Google has updated its Credential Provider for Windows to support physical security keys, giving businesses a stronger way to protect staff logins on Windows devices linked to Google Workspace.
- What it is: An update to Google Credential Provider for Windows (GCPW) that adds support for FIDO2-compliant physical security keys as a second factor when staff log into Windows.
- Who is affected: Businesses using Google Workspace with staff logging into Windows PCs via GCPW.
- What the risk is: This isn't a vulnerability, it's a security improvement. Without it, businesses relying on weaker forms of two-step verification (like SMS codes) remain more exposed to phishing and account takeover.
- What action is needed: Administrators can now enforce 2-step verification using hardware security keys at the Windows login screen, rather than relying on phone-based codes that can be intercepted or socially engineered.
We recommend businesses handling sensitive data consider rolling out hardware security keys for staff with Windows devices, particularly for admin and finance accounts.
Source: Google Workspace Updates blog