top of page

Passkeys for Small Business: What Microsoft 365 Users Need to Know

Aug 27
16 min read


Passkeys for small business guide covering Microsoft 365, modern authentication and passwordless security for small businesses
Passkeys are changing how businesses protect Microsoft 365 accounts. This guide explains passkeys, Microsoft Authenticator, Windows Hello, password managers, YubiKeys and account recovery for small businesses.


Updated August 2026: When I originally wrote this article in April 2025, passkeys were something I thought small business owners should start understanding. A lot has changed since then. Microsoft is now actively moving Microsoft Entra users toward passkeys and phishing-resistant authentication, and businesses that still rely on Microsoft-provided SMS or voice authentication have some important changes coming. I have updated this article to explain what those changes mean, how passkeys actually work, where Windows Hello, Microsoft Authenticator, password managers and physical security keys such as YubiKeys fit into the picture, and something I think businesses need to spend more time thinking about: what happens when an employee gets a new phone, loses a device or leaves the company.


Passwords have been part of using computers for so long that most of us have developed an entire routine around them. We create them, forget them, reset them, store them in password managers and occasionally discover that the password we were absolutely certain was correct is apparently not the password the website remembers. Then we added MFA, which improved account security but also introduced another collection of text messages, push notifications, authentication apps and verification codes that employees have to understand.


are changing that model, but I do not think the useful conversation for a small business is simply that passwords are going away and passkeys are better. There are different types of passkeys, they can live in different places, and the right authentication approach may not be the same for every employee or every account. A passkey stored on an employee's phone creates different operational questions from a physical YubiKey assigned to an administrator, and a passkey synchronized through a credential manager creates different questions again.


That is why I think small businesses should understand what they are moving toward before simply telling everyone to click Create Passkey the next time Microsoft asks.


What Is a Passkey?

A password is a secret that you know and send to a service when you sign in. That creates one of the fundamental problems with passwords. If someone builds a convincing fake Microsoft sign-in page and convinces you to type your password into it, you have just given that person the same secret you use to authenticate yourself.


A passkey works differently. Passkeys use public key cryptography rather than relying on a shared secret that you type into a website. The private portion of the credential remains with the authenticator or credential provider, while the service uses the corresponding public key to verify the authentication. The credential is associated with the legitimate service, which is one of the reasons passkeys provide much stronger resistance to traditional credential phishing.


From the user's perspective, however, it can feel much simpler than that explanation sounds. You may unlock the credential with a fingerprint, your face, a device PIN or a physical security key. You prove that you have access to the credential without having to remember and type a reusable password into a login page.


That does not mean every time you use Face ID, Touch ID or a PIN you are automatically using a passkey. Those technologies can be used to unlock many different types of credentials and devices. That distinction is important because I still see passkeys described as though Face ID itself is the passkey. It is not.


Why Are Passkeys Harder to Phish?

One of the reasons I am interested in passkeys for small businesses is that they change a weakness we have spent years trying to solve through employee training.


I can train someone not to click suspicious links. I can show employees how to inspect a Microsoft login page. I can teach them to be suspicious when a login prompt appears unexpectedly. That training still matters, but people are people, and phishing pages have become very convincing.


A traditional password can be typed into the wrong website. A passkey is designed to work with the service for which it was created. That makes it much harder for an attacker to build a fake Microsoft login page and simply collect a reusable credential.

This is why Microsoft refers to passkeys as phishing-resistant authentication rather than simply another type of MFA.


Is Microsoft Getting Rid of SMS and Voice Authentication?

Microsoft is making a significant change here, and this is one of the main reasons I am updating this article now.


Beginning September 1, 2026, Microsoft says passkeys become the default authentication experience for applicable Microsoft Entra users who are currently enabled for SMS or voice authentication. Those users will begin being prompted to register a passkey during MFA sign-in.


The bigger date for businesses to understand is February 1, 2027. Microsoft plans to retire Microsoft-provided SMS and voice delivery for Microsoft Entra authentication. Organizations that still need SMS or voice authentication will have an option to work with supported customer-managed telecommunications providers, but that becomes an intentional configuration and business decision rather than simply continuing to rely on Microsoft's existing SMS and voice delivery.


