Local Business

Passkeys for small business: phishing-resistant sign-in without the hardware

Passkeys replace passwords with a cryptographic key your device holds, and they cannot be typed into a fake login page. Here is what they are, where they work today, how they fit with MFA and password managers, and how to roll them out without locking anyone out.

September 25, 2026 7 min read securitypasskeysauthenticationsmall businessMFA

For most of the history of computing, signing in has meant typing a secret into a box. The problem with typing a secret into a box is that people will type it into any box that looks right, including a fake one. Phishing works because the password does not know where it is being entered.

Passkeys fix that. They are a newer way of signing in that replaces the password with a cryptographic key stored on your phone, laptop, or password manager. You unlock it with your fingerprint, face, or device PIN, and it only works on the real website it was created for. A convincing fake login page gets nothing, because there is nothing to type and nothing to steal.

For a small business, passkeys are the most practical route yet to phishing-resistant sign-in, the kind that used to require buying hardware security keys for everyone.

What a passkey actually is

A passkey is built on open standards called FIDO2 and WebAuthn, developed by an industry group that includes Microsoft, Google, and Apple. When you create a passkey for a service, your device generates a pair of keys. The private key stays on your device or in your password manager. The public key goes to the service.

When you sign in, the service sends a challenge. Your device checks that the request is coming from the genuine website address, asks you to confirm with your fingerprint, face, or PIN, and signs the challenge with the private key. The service checks the signature with the public key. No secret crosses the internet, and nothing reusable is stored on the service’s side for an attacker to steal in a breach.

That website check is the important part. A phishing site at a lookalike address cannot trigger your passkey for the real site. The protection does not depend on anyone noticing a misspelled domain.

Two kinds of passkey

Synced passkeys live in a password manager or platform account, such as Apple’s iCloud Keychain, Google Password Manager, or a third-party password manager that supports them. They sync across your devices, so a new phone does not mean starting over. This is what most people will use for most accounts.

Device-bound passkeys stay on one specific piece of hardware, such as a physical security key or, in some business setups, an authenticator app on a managed phone. They never leave that device. This is stronger, and it is what you want for administrator accounts, but losing the device means relying on your recovery plan.

Where passkeys work today

Support has grown quickly. Microsoft and Google both support passkeys for their consumer accounts, and both offer passkey options for business accounts in Microsoft 365 and Google Workspace, configured by an administrator. Many banking, accounting, and software platforms have added them too, though support is uneven, and some services still treat a passkey as an optional extra rather than a full replacement.

The practical approach: check the services that matter most to your business, starting with email and your identity platform, and turn passkeys on wherever they are offered. Expect to run passkeys and passwords side by side for some time.

How passkeys relate to MFA and password managers

This is where people get confused, so it is worth being precise.

Passkeys and MFA. A passkey combines something you have (the device holding the key) with something you are or know (the fingerprint, face, or PIN that unlocks it). That is why many services treat a passkey sign-in as satisfying multi-factor authentication on its own. It is also stronger than codes from an app or text message, because those codes can still be typed into a fake page in real time.

Passkeys and password managers. They work together. A good business password manager can store passkeys alongside passwords, share access to the right accounts, and handle the many services that do not support passkeys yet. If you have already rolled out a password manager, you have a natural home for passkeys.

What passkeys do not replace. Account recovery, device security, and good offboarding. A passkey on an unlocked, unmanaged laptop is only as safe as that laptop.

A rollout plan for a small team

Passkeys are easy for individuals and a little more involved for a business, mainly because of recovery. Plan it rather than letting everyone improvise.

  • Start with administrators. Your Microsoft 365 or Google Workspace admin accounts get device-bound passkeys or hardware keys first, with at least two registered per person.
  • Enable passkeys in your identity platform. Configure the admin settings so staff can register passkeys for their work accounts, and decide which types you will allow.
  • Decide where passkeys will live. For most staff, that means the company password manager or a managed device, not a personal phone’s platform account that you cannot control.
  • Walk people through registration. Ten minutes each. Register the passkey, test signing in with it, and confirm a second sign-in method still works.
  • Expand to other critical services. Banking, accounting, domain registrar, payment platforms. Wherever passkeys are offered and a takeover would hurt.
  • Tighten gradually. Once everyone is comfortable, consider requiring phishing-resistant methods for your most sensitive accounts, and retiring SMS codes where you can.

The recovery pitfalls

Most passkey trouble is recovery trouble. Plan for these before they happen.

Lost or replaced phones. If someone’s only passkey is on a phone that goes through the wash, they need a way back in. Register at least two methods per person: a synced passkey plus a backup, or two security keys.

Personal accounts holding work keys. If a staff member creates a work passkey in their personal Apple or Google account, it leaves with them when they do. Keep work passkeys in company-managed places.

Offboarding. When someone leaves, remove their registered passkeys and methods from your identity platform, just as you would disable their password. Check shared accounts too.

Recovery that undoes the security. If the fallback for a lost passkey is a text message to a phone number, an attacker who can hijack that number can bypass the whole thing. Make recovery go through an administrator who verifies the person, not through a weaker automated route.

Shared accounts. Passkeys are designed around individuals. For shared logins, a password manager with controlled sharing is usually the better fit until the service supports proper individual access.

A short checklist

  • Admin accounts protected with device-bound passkeys or hardware keys, two per person
  • Passkeys enabled in Microsoft 365 or Google Workspace for staff
  • A decision on where work passkeys live, and it is not personal accounts
  • Every person registered with at least two sign-in methods
  • A recovery process that goes through a human, not an SMS code
  • Offboarding steps updated to remove passkeys and methods

Where this fits

Passkeys are the next step after multi-factor authentication, and they sit comfortably alongside a company password manager. Enforcing them consistently across staff, devices, and offboarding is the kind of work device management handles day to day.

Send us a short brief about how your team signs in today, and we will reply in writing within one business day.

— Newsletter

Get the writing by email.

An occasional note from the team — case studies, new free tools, engineering essays. Never daily.

Three fields, no tracking. Privacy policy.

Esc