Passkeys offer a simpler and more secure alternative. They let users sign in using the fingerprint, face recognition or PIN they already use to unlock their phone or laptop — without typing a password.
A passkey replaces your password with your device's built-in security. When you create one, your device generates two cryptographic keys. The private key stays securely on your device, while the website stores the public key. When you sign in, the website sends a challenge that only your private key can answer. After you confirm your identity with your fingerprint, face or PIN, the device completes the login.
Passkeys are based on the FIDO security standard, supported by major technology companies including Apple, Google and Microsoft.
When redirected to a fake login page via a poisoned link, you type in your password, it gets passed on to the attacker, you approve the MFA prompt, and the attackers steals the resulting session token. At this point, the attacker can use this token to login to your account directly, skipping future password and MFA prompts. Now they are in, they can do some real damage. One option to protect yourself against this is to use Passkeys.
Passkeys address several of the biggest weaknesses of passwords:
Traditional methods such as SMS codes and some approval prompts can still be vulnerable to social engineering.
Passkeys are already supported by major platforms including Microsoft, Google and Apple, as well as an increasing number of banks, password managers and business applications.
Synced passkeys are backed up through services such as Apple, Google or Microsoft accounts, allowing them to work across multiple devices.
Device-bound passkeys remain on a specific device or security key. These provide a higher level of control and are particularly useful for sensitive accounts.
For most businesses, yes. You don't need to replace every password immediately. A gradual rollout is usually the best approach. Microsoft 365 supports passkeys through Microsoft Entra, allowing users to authenticate using compatible devices, Microsoft Authenticator or security keys. Google Workspace also supports passkeys. Your IT provider can manage the configuration and rollout to minimise disruption.
A passkey lets you sign in using your fingerprint, face recognition or PIN instead of a password. Your device proves your identity without sending a password to the website.
Yes. They are resistant to phishing, don't rely on passwords that can be stolen in a data breach, and cannot be reused across different services.
A synced passkey can usually be restored through your Apple, Google or Microsoft account. For device-bound passkeys, you should register a second device or security key as a backup.
Yes. Microsoft Entra supports passkey authentication, including options using Microsoft Authenticator, security keys and compatible devices.
A passkey can provide two-factor protection in a single login. Access requires possession of the device plus a fingerprint, face scan or PIN, removing the need for the traditional password-and-code combination in supported scenarios.

























