What Are Passkeys, and Should Your Business Use Them?
Passwords are the weakest part of most business accounts. People reuse them, forget them and get tricked into typing them into fake sites. Passkeys are a newer way to sign in that removes most of those problems, and they are increasingly available in the tools you already use.
What a passkey is
A passkey is a sign-in method that replaces the password. Instead of typing a secret, you approve the sign-in with something you already use to unlock your device: a fingerprint, your face or a PIN. Behind the scenes, your device holds a private key that never leaves it, and the website holds the matching public key.
Passkeys follow an open standard called FIDO2, backed by Microsoft, Apple and Google, so they work across major devices and browsers.
Why they are harder to attack than passwords
- Nothing to steal on the website. The website stores only the public half. A breach of the site does not expose anything an attacker can use to sign in.
- Nothing to type into a fake page. A passkey is tied to the real website’s address. If you land on a lookalike site, your device will not offer it. That blocks the phishing pages that defeat passwords and text message codes.
- Nothing to guess or reuse. Each passkey is unique to one site.
Government cybersecurity guidance, including CISA’s, points to this kind of phishing-resistant sign-in as the strongest practical protection against the account takeovers that start most business incidents. See our post on why text message codes are no longer enough.
Where you can use them already
Many major services support passkeys, including Microsoft accounts, Google, Apple, and a growing list of banks, shopping sites and business tools. For businesses, Microsoft Entra ID, which powers Microsoft 365 sign-in, lets administrators allow passkeys and FIDO2 security keys, including passkeys in the Microsoft Authenticator app. Availability and settings vary by service and by plan, so ask your IT provider what applies to your accounts.
Should your business use them?
For most small businesses, yes, in stages. Passkeys are a strong fit for:
- Administrators and anyone with access to money or customer data, since these accounts are the biggest targets.
- Email and Microsoft 365 accounts, which attackers try first.
- Staff who struggle with passwords, since a fingerprint is easier than a long password.
You do not have to switch everything at once. Many organizations begin with administrators and a pilot group, learn what works, and expand.
What to watch out for
- Lost or replaced devices. Plan recovery before you need it. Passkeys can be stored on a single device or synced through a platform such as a Microsoft, Google or Apple account. Register more than one method for each important account, and have an identity check process for lost devices.
- Shared computers and shared accounts. Passkeys suit personal sign-ins on a person’s own device. Shared accounts and shared workstations need a different approach, such as hardware security keys or separate accounts.
- Older systems. Some software and websites do not support passkeys yet, so you will keep passwords and multi-factor authentication for them for a while.
- Mixed methods. Keep strong multi-factor authentication on accounts that cannot use passkeys, and turn off weaker methods when everyone has a stronger one.
How to get started with passkeys
- Turn on multi-factor authentication everywhere, and move from text codes to an authenticator app.
- Enable passkeys or security keys for administrators and finance staff.
- Document recovery steps and register a backup method for each person.
- Train staff with a short walk-through, and keep the old method available briefly.
- Expand to everyone, then retire weaker methods.
Our Microsoft 365 support covers multi-factor authentication and access policies, and passkeys are something we are glad to discuss as part of that. A free security review looks at how your accounts and passwords are protected today.
Frequently asked questions
What is a passkey in simple terms?
A passkey lets you sign in with your fingerprint, face or device PIN instead of typing a password. A secret stays on your device and proves it is really you to the website.
Are passkeys safer than passwords?
Yes, in most cases. They cannot be guessed, reused or typed into a fake website, and a breach of the site does not expose a password to steal.
What happens if I lose the device with my passkey?
If you have set up recovery, such as a second device, a security key or a verified reset process through your IT provider, you can sign in again. This is why registering a backup method matters.
Does Microsoft 365 support passkeys?
Yes. Microsoft Entra ID supports passkeys and FIDO2 security keys as sign-in methods, and administrators can enable them. What is available depends on your configuration and plan.
Do passkeys replace multi-factor authentication?
A passkey can serve as strong multi-factor authentication on its own, since it combines something you have, the device, with something you are or know, the fingerprint or PIN. Some accounts and services still need other methods alongside it.