I would not wait until January to find out how employees are currently authenticating.

For a small business using Microsoft 365, I would first want to know who is still using SMS or voice, which employees already use Microsoft Authenticator, whether Windows computers are being managed, what other authentication methods are registered and whether the business has a recovery process when one of those methods stops working.

That is also one of the areas I look at during a Microsoft 365 Tenant Security Review and Microsoft 365 Audit. Seeing an MFA requirement in Microsoft does not tell me everything I need to know. I want to understand how people are actually satisfying that requirement.


Does a Passkey Replace MFA?

This is where the terminology can get confusing because people are accustomed to thinking of MFA as a password followed by a second step.


A passkey can provide multifactor authentication without requiring that familiar sequence. For example, a device-bound credential can establish possession of the device while a PIN or biometric verifies the person using it. The user may experience one sign-in action even though multiple factors are involved in the authentication.


That is one reason I would not explain passkeys to employees as simply “the new MFA app.” The underlying authentication model is different.


It also does not mean a business should turn off every other authentication method tomorrow. Authentication needs to be planned around the users, devices, applications and recovery requirements of the business.


Where Can a Passkey Live?

This is one of the areas where I think a table helps because there is no single answer to “Where is my passkey?”

Authentication option

What it means in practice

What I would think about for a business

Microsoft Authenticator passkey

A device-bound passkey can be created in Microsoft Authenticator on a supported phone.

What happens when the employee replaces, loses or damages the phone?

Synced passkey

The passkey can be synchronized through a supported credential provider and become available on other authorized devices.

Who controls the account doing the synchronization, particularly if the credential belongs to the business?

Microsoft Entra passkey on Windows

A passkey can be stored locally on a supported Windows device using the Windows Hello credential system.

Device management, recovery and how employees use multiple computers all matter.

Windows Hello for Business

Windows uses a device-bound credential that can be unlocked with a PIN, fingerprint or facial recognition.

This can work well with managed company Windows computers and Microsoft's identity controls.

FIDO2 security key such as a YubiKey

The credential resides on a physical security key that the user possesses.

Who owns the key, who gets one, whether a backup key is needed and what happens if a key is lost?

Supported password manager or credential manager

Some password managers and platform credential managers can create, store and synchronize passkeys.

Administration, recovery, sharing, offboarding and passkey capabilities vary by product.

Apple Passwords and iCloud Keychain

Apple can store and synchronize passkeys across approved Apple devices.

A business should understand whether the Apple Account involved is personally or organizationally controlled.

The point is not that one of these is universally the correct answer. Microsoft itself now supports both synced and device-bound approaches because businesses and users have different requirements.


What Is the Difference Between a Synced Passkey and a Physical Security Key?

This distinction matters more once you start thinking about passkeys as something a business has to manage rather than simply a new way to log in.


Synced Passkey

Physical FIDO2 Security Key

Where it lives

Through a supported credential provider that can make it available across authorized devices

On the physical security key

Convenience

Generally easier for someone who uses multiple supported devices

The person needs access to the physical key

If a device changes

The credential may remain available through the supported synchronization provider

The credential remains with the security key

Business question

Who controls the credential provider account?

Who owns and controls the physical key?

Recovery planning

Depends on the provider and account configuration

Requires planning for lost, damaged or unavailable keys

Where I might consider it

Everyday users where convenience and phishing resistance both matter

Privileged, sensitive or other accounts where I want a physical authenticator involved

Microsoft currently recommends FIDO2 security keys particularly for highly regulated environments and users with elevated privileges, while synced passkeys can provide a more convenient phishing-resistant option for many other users.


That does not mean every administrator automatically needs a YubiKey, nor does it mean synced passkeys are somehow the weak option. The business needs to decide which authentication model fits the risk and the way people actually work.


Where Do Password Managers Fit Into This?

Password managers are not suddenly irrelevant because passkeys exist.

Businesses are going to have a mixture of authentication methods for a long time. Some services support passkeys today. Others still use passwords. Businesses may also have administrative credentials, shared credentials or older applications that need to be handled appropriately.


Modern password managers can also support passkeys, although the capabilities vary by product. That is why I would talk about password managers as a category rather than telling every small business that it needs to use the same product I use.

