Google has updated its Credential Provider for Windows to support physical security keys as a second login factor, giving businesses a stronger option for protecting Windows sign-in.
- What it is: FIDO2-compliant physical security keys (such as a YubiKey) can now be used as the second factor when signing into Windows devices managed through Google Credential Provider for Windows (GCPW).
- Who is affected: Businesses using Google Workspace with GCPW to manage Windows device logins.
- The benefit: Hardware keys are harder to phish than SMS codes or authenticator app prompts, because they require physical possession of the device.
- What to do: If you use GCPW for Windows sign-in, ask your IT provider whether enabling hardware key support is worthwhile for staff who handle sensitive data or have admin access.
This is an optional upgrade rather than an urgent fix, but it is worth considering for your higher-risk accounts.