Back to blogCybersecurity

Passkeys Are Replacing Passwords. Is Your Business Ready?

7 min read

Passkeys are the biggest change to how people log in to systems since the password itself. They are faster, more secure, and increasingly the default option on consumer platforms. For business, the rollout is a few years behind consumer, but the direction is clear.

Most Australian SMBs have not yet thought about passkeys in any structured way. The questions you are likely to be asked over the next year, by your security insurer, by your auditors, by your security-conscious clients, are going to push the topic up the priority list. Better to understand it before you have to answer the questions.

This is the working briefing.

What a passkey actually is

A passkey is a cryptographic credential that lives on your device, protected by the device's local authentication, such as a fingerprint, face recognition, or a PIN. When you sign in to a service, your device proves to the service that it holds the passkey, without ever sending the passkey itself across the network.

That is the technical core. A few practical consequences follow.

There is no shared secret to phish. With a password, the user types something the attacker can capture or trick out of them. With a passkey, the user authorises a cryptographic operation on their device. Even a perfectly crafted phishing site cannot get the passkey, because the device will only release it to the legitimate site.

There is nothing to leak in a database breach. A service stores only the public part of the passkey. If the service is breached, attackers get a list of public keys, which they cannot use to impersonate the user.

There is nothing to forget. The user does not type a passkey. They authorise its use with the same biometric or PIN they already use to unlock their phone or laptop. The mental load drops to roughly zero.

The standard underneath this is FIDO2 and WebAuthn, supported now by every major platform: Apple, Google, Microsoft, the major password managers, and an increasing share of business identity providers.

Why this matters for business

Three reasons.

The phishing problem. As covered in our recent post on AI-powered phishing, the assumption that a careful user can spot a fake login page no longer holds. Passkeys are the only widely deployed credential type that defeats this attack class structurally, not by user vigilance. For high-privilege accounts, this is now the defining argument.

The credential reuse problem. Even with password managers, real users still reuse passwords across services. A credential stolen at a third-party site becomes a key into your business systems. Passkeys are unique per service by design and cannot be reused.

The audit and insurance trajectory. Cyber insurers and security auditors are starting to ask not just "do you have MFA" but "what kind of MFA". Phishing-resistant MFA, of which passkeys are the most usable form, is becoming the new bar for high-privilege accounts. Tenants that align early have an easier time at renewal.

Where passkeys fit in your existing stack

If you are running Microsoft 365 or Google Workspace, you already have most of the infrastructure.

Microsoft Entra ID supports passkeys for Microsoft 365 sign-ins, including via security keys, mobile devices, and platform authenticators. The licensing for the basic capability is included in Business Premium and most enterprise tiers. Conditional Access can be configured to require phishing-resistant authentication for selected user groups or applications.

Google Workspace supports passkeys natively. Administrators can enforce passkey use, allow it as an option, or restrict it to specific organisational units.

Major identity providers like Okta and Auth0 support passkeys. Most modern business SaaS applications now offer passkey sign-in, either directly or via single sign-on through your identity provider.

The result is that for most Microsoft or Google centric SMBs, the rollout is a configuration project, not a procurement project.

The practical rollout plan

A sensible rollout for a fifty-person business takes two quarters. Faster is possible, slower is fine. Skipping the planning phase is the most common cause of stalled rollouts.

Phase one, weeks one to two: select your passkey form factors. For each user role, decide what kind of passkey makes sense. Most users can use a platform passkey on their phone or laptop. High-privilege accounts, like IT admins and finance leaders, should have at least one hardware key (a USB or NFC FIDO2 key) as well, both for redundancy and for stronger guarantees. Pilot users should also have a backup method.

Phase two, weeks three to four: pilot with five or six users. Cover a range of roles, devices, and tech comfort levels. Document the actual sign-in experience on each device type. Identify the rough edges, such as third-party SaaS apps that do not yet support passkeys, or specific scenarios where the user has to fall back to password plus MFA. Capture the support questions and FAQ items.

Phase three, weeks five to eight: roll out to administrative roles. This is the highest-value group and also the easiest to support directly. Enforce phishing-resistant authentication for administrative roles in your identity provider. Issue hardware keys to anyone who needs them. Verify each admin has at least two enrolled passkeys, on different devices, before retiring their password as a sign-in method.

Phase four, weeks nine to sixteen: roll out to remaining staff. Run small group sessions, fifteen minutes each, walking people through enrolment on their device. Have a clear support path for the inevitable confusion in the first week. Resist the temptation to make it mandatory in the first month. Make it the easier option, fix the rough edges, and the adoption follows.

Phase five, weeks seventeen to twenty: tighten the policy. Once most users have a passkey enrolled, raise the requirement. Enforce passkey or hardware MFA for sign-ins to sensitive applications. Reduce password reset options that bypass strong authentication. Decide whether to allow password sign-in to remain as a fallback or to retire it entirely for accounts that have a passkey.

The total elapsed time is around five months. The total focused effort is much smaller, often two weeks of meaningful work spread across the period.

What to plan for at the edges

A few real-world wrinkles worth thinking about in advance.

Lost or replaced devices. A passkey lives on a specific device. Phones get lost, laptops get replaced. Plan for re-enrolment, including the verification steps required. Most users should have at least two passkeys on different devices to avoid lockout.

Shared accounts. Passkeys are tied to a person, not a role. If your business has shared accounts, that is a hygiene issue passkeys force you to confront. The solution is to retire the shared account, not to find a clever workaround for the passkey.

Older browsers and devices. Almost everything modern supports passkeys. Older devices, kiosk machines, and specific embedded environments may not. Plan for these as exceptions with documented compensating controls, not as reasons to avoid the rollout.

External-facing systems. Your customer-facing systems can also offer passkeys to your customers. This is a separate project, but worth considering. The customer experience is genuinely better, and the security posture for accounts that hold customer money or data is materially stronger.

Backup and recovery for high-privilege accounts. Your break-glass administrative account should not depend on a single device. Multiple hardware keys stored in separate physical locations is the standard pattern.

When to start

The honest answer is now, with a small pilot, even if you are not ready for a full rollout.

The cost of getting your administrative team onto phishing-resistant authentication is low. The risk reduction is significant and immediate. The wider rollout can follow at your own pace once that foundation is in place. The version of this rollout that goes badly is the one that is still being planned in eighteen months while the threat environment continues to harden.

If you would like an outside view on what passkey rollout would look like in your specific environment, our free IT health check includes a phishing-resistant authentication review. We assess your current MFA posture, your identity provider, and your existing licensing, and we deliver a tailored rollout plan. No obligation, no sales pitch.

Learn more about our cybersecurity services

Need help with cybersecurity?

Our free IT health check will show you exactly where your business stands and what to prioritise. No obligation.

Book your free health check

Get IT insights in your inbox

Practical tips for Australian businesses. No spam. Unsubscribe anytime.