Google has added support for physical security keys as a second login step for Windows devices managed through Google Workspace, giving businesses a stronger alternative to password-based sign-in.
- What it is: The Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant hardware security keys as a second factor when staff sign in to Windows.
- Who is affected: Businesses using Google Workspace with GCPW to manage Windows devices and enforce two-step verification.
- The risk: Nothing changes automatically, but businesses relying only on passwords or SMS codes remain more exposed to phishing than those using hardware keys.
- What to do: Administrators can enable hardware security key support through the Google Admin console and roll physical keys out to staff who handle sensitive data.
This is an optional upgrade rather than an urgent patch, and we recommend it for any business wanting to move staff away from password-only sign-in. See Google's Workspace Updates blog for details.