Google has extended its Credential Provider for Windows to support physical security keys, giving businesses a stronger option for protecting staff logins on Windows devices.
- What it is: The Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor, alongside existing verification options.
- Who is affected: Any organisation using Google Workspace with Windows devices managed through GCPW.
- Why it matters: Physical security keys are harder to phish or intercept than one-time codes sent by app or SMS, since they require the physical device to be present at sign-in. Businesses handling sensitive client data or subject to compliance requirements will find this a meaningful upgrade.
- What to do: Administrators can enable 2-Step Verification enforcement using hardware security keys at the Windows login screen through the Admin console. No action is required if you don't use hardware keys today, but it's worth considering for staff with higher-risk access, such as finance or admin accounts.
We recommend reviewing your Workspace security settings periodically, and this is a good opportunity to consider hardware keys for your highest-risk user accounts.