IT & SupportIT SupportMicrosoft 365Server SolutionsVirtualisationCyber SecurityCyber SecuritySavvy SecureEmail SolutionsAccess ControlCCTVConnectivity & CommsBusiness Phone SystemsProfessional CommunicationNetwork & WiFiMobile ConnectivityBroadband CheckerWeb & DigitalWeb DesignAll servicesResource CentreKnowledge HubGuidesMicrosoft 365Cyber SecurityIT SupportPhones & BroadbandCCTV & Security SystemsPlanning & ProductivityAll resources by topicCompanyLocationsFAQsAboutContactGet a Quote
Cyber Security

What are passkeys, and are they safe for your business?

Employee using a fingerprint to approve a secure sign-in

This is for a small business owner who has started seeing passkey prompts and wants a straight answer before asking staff to use them. It explains what a passkey does, why it is safer than a password and a code, the limits to plan for, and the Microsoft change that makes this relevant to Microsoft 365 users.

The short version

A passkey is a secure, passwordless way to sign in to an app or website using the lock on a device you already use. That might be a fingerprint, face check or device PIN. The NCSC describes it as a secure, passwordless authentication method and recommends that users choose passkeys over passwords wherever they are available.

It is not simply a more convenient password. A passkey is built on the FIDO2 standard and is a complete alternative to a traditional password. You unlock it on your own device, then the device proves to the genuine website or app that it holds the right passkey. For a useful comparison with older second-factor methods, read our explanation of what multi-factor authentication is.

What happens when you sign in

Behind the scenes, a passkey is a pair of keys. The private key stays on the user's device or security key. The service stores only the matching public key. When someone signs in, the service sends a challenge and the device signs it with the private key. No shared password travels between the user and the service.

This matters because there is no secret for a criminal to capture, reuse or persuade somebody to hand over. The fingerprint or face check is local to the device, and biometric data is not sent to the website or app. A passkey is also tied to the specific site or app where it was created. A lookalike phishing domain cannot ask for the real passkey, which is why passkeys are called phishing-resistant.

They avoid password reuse, credential stuffing, password-database breaches and password spraying. Unlike codes and push approvals, there is no code or approval for a user to pass to an attacker, so they resist MFA fatigue and push-bombing too. A passkey is a useful improvement for email, cloud files and other accounts staff use every day, but it does not remove the need for the wider checks in our Microsoft 365 security guide.

The trade-offs to decide before rollout

The real planning problem is recovery. If a phone is lost and it was the only registered method, a member of staff can be locked out. Every user needs a second registered method or a documented recovery route. This needs ownership, not a vague instruction to contact IT when something goes wrong.

Synced passkeys live in a platform credential manager, such as iCloud Keychain or Google Password Manager, and can sync across a user's devices. They are easier to recover, but depend on the user's Apple or Google account. Device-bound passkeys, including Microsoft Authenticator passkeys, Entra passkeys on Windows and FIDO2 security keys, stay on one device or key. They are tighter, but need a replacement plan.

  • Not every business application supports passkeys yet, so passwords will not disappear from a small business overnight. A password manager still has a job.
  • Shared or hot-desk devices, kiosks and staff without smartphones need a deliberate approach. A FIDO2 security key is the usual answer.
  • BYOD can be a fair concern. Some staff will not want a work credential on a personal phone, and a security key avoids that argument.
  • Choose the method around the person's devices and working pattern, not just the easiest option for the administrator.

These are reasons to plan, not reasons to avoid passkeys. The right choice can vary between a member of staff using their own phone, a Windows desktop user and somebody who works on a shared device. TSS can help businesses in Bury and Greater Manchester put the supporting cyber security basics in the right order.

What the NCSC and Cyber Essentials position means

The NCSC is the UK government's technical authority on cyber security and part of GCHQ. It recommends passkeys over passwords wherever they are available. In its April 2026 position, the NCSC said passkeys should be the default authentication option for consumers and that it no longer recommends individuals use passwords where passkeys are available. That is useful direction for a business, not a formal business mandate.

Passkeys are not compulsory for Cyber Essentials. However, the requirements that took effect from April 2026 make MFA on a cloud service pass or fail when that service offers MFA. The update also puts more emphasis on passwordless authentication and promotes passkeys. For the broader context, see our Cyber Essentials guide for Greater Manchester businesses.

Why Microsoft 365 users should prepare now

Microsoft begins rolling out passkeys as the default authentication experience in Microsoft Entra ID on 1 September 2026. As the rollout reaches an organisation, users enabled for SMS or voice are automatically enabled for passkeys and prompted to register one the next time they perform MFA. That date starts a rollout. It is not a deadline to have every user moved on that day.

The hard date is 1 February 2027. Microsoft then retires its own telecom delivery for SMS and voice authentication, and passkey registration is enforced for users who use SMS or voice before they can sign in. Microsoft says there is no opt-out. Organisations that genuinely need to keep SMS or voice can configure a supported third-party telecom provider through the Microsoft Security Store from 30 October 2026, with the provider's telecom costs paid by the customer.

Do not wait for staff to be surprised by the prompt. Use our Microsoft 365 passkey rollout guide to work through the users, recovery arrangements and awkward cases before the change becomes urgent.

What to do next

Start by finding out which people still rely on SMS or voice for Microsoft sign-ins and where a lost device would cause a lockout. Then choose a small pilot group and test the recovery route before asking everyone else to register. If you want a calm second opinion, arrange a free, no-obligation chat with TSS. We support businesses across Bury, Greater Manchester and Lancashire.

Not sure which passkey method suits your staff?

Book a free, no-obligation chat and we will help you plan the devices, recovery and staff communication.

Call us Get a quote