Skip to main content
Cybersecurity

Passkeys for Business: When MFA Is Not Enough

Passkeys for Business: When MFA Is Not Enough

Here’s the short version: passkeys for business are phishing-resistant sign-in, not a new password manager. They stop a class of attacks that SMS and tired Authenticator prompts still lose. They do not replace Conditional Access, break-glass, or a plan for a lost phone.

Most small Microsoft 365 tenants we see have MFA licensed and a pile of exceptions. Push notifications are better than nothing. They are not enough for Global Admin, and they are getting easier to socially engineer. Passkeys and FIDO2 security keys are the next control, not a rebrand of the last one.

Microsoft documents passwordless authentication and how to enable passkeys (FIDO2) in Entra. The FIDO Alliance’s passkeys overview is the vendor-neutral version. Read those if you like specs. This page is the SMB order: who, when, and what you still cannot skip.

If you have not finished ordinary MFA, do that first. See multi-factor authentication. Passkeys on a tenant that still allows legacy auth is a tuxedo over sneakers.

Microsoft is not waiting for you to feel ready. Passkeys become the default Entra experience starting 1 September 2026 for users enabled for SMS or voice, and Microsoft-provided SMS and voice delivery retires 1 February 2027. Authenticator push and TOTP are not that retirement. Native text-message MFA is. Plan the admin keys now, not after the prompt becomes blocking.

What a passkey actually is

A passkey is a cryptographic credential. The private piece stays on a device or in a synced vault. The site gets a public piece. When you sign in, the device proves it holds the private piece for that site. A fake login page cannot complete that proof, which is why phishing-resistant MFA is the phrase insurers and CISA keep using. CISA’s MFA page still starts with “do MFA,” then pushes you toward methods that survive a fake site.

Synced passkeys (iCloud, Google, sometimes a work vault) are convenient. Device-bound passkeys and hardware security keys are stricter. For Global Admin, prefer a hardware key you can lock in a drawer. For a salesperson, a platform passkey on a managed phone is already a large upgrade from SMS.

Authenticator can also hold a passkey. That is different from Authenticator push. Push is still a prompt someone can approve on a fake site. A passkey in Authenticator is FIDO2. Do not mix those two sentences in the insurance form.

Passkeys vs Authenticator vs SMS

MethodPhishing resistant?Fatigue / push scamsSMB fit
SMSNoSIM and intercept riskRetire it for admins now
Authenticator pushUsually noYes, if users approve noiseFine as a step-up, not as the admin method
Authenticator number matchBetterLowerGood default for staff
Passkey / FIDO2 keyYes, if FIDO2No prompt-to-approve a fake siteAdmins first, then finance

NIST SP 800-63B is the authenticator catalog governments cite. You do not need to implement every NIST level. You do need to stop treating SMS as “MFA done” for people who can change the tenant.

Microsoft lists FIDO2 compatibility so you do not buy a key that Entra will not accept. Compatibility is a shopping list, not a rollout.

Person using a phone next to a laptop in an office
Passkeys prove the real site; a fake login page cannot complete the ceremony

Who should enroll first

Not the intern. Not the whole company on a Friday.

  1. Global Admins and anyone who can edit Conditional Access. If those accounts fall, the rest of MFA is a suggestion.
  2. Finance and anyone who initiates wires. Same reason as business email compromise.
  3. Help desk staff who can reset others. A compromised reset desk is a factory for new admins.
  4. Everyone else, after the first three groups have two methods each.

Hardware keys for group 1. Platform passkeys for groups 2 and 3 if keys feel like overkill and the phones are managed. Unmanaged personal phones as the only admin method is how you lose a weekend.

This pairs with Conditional Access without locking agents out. Passkeys are a method. Conditional Access is the policy that requires it for the right apps.

What still needs a password (for now)

Be honest with the office.

  • Break-glass. Microsoft’s current emergency-access guidance wants a phishing-resistant method (FIDO2 key recommended) on a cloud-only account, stored apart from daily admin, excluded from Conditional Access that would block it. A long password in an envelope is the old pattern. See our break-glass account guide. Do not put the only method on the same phone as daily mail.
  • Legacy apps. A scanner or line-of-business tool that cannot do FIDO still needs a path. Fix or isolate it. Do not keep basic auth for the whole tenant because of one copier. That is the legacy authentication job (if you have not done it, do it before passkeys).
  • Recovery. A lost key is an identity ticket, not a philosophy problem. Two keys, or a key plus a passkey, or a Temporary Access Pass you issue in person.

Microsoft’s security key how-to is the admin procedure. Print the lost-device steps next to it.

