Home 9 Business 9 What Are Passkeys, and Should Your Business Use Them?

What Are Passkeys, and Should Your Business Use Them?

Cybersecurity made simple

Passkeys: The Safer, Simpler Way to Sign In Without Passwords

Passwords have been causing businesses problems for years. They get reused, forgotten, guessed, leaked, written down, shared, and typed into fake login pages by mistake.

Passkeys are designed to fix that. Instead of typing a password, you sign in using the same fingerprint, face recognition or PIN you already use to unlock your phone or laptop.

For many businesses, especially those using Microsoft 365, passkeys are one of the most practical steps towards safer, faster, passwordless sign-ins.

/wp-content/uploads/2026/07/passkey-secure-login-phone-laptop.jpg
Suggested image: a professional, friendly visual of someone signing in with fingerprint or face recognition on a phone and laptop.

Quick summary

A passkey lets you sign in to an app or website using your fingerprint, face scan or device PIN, with no password to type. It is built on FIDO security standards and uses cryptography rather than a shared password. That means there is no password for an attacker to steal, reuse or trick out of you.

Passkeys are already supported by major platforms including Microsoft, Apple and Google, and Microsoft Entra supports passkeys for workplace sign-ins, including passkeys in Microsoft Authenticator, FIDO2 security keys and other supported passwordless methods.

Why passwords are still such a big problem

Most businesses know passwords are not perfect, but they are often treated as “good enough”. The trouble is that attackers love “good enough”.

Passwords depend on people making good choices every single time. They have to create strong passwords, avoid reusing them, spot fake login pages, resist urgent-looking emails, and never accidentally approve the wrong sign-in. That is a lot to ask when staff are busy, distracted or under pressure.

CISA has warned that traditional forms of MFA, such as SMS codes, authenticator app codes and push notifications, can still be bypassed by phishing and social engineering. In its guidance on FIDO authentication, CISA says: “Credential phishing is a sad fact of life.” It also explains that the FIDO Alliance created a phishing-resistant form of MFA.
Read CISA’s guidance on FIDO authentication.

What is a passkey?

A passkey is a password replacement. Instead of typing a password into a website, your device proves it is really you.

The FIDO Alliance describes a passkey as a FIDO authentication credential that allows a user to sign in to apps and websites using the same process they use to unlock their device, such as biometrics, PIN or pattern.
View the FIDO Alliance passkeys guide.

1. You create a passkey

Your device creates a pair of cryptographic keys for that specific website or app.

2. The private key stays private

The private key stays protected on your device. It is not shared with the website.

3. You sign in securely

You unlock the passkey with your fingerprint, face or PIN, and the website checks the response.

The important bit is this: the website never receives a password, because there is no password to receive.

/wp-content/uploads/2026/07/passkey-how-it-works-cybersecurity.jpg
Suggested image: a simple visual showing a trusted phone or laptop securely connecting to a genuine website, with no password shown.

Why passkeys are much harder to attack

A password is a shared secret. You know it, the website checks it, and attackers try to steal it. A passkey works differently. There is no reusable password and the sign-in is linked to the real website or app.

In plain English: a passkey will not work on a fake copycat website. If someone sends you to a convincing phishing page, your passkey does not simply hand over a secret. The sign-in fails because the site is not the genuine one.
Password problem How passkeys help
People reuse passwords across accounts. Each passkey is unique to the website or app it was created for.
Passwords can be typed into phishing pages. Passkeys are bound to the legitimate site, so they cannot be used on lookalike domains.
Password databases can be stolen in breaches. The website stores a public key, not a reusable password.
SMS codes and push approvals can be tricked out of people. Passkeys use phishing-resistant cryptographic authentication instead of one-time codes.

“Instead of vulnerable secrets or potentially identifiable personal information, a passkey uses a private key stored safely on the user’s device. It only works on the website or app for which the user created it.”

Microsoft Security Blog, World Passkey Day

Microsoft also explains that because a passkey only works for the website or app it was created for, users cannot be tricked into signing in to a malicious lookalike website using that passkey.
Read Microsoft’s passkey article.

Where can you use passkeys already?

Passkeys are no longer a niche technology. Major technology platforms have built support into their devices, browsers and sign-in systems.

Microsoft Support explains that you can use a passkey to sign in to a Microsoft personal, work or school account, as well as many other websites, apps and services. Microsoft also says passkeys can be saved to options such as Microsoft Password Manager, a mobile device, a security key, or Windows Hello.
View Microsoft Support’s passkey guidance.

