With the implementation of increasingly sophisticated cybersecurity technology, hackers have turned to social engineering to steal companies’ valuable data. The last couple of years have seen explosive growth in phishing attacks, many involving impersonation of employees. This makes authentic identities a cornerstone of any corporate cyber security posture. Carmax has implemented an identity and access management solution by partners Axiad and IDEMIA that uses IDEMIA’s PIV-based smart cards as a combined physical and digital access token, with certificate-based authentication (CBA) and identity and access management (IAM) system from Axiad. This talk discusses how this has been implemented by Carmax and how this passwordless, token-based solution can serve as an effective means for protecting sensitive corporate data.