31 August 2026
What Are Passkeys, and Should Your Business Use Them?
By Jack Wetson-Catt
Photo by Christin Hume on Unsplash
Passwords are the weak point in most businesses.
People reuse them across accounts, write them down, and type them into convincing fake login pages without realising it. Here at Atema, we see this play out with clients across Gloucestershire and the wider South West more often than any other single cause of a security incident.
Passkeys are the technology built to replace passwords, and they fix the parts that cause the most trouble. Instead of typing a password, you sign in with the same fingerprint, face scan or PIN you already use to unlock your phone or laptop. There's no password to type, so there's nothing for an attacker to steal, guess or trick out of you.
Let's look at what passkeys actually are, why they're so much harder to attack than passwords, and whether your business should start rolling them out.
What is a passkey?
A passkey replaces your password with your device's own security. Instead of typing a password, you prove it's you the same way you unlock your phone, with a fingerprint, a face scan, or a PIN.
When you set up a passkey for a website, your device creates two matching keys. The private key stays locked on your device and never leaves it. The public key is stored by the website. When you sign in, the site sends a challenge that only your private key can answer, your device answers it once you confirm with your fingerprint or PIN, and you're in. The website never sees a password, because there isn't one.
This approach comes from a security standard called FIDO, which Apple, Google and Microsoft all build on, and the UK's National Cyber Security Centre now formally recommends it over passwords (more on that below).
Why passkeys are harder to attack than passwords
A password is a secret you share with the website every time you log in, and that's exactly what attackers go after. A passkey has no shared secret to intercept, and that one difference fixes the biggest problems with passwords.
- They can't be phished. A passkey only works on the real website it was created for. Land on a convincing fake, and the passkey simply won't work, so there's nothing to hand over. That matters, because phishing is how most break-ins start, the same weak point we cover in our guide to protecting your business from QR code scams.
- There's no password to steal in a breach. The website only keeps your public key, which is useless on its own. If the company gets hacked, there's no password list to grab and try on your other accounts.
- Nothing to reuse or forget. Each passkey is unique to one site and generated automatically, so reused and weak passwords stop being a problem entirely.
Older methods like text-message codes and app approval prompts can still be talked out of people by a determined scammer. A passkey removes that step altogether, since there's nothing to read out over the phone or type into a fake page.
Where you can use passkeys already
Support has spread fast. You can already sign in with passkeys to Microsoft, Google and Apple accounts, plus a growing list of banks, password managers and business tools. All three have built passkeys into their phones, laptops and browsers, so the device already sitting in your pocket can store and use them.
There are two types worth knowing about. A synced passkey is backed up to your Apple, Google or Microsoft account, so it works across all your devices and you're covered if you lose one. A device-bound passkey stays on a single device, like a physical security key you plug in, which is the most locked-down option and a common choice for the most sensitive accounts.
Should your business use them?
For most businesses, yes, and you can start small. There's no need to switch everything overnight or drop passwords on day one.
If you use Microsoft 365, passkeys are already available through Microsoft Entra. Staff can sign in with a passkey stored in the Microsoft Authenticator app, a security key, or their own device, and Google Workspace supports them too. This is exactly the kind of setup our Microsoft 365 & cloud work covers as part of ongoing account management, rather than something left sitting unconfigured on a tenant nobody's revisited.
They're also just faster. Microsoft says signing in with a synced passkey takes around 3 seconds, against roughly 69 seconds for a password plus a traditional MFA code. Across a whole team, that adds up over a working week.
A practical way to start:
- Turn passkeys on for your most sensitive accounts first, administrators, finance, and anyone who can move money or change systems.
- Let everyone else add a passkey as a faster, safer way to sign in, alongside their normal login at first.
- Make sure each person has a backup, like a second device or a security key, so a lost phone doesn't lock anyone out.
Your IT provider can switch this on and run the rollout so nobody gets locked out along the way. It's worth pairing that rollout with the wider cyber security & compliance work covering phishing defence and staff awareness, since passkeys close off one route in but not every route in.
What to watch out for
Passkeys aren't magic, and a few things are worth planning for before you roll them out.
- Account recovery. If someone loses the only device with their passkey and has no backup, they can get locked out. A synced passkey or a second registered device fixes this, but it needs setting up ahead of time, not after someone's already stuck.
- Not everything supports them yet. Support is growing fast, but some older systems and smaller vendors still rely on passwords, so you'll likely run both side by side for a while.
- Shared devices and logins. Passkeys are tied to a person and their device, so any shared computers or shared accounts need their own plan, since the usual "everyone knows the password" approach doesn't map onto passkeys at all.
If your business has ever had to deal with a compromised account, our step-by-step guide to what to do during a cyberattack covers the wider response, resetting passwords and turning on multi-factor authentication being the first move in exactly the kind of incident passkeys are designed to prevent in the first place.
Passkeys are one of the more genuinely useful security upgrades to land in years, low effort for staff, and a real reduction in the number of ways an account can be broken into. If you'd like us to look at where passkeys make sense across your business and run the rollout for you, book a call with our team and we'll take it from there.
Frequently Asked Questions
What is a passkey in simple terms?
It's a way to log in using your fingerprint, face or PIN instead of a password. Your device proves it's you to the website, and no password is ever typed or stored.
Are passkeys safer than passwords?
Yes. They can't be phished, there's no password for a hacker to steal in a data breach, and there's nothing to reuse or forget. The NCSC formally recommends passkeys wherever a service supports them, and its own assessment is that FIDO2 credentials, including passkeys, are as secure or more secure than traditional MFA against the common credential attacks it sees in the wild.
What happens if I lose the device with my passkey?
If it was a synced passkey, it's backed up to your Apple, Google or Microsoft account and still available on your other devices. If it was device-bound and you have no backup, you'd use a recovery method to get back in, which is why setting up a second passkey or device in advance matters.
Does Microsoft 365 support passkeys?
Yes. Passkeys are available through Microsoft Entra at no extra cost, including on the free tier. Staff can use a passkey in the Microsoft Authenticator app, a security key, or their own device.
Do passkeys replace multi-factor authentication?
A passkey can count as multi-factor authentication on its own. Unlocking it needs both your device (something you have) and your fingerprint, face or PIN (something you are or know), so it covers two factors in one step and can replace the old password-plus-text-code routine.
Written by
Jack Wetson-CattJack co-founded Atema in 2017 and leads the team day to day, bringing years of IT experience across telecoms, finance and legal to how Atema supports its own clients.
