Passwords remain one of the weakest points in business security. Staff reuse them, attackers steal them through convincing sign-in pages, and support teams spend time resetting them when they are forgotten.
Passkeys offer a practical alternative. They let someone sign in using the security already built into their phone, computer or hardware security key, without sending a reusable password across the internet.
The UK National Cyber Security Centre recommends choosing passkeys over passwords wherever they are available because they are resistant to phishing and cannot be intercepted or reused in the same way as a password. Read the NCSC’s passkey guidance.
That does not mean every business should immediately disable every password. A safe move to passkeys requires planning, testing and a reliable account-recovery process.
What is a passkey?
A passkey is a digital credential created for a specific website, application or online service. It consists of two related cryptographic keys.
The service keeps the public key. The private key remains protected by the user’s device, security key or approved password manager. When the user signs in, the device proves it holds the private key without revealing it.
The user normally authorises the sign-in with the same method used to unlock the device, such as Face ID, Touch ID, a fingerprint, a device PIN or a hardware security key.
The biometric information is not sent to the website or cloud service. It is checked locally by the device to unlock the passkey. Google’s Workspace guidance confirms that a fingerprint, face scan, PIN or pattern remains local and is not shared with Google or other parties. See Google Workspace passkey guidance.
Because a passkey is tied to the genuine website or application for which it was created, a fraudulent login page cannot simply collect and reuse it.
Where can a business use passkeys?
Support is already available across many of the platforms commonly used by small businesses.
Microsoft Entra ID supports both synced and device-bound passkeys. Credentials can be held in Microsoft Authenticator, on a FIDO2 hardware security key or through an approved passkey provider. Microsoft also allows administrators to target deployment at selected groups before extending it across the organisation. Review Microsoft’s current Entra passkey guidance.
Apple devices can store passkeys in iCloud Keychain and make them available across compatible iPhones, iPads and Macs using the same Apple Account. Apple requires two-factor authentication and iCloud Keychain to be enabled. See Apple’s UK passkey instructions.
Google Workspace administrators can allow users to skip password challenges and authenticate with a passkey stored on a phone, computer or security key. Administrators can also restrict deployment to hardware security keys where that is appropriate.
Availability still varies between applications. Older software, legacy email clients and some specialist services may continue to require passwords, so passkeys should be introduced as part of a wider identity-security plan.
A sensible passkey rollout for a small business
1. Start with the accounts that matter most
Begin with administrators, directors, finance users and anyone who can access sensitive customer information. These accounts present the greatest risk if their credentials are stolen.
Do not overlook shared cloud services, domain administration, backup platforms, remote-access tools and social-media accounts.
2. Review the devices people actually use
A passkey plan must reflect the real workplace. Check whether staff use managed Windows PCs, Macs, iPhones, Android phones or Chromebooks, and whether personal devices are permitted.
Decide whether passkeys may synchronise through personal accounts or whether company-controlled authenticators and hardware security keys are required.
3. Plan account recovery before deployment
A lost phone must not become a business emergency.
Privileged users should normally have more than one approved authentication method. This might include a second managed device, a spare hardware security key stored securely or an administrator-controlled recovery process.
Recovery must be documented, tested and protected from social engineering. An attacker who cannot steal a passkey may instead attempt to persuade someone to reset it.
4. Run a small pilot
Choose a group representing different roles and devices. Test everyday sign-ins, remote working, replacement devices and recovery.
The pilot should identify unsupported applications and unclear instructions before they affect the whole company. Record what users found confusing and improve the guidance before expanding the rollout.
5. Update joiner, mover and leaver procedures
Authentication credentials must follow the employment lifecycle. New starters need an approved enrolment process. Role changes may require different security controls, while leavers must have passkeys and active sessions removed promptly from company services.
Company-owned hardware security keys should be inventoried and recovered where possible.
6. Keep stronger controls for privileged access
Convenient synced passkeys can be suitable for many everyday users. Administrators or people handling particularly sensitive systems may benefit from device-bound passkeys or dedicated hardware security keys.
Microsoft describes FIDO2 security keys as an appropriate option for elevated and highly regulated users because the private key remains on the physical authenticator. Read Microsoft’s explanation of FIDO2 security keys.
7. Train staff in the new sign-in process
Passkeys reduce phishing risk, but people still need to understand what has changed.
Explain that staff should not approve unexpected recovery requests, scan unsolicited sign-in QR codes or disclose device PINs. Provide a clear route for reporting lost devices and suspicious prompts.
Passkeys are one part of good account security
Passkeys can make sign-in both safer and easier, but they do not replace device management, software updates, access reviews or reliable backups.
A compromised or unmanaged device can still expose business information after a legitimate user has signed in. Businesses should combine passkeys with:
- Managed and encrypted devices
- Prompt removal of unused accounts
- Restricted administrator privileges
- Regular access reviews
- Secure recovery procedures
- Monitoring for unusual sign-ins
- Tested backup and incident-response arrangements
The objective is not simply to remove passwords. It is to create an authentication process that is easier for genuine users and substantially harder for an attacker to exploit.
Need help planning a safe rollout?
MSP247 supports businesses using Windows, Mac, iPhone, iPad, Chromebook, Microsoft 365, Google services and mixed-device environments. Our free business IT review can examine your current authentication methods, administrator accounts, device management and recovery arrangements.
Related services: managed IT support, Apple business IT support, Microsoft 365 support and management, and cybersecurity services.












