A practical, phone-free MFA alternative for frontline retail
Most MFA frameworks were built for office workers who sit at assigned desks, carry a personal phone throughout the day, and log in once in the morning.
Retail was an afterthought, if it was considered at all. Now, when security teams in retail environments try to enforce MFA on the store floor, they quickly discover that the assumptions baked into those frameworks simply do not hold.
In many retail environments, associates don't have phones on the floor. Devices stay in lockers, which eliminates the most common MFA factor before the conversation even starts.
Why passkeys work brilliantly, and where they hit their limits
Passkeys have earned their reputation. They are FIDO2-certified, phishing-resistant, and a genuine improvement over passwords for almost every workforce context. For office workers authenticating from an assigned laptop or a personal phone, passkeys are close to ideal.
The store floor is a different environment. Passkeys are bound to a device: a phone in a locker, or a workstation that ten associates will share over a single shift.
When the device is personal and always on-hand, that binding is a feature. When the device is shared and the person isn't, that binding becomes a liability. A passkey doesn't know who is sitting down at the terminal; it only knows that someone with access to the device is there.
Any credential architecture designed around device ownership runs into friction when device ownership doesn't map cleanly to individual workers. Passkeys belong in your authentication strategy, but may not be the sole answer for shared-workstation frontline environments.
1Kosmos supports passkeys for the worker populations where they fit, and extends that coverage to the environments where they don't.
The practical question is: what fills the gap where device-bound authentication can't follow the worker?
Why unattended hardware tokens fall short on the store floor
When phone-based authentication is off the table and passkeys can't anchor to a personal device, many teams turn to hardware tokens as the logical fallback, which is a reasonable instinct. But the dynamics of a shared workstation environment expose a problem that practitioners articulate precisely: if a token sits plugged into a terminal all shift while the associate moves around the store, it is not really a second factor anymore. It's a first factor that anyone nearby can use, and the shift change moment is where that gap is most exposed.
The value of something you have as an authentication principle depends entirely on the right person actually having it. An unattended token that lives at a station rather than on a person offers no meaningful accountability; the possession factor becomes a property of the workstation, not the worker.
A biometric hardware key that requires the enrolled individual to unlock it before use is a completely different model, and we'll get to that.
The problem with unattended tokens is that they can be used by anyone standing at the terminal, not only the person they were assigned to.
That's a structural mismatch, and reconfiguring the token policy does not resolve it.
When the credential becomes the person
Biometric authentication resolves this from a different direction entirely, by eliminating the gap between the credential and the individual. There is nothing to leave behind, nothing that can be borrowed, and nothing that can be used by whoever happens to be standing at the terminal.
1Kosmos supports two paths for frontline environments, and teams often deploy both depending on the workstation setup.
LiveID (face biometric via the terminal camera): With LiveID, an associate enrolls once and authenticates from any shared device, anywhere in the store, using their face. There is no token to manage, no phone required, and no credential that outlasts the person using it. The same associate who clocked in at the front register can walk to the stockroom, pick up where they left off on a different terminal, and the system knows exactly who is there.
1Key (fingerprint biometric via a dedicated hardware device): For environments where a camera-based workflow isn't the right fit, 1Key is a physical authentication device built specifically for shared-workstation deployment.
Unlike a conventional hardware token, 1Key requires the enrolled individual's fingerprint to unlock, making the possession factor inseparable from the biometric factor. An associate enrolls once; that enrollment follows them to every 1Key on the network. Multiple users can be enrolled per device, which means the hardware works for the whole team without credential sharing or token handoff.
The enrollment happens once. From there, the credential travels with the associate, not with the hardware and not with a device left in a locker.
Both paths are FIDO2-aligned and phishing-resistant, which means they integrate cleanly into environments where passkeys are already deployed for other worker populations. The frontline gets strong authentication that fits how they actually work. The security team gets consistency across the organization.
Authentication that holds up on the store floor
1Kosmos authentication works in retail environments with limited connectivity, meaning coverage gaps on the floor do not create exceptions or workarounds that weaken the overall approach.
For teams already running Microsoft Entra ID or Active Directory, 1Kosmos integrates natively, so there is no parallel system to manage. Login friction comes down measurably as well.
When an associate can authenticate in seconds at the start of a shift, using their face at the terminal or a tap of their finger on a 1Key, the security control stops being a source of delay and becomes invisible in the right way, letting the right people in and keeping everyone else out.
Get the full details below, or talk to the 1Kosmos team about what a rollout looks like for a retail environment like yours.