Microsoft 365

Microsoft Entra supports passkeys, including passkeys in Microsoft Authenticator and FIDO2 security keys.

Apple, Google and Microsoft accounts

Passkeys are built into modern phones, laptops, browsers and credential managers.

More business apps

Support is growing across password managers, SaaS tools, banks and online services.

Synced passkeys vs device-bound passkeys

There are two common types of passkey your business should understand.

Type What it means Best fit
Synced passkey A passkey that can sync through a supported credential manager, such as an Apple, Google, Microsoft or third-party password manager. Everyday users who need convenience across multiple devices.
Device-bound passkey A passkey that stays on one device or security key. Administrators, finance teams, privileged accounts and higher-risk roles.

Microsoft’s guidance for Intune describes passkeys as standards-based FIDO credentials that can be either device-bound or synced across devices. It also notes that Microsoft Entra ID can use device-bound passkeys through options such as Windows Hello or Microsoft Authenticator on supported iOS and Android versions.
https://learn.microsoft.com/en-us/mem/intune/protect/passwordless-authenticationRead Microsoft’s passwordless authentication guidance.

Should your business start using passkeys?

For most businesses, yes. But the best approach is not to rip out every password overnight. The sensible route is to start with the accounts that would cause the most damage if they were compromised.

A practical rollout plan

  1. Start with your highest-risk users. Prioritise administrators, senior leaders, finance teams and anyone who can access sensitive data or approve payments.
  2. Keep a backup sign-in method. Make sure users have a second device, security key or approved recovery route before you enforce passkeys.
  3. Run passwords and passkeys side by side at first. Give staff time to get comfortable before removing older methods where appropriate.
  4. Remove weaker methods over time. SMS codes, legacy MFA and shared passwords should be reduced wherever possible.
  5. Document the recovery process. If someone loses a phone or device, your team needs a safe process to restore access without opening a back door for attackers.

Microsoft Learn states that Microsoft Authenticator passkeys for Microsoft Entra ID require iOS 17 or later, or Android 14 or later. Cross-device registration and authentication also require Bluetooth and an active internet connection on both devices.
View Microsoft Learn’s Authenticator passkey requirements.

/wp-content/uploads/2026/07/passkey-rollout-business-team.jpg
Suggested image: a small business team reviewing a simple cybersecurity rollout plan with laptops and mobile devices.

What to watch out for

Passkeys are a major security improvement, but they still need planning. Like any technology, the value comes from implementing them properly.

1. Account recovery needs to be secure

If someone loses the only device with their passkey and has no backup, they could be locked out. If recovery relies on weak methods, attackers may target the recovery process instead.

2. Not every service supports passkeys yet

Some older systems and smaller platforms still rely on passwords, so most businesses will use a mixed approach for a while.

3. Shared accounts need special attention

Passkeys are designed for individual users. If your business still has shared logins, this is a good opportunity to replace them with named accounts and proper access controls.

4. Devices must be managed properly

A passkey is only as useful as the device and recovery process around it. Businesses should also think about device security, updates, conditional access and what happens when staff leave.

Passkeys and Microsoft 365

If your organisation already uses Microsoft 365, passkeys are especially worth looking at because Microsoft Entra supports several phishing-resistant passwordless options.

Microsoft’s ACSC Essential Eight guidance lists device-bound passkeys, FIDO2 security keys, Windows Hello for Business with hardware TPM, and passkeys in Microsoft Authenticator as phishing-resistant authentication methods in Microsoft Entra.
https://learn.microsoft.com/en-us/compliance/essential-eight/e8-mfa-maturity-level-3View Microsoft’s Essential Eight MFA guidance.

Microsoft’s own passkey setup guidance also explains that the easiest and fastest way to add a passkey for a work or school account is directly in Microsoft Authenticator, provided the mobile device meets the required iOS or Android version.
https://support.microsoft.com/en-us/account-billing/set-up-a-passkey-in-microsoft-authenticatorRead Microsoft’s Authenticator passkey setup guidance.

Bespoke IT tip: If you are using Microsoft 365, start by reviewing your admin accounts, finance users, MFA methods and conditional access policies. These are usually the best places to begin strengthening sign-ins.

Frequently asked questions

What is a passkey in simple terms?

A passkey is a safer way to log in without typing a password. You use your fingerprint, face recognition or device PIN, and your device proves it is really you.

