Passkeys: The Safer, Simpler Way to Sign In Without Passwords
Passwords have been causing businesses problems for years. They get reused, forgotten, guessed, leaked, written down, shared, and typed into fake login pages by mistake.
Passkeys are designed to fix that. Instead of typing a password, you sign in using the same fingerprint, face recognition or PIN you already use to unlock your phone or laptop.
For many businesses, especially those using Microsoft 365, passkeys are one of the most practical steps towards safer, faster, passwordless sign-ins.
Quick summary
A passkey lets you sign in to an app or website using your fingerprint, face scan or device PIN, with no password to type. It is built on FIDO security standards and uses cryptography rather than a shared password. That means there is no password for an attacker to steal, reuse or trick out of you.
Passkeys are already supported by major platforms including Microsoft, Apple and Google, and Microsoft Entra supports passkeys for workplace sign-ins, including passkeys in Microsoft Authenticator, FIDO2 security keys and other supported passwordless methods.
Why passwords are still such a big problem
Most businesses know passwords are not perfect, but they are often treated as “good enough”. The trouble is that attackers love “good enough”.
Passwords depend on people making good choices every single time. They have to create strong passwords, avoid reusing them, spot fake login pages, resist urgent-looking emails, and never accidentally approve the wrong sign-in. That is a lot to ask when staff are busy, distracted or under pressure.
CISA has warned that traditional forms of MFA, such as SMS codes, authenticator app codes and push notifications, can still be bypassed by phishing and social engineering. In its guidance on FIDO authentication, CISA says: “Credential phishing is a sad fact of life.” It also explains that the FIDO Alliance created a phishing-resistant form of MFA.
Read CISA’s guidance on FIDO authentication.
What is a passkey?
A passkey is a password replacement. Instead of typing a password into a website, your device proves it is really you.
The FIDO Alliance describes a passkey as a FIDO authentication credential that allows a user to sign in to apps and websites using the same process they use to unlock their device, such as biometrics, PIN or pattern.
View the FIDO Alliance passkeys guide.
1. You create a passkey
Your device creates a pair of cryptographic keys for that specific website or app.
2. The private key stays private
The private key stays protected on your device. It is not shared with the website.
3. You sign in securely
You unlock the passkey with your fingerprint, face or PIN, and the website checks the response.
The important bit is this: the website never receives a password, because there is no password to receive.
Why passkeys are much harder to attack
A password is a shared secret. You know it, the website checks it, and attackers try to steal it. A passkey works differently. There is no reusable password and the sign-in is linked to the real website or app.
| Password problem | How passkeys help |
|---|---|
| People reuse passwords across accounts. | Each passkey is unique to the website or app it was created for. |
| Passwords can be typed into phishing pages. | Passkeys are bound to the legitimate site, so they cannot be used on lookalike domains. |
| Password databases can be stolen in breaches. | The website stores a public key, not a reusable password. |
| SMS codes and push approvals can be tricked out of people. | Passkeys use phishing-resistant cryptographic authentication instead of one-time codes. |
“Instead of vulnerable secrets or potentially identifiable personal information, a passkey uses a private key stored safely on the user’s device. It only works on the website or app for which the user created it.”
Microsoft Security Blog, World Passkey Day
Microsoft also explains that because a passkey only works for the website or app it was created for, users cannot be tricked into signing in to a malicious lookalike website using that passkey.
Read Microsoft’s passkey article.
Where can you use passkeys already?
Passkeys are no longer a niche technology. Major technology platforms have built support into their devices, browsers and sign-in systems.
Microsoft Support explains that you can use a passkey to sign in to a Microsoft personal, work or school account, as well as many other websites, apps and services. Microsoft also says passkeys can be saved to options such as Microsoft Password Manager, a mobile device, a security key, or Windows Hello.
View Microsoft Support’s passkey guidance.
Microsoft 365
Microsoft Entra supports passkeys, including passkeys in Microsoft Authenticator and FIDO2 security keys.
Apple, Google and Microsoft accounts
Passkeys are built into modern phones, laptops, browsers and credential managers.
More business apps
Support is growing across password managers, SaaS tools, banks and online services.
Synced passkeys vs device-bound passkeys
There are two common types of passkey your business should understand.
| Type | What it means | Best fit |
|---|---|---|
| Synced passkey | A passkey that can sync through a supported credential manager, such as an Apple, Google, Microsoft or third-party password manager. | Everyday users who need convenience across multiple devices. |
| Device-bound passkey | A passkey that stays on one device or security key. | Administrators, finance teams, privileged accounts and higher-risk roles. |
Microsoft’s guidance for Intune describes passkeys as standards-based FIDO credentials that can be either device-bound or synced across devices. It also notes that Microsoft Entra ID can use device-bound passkeys through options such as Windows Hello or Microsoft Authenticator on supported iOS and Android versions.
https://learn.microsoft.com/en-us/mem/intune/protect/passwordless-authenticationRead Microsoft’s passwordless authentication guidance.
Should your business start using passkeys?