A practical, phone-free MFA alternative for frontline retail
Most MFA frameworks were built for office workers who sit at assigned desks, carry a personal phone throughout the day, and log in once in the morning.
Retail was an afterthought, if it was considered at all. Now, when security teams in retail environments try to enforce MFA on the store floor, they quickly discover that the assumptions baked into those frameworks simply do not hold.
In many retail environments, associates don't have phones on the floor. Devices stay in lockers, which eliminates the most common MFA factor before the conversation even starts.
Why passkeys work brilliantly, and where they hit their limits
Passkeys have earned their reputation. They are FIDO2-certified, phishing-resistant, and a genuine improvement over passwords for almost every workforce context. For office workers authenticating from an assigned laptop or a personal phone, passkeys are close to ideal.
The store floor is a different environment. Passkeys are bound to a device: a phone in a locker, or a workstation that ten associates will share over a single shift.
When the device is personal and always on-hand, that binding is a feature. When the device is shared and the person isn't, that binding becomes a liability. A passkey doesn't know who is sitting down at the terminal; it only knows that someone with access to the device is there.
Any credential architecture designed around device ownership runs into friction when device ownership doesn't map cleanly to individual workers. Passkeys belong in your authentication strategy, but may not be the sole answer for shared-workstation frontline environments.
1Kosmos supports passkeys for the worker populations where they fit, and extends that coverage to the environments where they don't.
The practical question is: what fills the gap where device-bound authentication can't follow the worker?
Why unattended hardware tokens fall short on the store floor
When phone-based authentication is off the table and passkeys can't anchor to a personal device, many teams turn to hardware tokens as the logical fallback, which is a reasonable instinct. But the dynamics of a shared workstation environment expose a problem that practitioners articulate precisely: if a token sits plugged into a terminal all shift while the associate moves around the store, it is not really a second factor anymore. It's a first factor that anyone nearby can use, and the shift change moment is where that gap is most exposed.
The value of something you have as an authentication principle depends entirely on the right person actually having it. An unattended token that lives at a station rather than on a person offers no meaningful accountability; the possession factor becomes a property of the workstation, not the worker.
A biometric hardware key that requires the enrolled individual to unlock it before use is a completely different model, and we'll get to that.
The problem with unattended tokens is that they can be used by anyone standing at the terminal, not only the person they were assigned to.
That's a structural mismatch, and reconfiguring the token policy does not resolve it.
When the credential becomes the person
Biometric authentication resolves this from a different direction entirely, by eliminating the gap between the credential and the individual. There is nothing to leave behind, nothing that can be borrowed, and nothing that can be used by whoever happens to be standing at the terminal.
1Kosmos supports two paths for frontline environments, and teams often deploy both depending on the workstation setup.
LiveID (face biometric via the terminal camera): With LiveID, an associate enrolls once and authenticates from any shared device, anywhere in the store, using their face. There is no token to manage, no phone required, and no credential that outlasts the person using it. The same associate who clocked in at the front register can walk to the stockroom, pick up where they left off on a different terminal, and the system knows exactly who is there.
1Key (fingerprint biometric via a dedicated hardware device): For environments where a camera-based workflow isn't the right fit, 1Key is a physical authentication device built specifically for shared-workstation deployment.
Unlike a conventional hardware token, 1Key requires the enrolled individual's fingerprint to unlock, making the possession factor inseparable from the biometric factor. An associate enrolls once; that enrollment follows them to every 1Key on the network. Multiple users can be enrolled per device, which means the hardware works for the whole team without credential sharing or token handoff.
The enrollment happens once. From there, the credential travels with the associate, not with the hardware and not with a device left in a locker.
Both paths are FIDO2-aligned and phishing-resistant, which means they integrate cleanly into environments where passkeys are already deployed for other worker populations. The frontline gets strong authentication that fits how they actually work. The security team gets consistency across the organization.
Authentication that holds up on the store floor
1Kosmos authentication works in retail environments with limited connectivity, meaning coverage gaps on the floor do not create exceptions or workarounds that weaken the overall approach.
For teams already running Microsoft Entra ID or Active Directory, 1Kosmos integrates natively, so there is no parallel system to manage. Login friction comes down measurably as well.
When an associate can authenticate in seconds at the start of a shift, using their face at the terminal or a tap of their finger on a 1Key, the security control stops being a source of delay and becomes invisible in the right way, letting the right people in and keeping everyone else out.
Get the full details below, or talk to the 1Kosmos team about what a rollout looks like for a retail environment like yours.
A practical, phone-free MFA alternative for frontline retail
Most MFA frameworks were built for office workers who sit at assigned desks, carry a personal phone throughout the day, and log in once in the morning.
