What is Passkeys?
Passkeys are a passwordless sign-in method built on the FIDO2 and WebAuthn standards, in which a user's device holds a private cryptographic key and the service holds the matching public key. To sign in, the user approves the request on the device with a fingerprint or a device PIN, and the device proves possession of the key without ever transmitting a secret that could be stolen or reused.
When a passkey is created, the device generates a unique key pair for that specific website or application and registers the public half with the service. At each login the service sends a random challenge; the device signs it with the private key after the user approves, and the service verifies the signature. Two properties make this resistant to phishing. The private key never leaves the device, so there is nothing to intercept. And the passkey is bound to the exact web address it was created for, so a look-alike site cannot trigger it no matter how convincing the page looks. Passkeys can be device-bound, living only on a hardware security key or a specific computer, or synced through a platform account so they follow the user across phones and laptops. Microsoft Entra ID supports both forms, including passkeys stored in the Microsoft Authenticator app.
For a small or mid-sized business passkeys close the gap left by ordinary multi-factor authentication. Push notifications and one-time codes can be phished with a fake login page that relays the code in real time, or worn down by repeated prompts until a tired employee taps approve. A passkey cannot be relayed. The transition is gradual: start with administrators and finance staff and keep a recovery path for lost devices. Some older applications will need single sign-on through Entra ID before they can use passkeys at all.
NetSys rolls out passkeys through its multi-factor authentication service, beginning with the accounts that attackers value most and using Entra ID authentication strength policies to require phishing-resistant methods for administrator roles and sensitive applications. Recovery procedures are documented before enforcement, and the change is paired with conditional access so a stolen password alone is never enough.
Why it matters for a small business
Most of the account takeovers that hit small businesses today defeat ordinary multi-factor authentication, either by phishing the code or by pestering the user with prompts until one is approved. Passkeys end both tactics because there is no code to steal and no prompt to approve from a fake site. For an owner that means the finance team's email and the administrator accounts can be protected in a way that does not depend on anyone spotting a convincing forgery. Users tend to like them, too: a fingerprint is faster than a password plus a code, and there is nothing to remember or reset.
Passkeys: FAQs
What is a passkey and how does it work?
A passkey is a login credential that replaces a password with a pair of cryptographic keys. The private key stays on your device, protected by your fingerprint or PIN, and the public key is stored by the website or application. When you sign in, the service sends a challenge, your device signs it after you approve, and the signature proves it is you. Nothing secret is typed or sent, so there is nothing for a phishing site to capture.
Are passkeys more secure than multi-factor authentication?
Passkeys are a form of multi-factor authentication, and they are more secure than the common kinds. Codes sent by text or generated by an app, and push approvals, can all be phished through a fake login page that relays them in real time or defeated by repeated prompts. A passkey is bound to the real site's address and never exposes a secret, so a look-alike page cannot use it. CISA describes FIDO-based methods, including passkeys, as phishing-resistant for this reason.
Do passkeys work with Microsoft 365?
Yes. Microsoft Entra ID supports passkeys stored in the Microsoft Authenticator app on iOS and Android, as well as passkeys on FIDO2 hardware security keys, and administrators can require them through authentication strength policies in Conditional Access. Users register a passkey from their security settings and then sign in to Microsoft 365 by approving on their phone or touching a key. Password-based sign-in can be phased out for specific groups once passkeys are in place and a recovery process exists.
More terms
Patch Management
Patch management is the routine of finding, testing, deploying and verifying software updates so known security holes close before attackers use them.
NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) is a voluntary set of guidelines from the U.S. National Institute of Standards and Technology for managing cyber risk.
Penetration Testing
Penetration testing is an authorized, simulated attack on a company's systems or staff to find exploitable weaknesses before a real attacker does.
Next-Generation Firewall (NGFW)
A next-generation firewall (NGFW) is a network security device that inspects traffic by application and content and blocks known threats before they enter.
Get the controls, not just the definition.
A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.
