware security keys are far harder for attackers to phish or intercept than passwords or text-message codes, closing off one of the most common ways accounts get compromised.
- What to do: If your business runs Google Workspace alongside Windows machines, talk to your IT provider about enforcing security keys for admins and any staff with access to sensitive data.
We are happy to help assess whether hardware security keys are a good fit for your business.
Source: Google Workspace Updates.