Sound Networks IT Support
Sound Networks IT Services
IT Support
Managed IT Services
Cyber Security
AI
Insights
Company

Request free IT audit

This site uses cookies for functionality and analytics Manage Close

A safer alternative to passwords

Passwords remain one of the weakest points in business security. They are reused, forgotten, written down and frequently stolen through phishing attacks.

Passkeys offer a simpler and more secure alternative. They let users sign in using the fingerprint, face recognition or PIN they already use to unlock their phone or laptop — without typing a password.

What is a passkey?

A passkey replaces your password with your device's built-in security. When you create one, your device generates two cryptographic keys. The private key stays securely on your device, while the website stores the public key. When you sign in, the website sends a challenge that only your private key can answer. After you confirm your identity with your fingerprint, face or PIN, the device completes the login.

The website never receives or stores a password.

Passkeys are based on the FIDO security standard, supported by major technology companies including Apple, Google and Microsoft.

An example of where passkeys can help.

The issue with MFA is an attack type called ‘adversary in the middle’ is on the rise.

When redirected to a fake login page via a poisoned link, you type in your password, it gets passed on to the attacker, you approve the MFA prompt, and the attackers steals the resulting session token. At this point, the attacker can use this token to login to your account directly, skipping future password and MFA prompts. Now they are in, they can do some real damage. One option to protect yourself against this is to use Passkeys.

Why are passkeys more secure?

Passkeys address several of the biggest weaknesses of passwords:

  • They resist phishing. A passkey is tied to the genuine website it was created for, so it cannot simply be entered into a convincing fake login page.
  • There is no password database to steal. Websites store only the public key, which cannot be used on its own to log into your account.
  • There is nothing to reuse or remember. Each passkey is unique to its service, eliminating weak and reused passwords.
  • They are quicker. Signing in can often be completed with a fingerprint, face scan or PIN in seconds.

Traditional methods such as SMS codes and some approval prompts can still be vulnerable to social engineering.

Where can you use passkeys?

Passkeys are already supported by major platforms including Microsoft, Google and Apple, as well as an increasing number of banks, password managers and business applications.

There are two main types:

Synced passkeys are backed up through services such as Apple, Google or Microsoft accounts, allowing them to work across multiple devices.

Device-bound passkeys remain on a specific device or security key. These provide a higher level of control and are particularly useful for sensitive accounts.

Should your business use passkeys?

For most businesses, yes. You don't need to replace every password immediately. A gradual rollout is usually the best approach. Microsoft 365 supports passkeys through Microsoft Entra, allowing users to authenticate using compatible devices, Microsoft Authenticator or security keys. Google Workspace also supports passkeys. Your IT provider can manage the configuration and rollout to minimise disruption.

A sensible rollout is:

  1. Start with high-risk accounts – administrators, finance teams and anyone able to access critical systems or move money.
  2. Offer passkeys to other staff alongside existing authentication methods.
  3. Set up a backup – users should have a second registered device or security key to avoid being locked out if their primary device is lost.

Frequently Asked Questions

What is a passkey?

A passkey lets you sign in using your fingerprint, face recognition or PIN instead of a password. Your device proves your identity without sending a password to the website.

Are passkeys safer than passwords?

Yes. They are resistant to phishing, don't rely on passwords that can be stolen in a data breach, and cannot be reused across different services.

What happens if I lose my device?

A synced passkey can usually be restored through your Apple, Google or Microsoft account. For device-bound passkeys, you should register a second device or security key as a backup.

Does Microsoft 365 support passkeys?

Yes. Microsoft Entra supports passkey authentication, including options using Microsoft Authenticator, security keys and compatible devices.

Do passkeys replace MFA?

A passkey can provide two-factor protection in a single login. Access requires possession of the device plus a fingerprint, face scan or PIN, removing the need for the traditional password-and-code combination in supported scenarios.

Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Need Help?