Synced passkeys versus a key on a lanyard

A synced passkey lives in Apple, Google, or another vault and follows the person to a new phone. That is why staff like them. It is also why you should not use a personal iCloud passkey as the only Global Admin method. When they leave, you want Entra to be the source of truth, not a consumer account you cannot open.

A hardware security key does not care about iCloud. It cares about a PIN and physical possession. Two keys in two places (desk drawer, home safe) is the boring admin design. One key on a carabiner next to the office badge is how keys disappear at lunch.

For a 20-person firm, mixed is fine: keys for admins, platform passkeys for people who live on a managed phone. Do not mix randomly. Write it down. Help desk cannot guess.

If the phone is unmanaged, prefer Authenticator number match plus a later Intune conversation rather than pretending a family iPad is a security key.

How to explain this without a TED talk

Partners do not want FIDO. They want “a fake Microsoft page cannot steal the login.” Use that sentence. Then show the prompt once. Then enroll them. Do not send a 19-page FAQ.

Finance needs: “The invoice phish that asks you to approve Authenticator still works on push. It does not complete a passkey ceremony.” That is the whole pitch.

IT needs: “Two methods, report-only, then enforce, break-glass is a separate FIDO key in a vault.” If that sounds like Conditional Access, it is. Passkeys are a method inside that machine, not a replacement for it.

How a small tenant rolls this out

Week 1: inventory methods

Who still has SMS. Who has Authenticator. Who is Global Admin. Who can reset passwords. You cannot enroll passkeys into a mystery.

Week 2: admins only

Register two methods per admin. Require passkey or security key for Azure portal and Entra via Conditional Access, in report-only first if you are jumpy. Then enforce.

Week 3: finance and help desk

Same two-method rule. Help desk needs a script for “I left my key at home.”

After that: everyone else, slowly

Do not make passkeys the only method for people who share a family iPad with work mail. App protection and Authenticator may still be the right pair. Intune is how you know which phones you can trust.

Laptop and meeting notes on an office table
Enroll Global Admins on passkeys before you argue about the whole company

Common ways this goes wrong

One key, no backup. The key lives in a laptop bag that goes through TSA. Buy two.

Passkeys on personal Apple IDs only. When the person leaves, the credential is in a consumer vault you cannot revoke cleanly. Prefer work-managed devices or hardware keys for privileged roles.

Enforcing for everyone before admins. You will roll back under ticket pressure. Start at the top.

Calling SMS ‘phishing resistant’ in the insurance form. It is not. Do not write that.

Skipping break-glass. A bad Conditional Access change plus passkeys-only admins is a tenant you cannot enter. Keep the sealed account.

Buying novelty keys that Entra will not take. Check the compatibility list before the Amazon order. A pretty key that fails registration is a paperweight and a lost week.

Enrolling over email only. For admins, do it in person or on a video call where you can see the device. A phish that says “register your new passkey here” is the attack you are trying to end.

Cybersecurity for identity is MFA, then Conditional Access, then phishing-resistant methods for the people who can hurt you. Passkeys are that third rung.

If you want admins on keys without locking the office out of Outlook, contact Secure Techies. We work from Canoga Park. We will tell you who needs a hardware key this month and who can wait. Bring a list of Global Admins and how they sign in today. That list is the project. Everything else is theater until it exists. If the list has SMS on an admin, start there before you order keys. A hardware key will not save a password that still works without it.

Frequently Asked Questions

Passkeys for business are FIDO2 credentials bound to a device or a synced provider, used to sign in without typing a password that a phish site can steal. In Microsoft Entra they show up as passkeys or security keys. They are phishing-resistant in a way SMS and many push prompts are not.
For phishing resistance, yes, when they are implemented as FIDO2. Authenticator push can still be socially engineered (MFA fatigue, fake prompts). Passkeys and security keys prove the user is on the real site. Authenticator remains useful as a backup method and for users who are not ready for keys.
Global Admins and anyone who can change Conditional Access, billing, or bank connections. Then finance and anyone who initiates wires. Rolling passkeys to every volunteer or seasonal worker on day one is how projects stall. Start with the accounts that can empty the tenant.
No. Conditional Access decides when a method is required. Passkeys are one grant method. You still need policies, break-glass, and a way to recover a lost device. A passkey on an account that Conditional Access never requires is a sticker.
They sign in with a backup method you planned: a second key, a synced passkey on another device, or a temporary TAP you issue in person. If the only method was one phone that is now in a cab, you will be resetting that account as an admin. Two methods is the design, not one hero device.
Share

Talk to a real IT expert — free

No sales pressure, no jargon. Just a straight assessment of where your IT and security stand, and what to do next.