Retail was an afterthought, if it was considered at all. Now, when security teams in retail environments try to enforce MFA on the store floor, they quickly discover that the assumptions baked into those frameworks simply do not hold.
In many retail environments, associates don't have phones on the floor. Devices stay in lockers, which eliminates the most common MFA factor before the conversation even starts.
Why passkeys work brilliantly, and where they hit their limits
Passkeys have earned their reputation. They are FIDO2-certified, phishing-resistant, and a genuine improvement over passwords for almost every workforce context. For office workers authenticating from an assigned laptop or a personal phone, passkeys are close to ideal.
The store floor is a different environment. Passkeys are bound to a device: a phone in a locker, or a workstation that ten associates will share over a single shift.
When the device is personal and always on-hand, that binding is a feature. When the device is shared and the person isn't, that binding becomes a liability. A passkey doesn't know who is sitting down at the terminal; it only knows that someone with access to the device is there.
Any credential architecture designed around device ownership runs into friction when device ownership doesn't map cleanly to individual workers. Passkeys belong in your authentication strategy, but may not be the sole answer for shared-workstation frontline environments.
1Kosmos supports passkeys for the worker populations where they fit, and extends that coverage to the environments where they don't.
The practical question is: what fills the gap where device-bound authentication can't follow the worker?
Why unattended hardware tokens fall short on the store floor
When phone-based authentication is off the table and passkeys can't anchor to a personal device, many teams turn to hardware tokens as the logical fallback, which is a reasonable instinct. But the dynamics of a shared workstation environment expose a problem that practitioners articulate precisely: if a token sits plugged into a terminal all shift while the associate moves around the store, it is not really a second factor anymore. It's a first factor that anyone nearby can use, and the shift change moment is where that gap is most exposed.
The value of something you have as an authentication principle depends entirely on the right person actually having it. An unattended token that lives at a station rather than on a person offers no meaningful accountability; the possession factor becomes a property of the workstation, not the worker.
A biometric hardware key that requires the enrolled individual to unlock it before use is a completely different model, and we'll get to that.
The problem with unattended tokens is that they can be used by anyone standing at the terminal, not only the person they were assigned to.
That's a structural mismatch, and reconfiguring the token policy does not resolve it.
When the credential becomes the person
Biometric authentication resolves this from a different direction entirely, by eliminating the gap between the credential and the individual. There is nothing to leave behind, nothing that can be borrowed, and nothing that can be used by whoever happens to be standing at the terminal.
1Kosmos supports two paths for frontline environments, and teams often deploy both depending on the workstation setup.
LiveID (face biometric via the terminal camera): With LiveID, an associate enrolls once and authenticates from any shared device, anywhere in the store, using their face. There is no token to manage, no phone required, and no credential that outlasts the person using it. The same associate who clocked in at the front register can walk to the stockroom, pick up where they left off on a different terminal, and the system knows exactly who is there.
1Key (fingerprint biometric via a dedicated hardware device): For environments where a camera-based workflow isn't the right fit, 1Key is a physical authentication device built specifically for shared-workstation deployment.
Unlike a conventional hardware token, 1Key requires the enrolled individual's fingerprint to unlock, making the possession factor inseparable from the biometric factor. An associate enrolls once; that enrollment follows them to every 1Key on the network. Multiple users can be enrolled per device, which means the hardware works for the whole team without credential sharing or token handoff.
The enrollment happens once. From there, the credential travels with the associate, not with the hardware and not with a device left in a locker.
Both paths are FIDO2-aligned and phishing-resistant, which means they integrate cleanly into environments where passkeys are already deployed for other worker populations. The frontline gets strong authentication that fits how they actually work. The security team gets consistency across the organization.
Authentication that holds up on the store floor
1Kosmos authentication works in retail environments with limited connectivity, meaning coverage gaps on the floor do not create exceptions or workarounds that weaken the overall approach.
For teams already running Microsoft Entra ID or Active Directory, 1Kosmos integrates natively, so there is no parallel system to manage. Login friction comes down measurably as well.
When an associate can authenticate in seconds at the start of a shift, using their face at the terminal or a tap of their finger on a 1Key, the security control stops being a source of delay and becomes invisible in the right way, letting the right people in and keeping everyone else out.
Get the full details below, or talk to the 1Kosmos team about what a rollout looks like for a retail environment like yours.
The latest in identity security.
Enter our orbit.
The latest in identity security.
Enter our orbit.
The latest in identity security.