For most businesses, yes. But the best approach is not to rip out every password overnight. The sensible route is to start with the accounts that would cause the most damage if they were compromised.
A practical rollout plan
- Start with your highest-risk users. Prioritise administrators, senior leaders, finance teams and anyone who can access sensitive data or approve payments.
- Keep a backup sign-in method. Make sure users have a second device, security key or approved recovery route before you enforce passkeys.
- Run passwords and passkeys side by side at first. Give staff time to get comfortable before removing older methods where appropriate.
- Remove weaker methods over time. SMS codes, legacy MFA and shared passwords should be reduced wherever possible.
- Document the recovery process. If someone loses a phone or device, your team needs a safe process to restore access without opening a back door for attackers.
Microsoft Learn states that Microsoft Authenticator passkeys for Microsoft Entra ID require iOS 17 or later, or Android 14 or later. Cross-device registration and authentication also require Bluetooth and an active internet connection on both devices.
View Microsoft Learn’s Authenticator passkey requirements.
What to watch out for
Passkeys are a major security improvement, but they still need planning. Like any technology, the value comes from implementing them properly.
1. Account recovery needs to be secure
If someone loses the only device with their passkey and has no backup, they could be locked out. If recovery relies on weak methods, attackers may target the recovery process instead.
2. Not every service supports passkeys yet
Some older systems and smaller platforms still rely on passwords, so most businesses will use a mixed approach for a while.
3. Shared accounts need special attention
Passkeys are designed for individual users. If your business still has shared logins, this is a good opportunity to replace them with named accounts and proper access controls.
4. Devices must be managed properly
A passkey is only as useful as the device and recovery process around it. Businesses should also think about device security, updates, conditional access and what happens when staff leave.
Passkeys and Microsoft 365
If your organisation already uses Microsoft 365, passkeys are especially worth looking at because Microsoft Entra supports several phishing-resistant passwordless options.
Microsoft’s ACSC Essential Eight guidance lists device-bound passkeys, FIDO2 security keys, Windows Hello for Business with hardware TPM, and passkeys in Microsoft Authenticator as phishing-resistant authentication methods in Microsoft Entra.
https://learn.microsoft.com/en-us/compliance/essential-eight/e8-mfa-maturity-level-3View Microsoft’s Essential Eight MFA guidance.
Microsoft’s own passkey setup guidance also explains that the easiest and fastest way to add a passkey for a work or school account is directly in Microsoft Authenticator, provided the mobile device meets the required iOS or Android version.
https://support.microsoft.com/en-us/account-billing/set-up-a-passkey-in-microsoft-authenticatorRead Microsoft’s Authenticator passkey setup guidance.
Frequently asked questions
What is a passkey in simple terms?
A passkey is a safer way to log in without typing a password. You use your fingerprint, face recognition or device PIN, and your device proves it is really you.
Are passkeys safer than passwords?
Yes. Passkeys are much harder to phish because they are linked to the real website or app they were created for. There is also no password for an attacker to steal, reuse or guess.
Can passkeys replace MFA?
In many cases, yes. A passkey can satisfy multi-factor authentication because it combines something you have, such as your device, with something you are or know, such as your fingerprint, face or PIN.
What happens if I lose the device with my passkey?
That depends on how the passkey was set up. Synced passkeys may be available on other trusted devices. Device-bound passkeys need a backup sign-in method or recovery process. This is why businesses should plan recovery before rolling passkeys out widely.
Does Microsoft 365 support passkeys?
Yes. Microsoft Entra supports passkeys and other passwordless authentication methods, including passkeys in Microsoft Authenticator, FIDO2 security keys and Windows Hello for Business.
Should small businesses use passkeys?
Yes, in most cases. Small businesses are regularly targeted by phishing and credential theft. Passkeys can reduce that risk and make sign-ins easier for staff when rolled out properly.
The bottom line
Passwords have been the weak point for too long. They are easy to forget, easy to reuse and far too easy to trick out of people.
Passkeys are not just another security buzzword. They are a practical way to remove the password from the login process and protect your business against one of the most common causes of cyber incidents: stolen credentials.
You do not need to move everything at once. Start with your most sensitive accounts, make sure recovery is properly planned, and build from there.
Want to make Microsoft 365 sign-ins safer?
Bespoke IT Solutions can help you review your current Microsoft 365 security setup, strengthen MFA, reduce risky password use and plan a sensible passkey rollout for your team.
If you are not sure whether your business is ready for passkeys, we can help you understand what is already available, what needs tightening, and where to start.
/contact/Speak to Bespoke IT Solutions
References and further reading
- FIDO Alliance: Passkeys
- CISA: Next Level MFA — FIDO Authentication
- Microsoft Security Blog: World Passkey Day
- Microsoft Support: Create and save a passkey
- Microsoft Learn: Enable passkeys in Authenticator for Microsoft Entra ID
- https://learn.microsoft.com/en-us/compliance/essential-eight/e8-mfa-maturity-level-3Microsoft Learn: Essential Eight MFA Maturity Level 3 with Microsoft Entra