Are passkeys safer than passwords?

Yes. Passkeys are much harder to phish because they are linked to the real website or app they were created for. There is also no password for an attacker to steal, reuse or guess.

Can passkeys replace MFA?

In many cases, yes. A passkey can satisfy multi-factor authentication because it combines something you have, such as your device, with something you are or know, such as your fingerprint, face or PIN.

What happens if I lose the device with my passkey?

That depends on how the passkey was set up. Synced passkeys may be available on other trusted devices. Device-bound passkeys need a backup sign-in method or recovery process. This is why businesses should plan recovery before rolling passkeys out widely.

Does Microsoft 365 support passkeys?

Yes. Microsoft Entra supports passkeys and other passwordless authentication methods, including passkeys in Microsoft Authenticator, FIDO2 security keys and Windows Hello for Business.

Should small businesses use passkeys?

Yes, in most cases. Small businesses are regularly targeted by phishing and credential theft. Passkeys can reduce that risk and make sign-ins easier for staff when rolled out properly.

The bottom line

Passwords have been the weak point for too long. They are easy to forget, easy to reuse and far too easy to trick out of people.

Passkeys are not just another security buzzword. They are a practical way to remove the password from the login process and protect your business against one of the most common causes of cyber incidents: stolen credentials.

You do not need to move everything at once. Start with your most sensitive accounts, make sure recovery is properly planned, and build from there.

Want to make Microsoft 365 sign-ins safer?

Bespoke IT Solutions can help you review your current Microsoft 365 security setup, strengthen MFA, reduce risky password use and plan a sensible passkey rollout for your team.

If you are not sure whether your business is ready for passkeys, we can help you understand what is already available, what needs tightening, and where to start.

/contact/Speak to Bespoke IT Solutions

References and further reading

Recent Posts

How are cyber attacks effecting your insurance?

How are cyber attacks effecting your insurance?

Cyber Insurance Renewal: What’s Changed and How to Avoid Claim Denial If your cyber insurance renewal feels harder this year, you’re not alone. Right now, many businesses are facing longer forms, tougher questions, and more pressure to prove their security. As a...

Could Someone Send Emails Pretending To Be Your Business

Could Someone Send Emails Pretending To Be Your Business

Cyber Security Guide Could Someone Send Emails Pretending To Be Your Business? Email spoofing is one of the simplest ways scammers can damage trust in your business. The good news is that three DNS records — SPF, DKIM and DMARC — can make it much harder for criminals...

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships

Continuous Digital Transformation Partnerships Why outsourcing is no longer about handing work off, but moving forward together For many organisations, change never really stops. You upgrade one system, and another starts to fall behind. You move to the cloud, and...

5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today

5 Microsoft 365 Settings You Should Check Today (Especially if Your Setup Is a Few Years Old) If your Microsoft 365 system was set up a few years ago, there’s a good chance it’s not as secure as you think. Microsoft has improved security defaults over time. But those...

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be You?

Could a Cyber Criminal Send Emails Pretending to Be Your Company Today? Imagine one of your customers receives an email from what appears to be your accounts department. The branding looks correct. The signature looks genuine. The email address seems legitimate. The...

How Outsourcing Is Driving Innovation in UK Businesses

How Outsourcing Is Driving Innovation in UK Businesses

Beyond Cost Savings: Outsourcing for Innovation Why UK businesses are turning IT partners into growth drivers The problem For a long time, outsourcing was just about saving money. You handed over IT tasks, reduced costs, and kept things running. But today, that...

How secure is your backup solution?

How secure is your backup solution?

Immutable Backups: The Cyber Insurance Question That Catches Businesses Out Immutable backups are now one of the most important parts of cyber insurance and ransomware protection. However, many businesses are not sure what they are or whether they already have them in...

What to do in case of a cyber attack

What to do in case of a cyber attack

Cyberattack? Here's Exactly What Your Business Should Do in the First Hour It's 2pm on a normal Monday. Your team are busy working, emails are flowing, and everything seems normal. Then suddenly something isn't right. Files won't open. Systems are running strangely. A...

Small businesses are still targets of cyber attacks.

Small businesses are still targets of cyber attacks.

A ransomware attack on a small business does not happen overnight. Instead, it builds step by step, often starting with simple mistakes that go unnoticed. In fact, many attacks succeed because of small gaps rather than complex hacking. So in this guide, we will walk...