Google has extended hardware security key support for Windows sign-in, giving Google Workspace admins a stronger option for protecting staff accounts against phishing.
- What it is: The Google Credential Provider for Windows (GCPW) now supports FIDO2-compliant physical security keys as a second factor when staff log into their Windows PC.
- Who is affected: Google Workspace businesses that manage staff Windows logins through GCPW.
- What the risk is: Not a vulnerability – this is a security improvement opportunity. Businesses still relying on SMS or app-based codes remain more exposed to phishing than those using physical security keys.
- What action is needed: Consider rolling out FIDO2 hardware keys for staff with access to sensitive data, and review your 2-Step Verification settings in the Admin console.
We recommend reviewing your current second-factor authentication method and upgrading higher-risk accounts to hardware key protection where practical.
Source: Google Workspace Updates