At home, my wife and I use 1Password. I also have clients using LastPass Teams, and other businesses may use completely different platforms. The important questions for me are whether the platform fits the business, who administers it, how access is removed when an employee leaves, what recovery looks like and what capabilities the specific product actually supports.


I would also be careful about employees saving business passkeys into personal password managers without the company ever making a decision about whether that is appropriate. The fact that a browser or application offers to save a credential does not automatically mean that is where the business wants its credentials to live.


What About Windows Hello and That PIN on My Computer?

I use Windows Hello PINs on my own Windows computers because they make signing into the devices convenient without requiring me to type my Microsoft password every time.

A question I hear when explaining this kind of authentication is understandable: How can a short PIN possibly be better than a long password?


The answer is that a Windows Hello PIN does not work like a traditional password. The PIN is associated with that device and is used to unlock the Windows Hello credential. Microsoft states that the PIN does not leave the device. Someone cannot simply learn that PIN and use it from another computer the way they could use a stolen Microsoft password.


Windows Hello for Business combines the device-bound credential with a PIN or biometric gesture and is part of Microsoft's phishing-resistant authentication strategy.

That does not mean I recommend setting every Windows computer to the shortest PIN possible and calling the job finished. It means the security model behind the PIN is different from a reusable password.


How Do I Handle Authentication in My Own Environment?

I use a combination because I do not think every account and every device needs to be handled exactly the same way.


My Windows computers use Windows Hello PINs for convenient device sign-in. I use Microsoft Authenticator for Microsoft authentication, Apple's password management tools within the Apple ecosystem and password managers for different credentials and passkeys. At home, my wife and I currently use 1Password.


For some of my more sensitive accounts, I use YubiKeys because I want a physical security key involved in the authentication process. I am deliberately not saying that every small business should copy that exact configuration. My accounts do not all serve the same purpose, and I do not necessarily want the same balance between convenience, recovery and physical control for every one of them.


What I would carry over to a business environment is the planning behind it. I want to know where the credential lives, who controls it, what happens if the device containing it disappears and how access can be recovered without creating an easy path for someone impersonating the employee.


You Trade In Your Old Phone

This is one I would flag for every business using Microsoft Authenticator because I have run into it with clients more than once.


Someone gets a new phone. They transfer their photos, contacts and applications, everything appears to be working, and they trade in or erase the old phone. Then they discover that Microsoft authentication does not work on the replacement device the way they expected.


For Microsoft work and school accounts, restoring Microsoft Authenticator does not simply recreate every authentication relationship on the new phone. Microsoft says the account name can be restored, but the user still needs to sign in again and complete setup. Passkeys require even more attention. A passkey stored only in Microsoft Authenticator on the old phone is device bound and does not synchronize to the replacement phone.

Microsoft's current recommendation is to complete the transfer and verify access before erasing, trading in or recycling the old phone.


Unfortunately, in the real world, IT often finds out about the new phone after the old one is already gone.


I have had clients upgrade phones and then contact me because authentication stopped working. Depending on the situation, I may need to remove obsolete authentication methods associated with the old device and have the employee register the appropriate methods again. Microsoft also provides tools such as a Temporary Access Pass that can be used by an administrator, when appropriately configured, to help a user securely bootstrap a new passwordless authentication method.


This is why I now think phone replacement needs to be treated as an IT event when the phone is being used for business authentication.


New Phone Checklist

If an employee uses a phone for Microsoft 365 authentication, I would want the process to include:

  • Tell IT before wiping, trading in or disposing of the old phone.

  • Keep the old phone available until authentication has been configured and tested on the new phone.

  • Register any authentication methods that need to be recreated on the replacement device.

  • Verify that Microsoft 365 sign-in works from the new phone.

  • Verify any passkeys the employee needs.

  • Remove authentication methods associated with the old device when they are no longer needed.

  • Only then erase or trade in the old phone.

And because people will inevitably replace phones without calling IT first, the business needs a recovery process for that situation too.


What Happens if the Old Phone Is Already Gone?

This is where recovery planning becomes part of authentication security.

If someone calls IT and says, “I bought a new phone and now I cannot get into Outlook,” I do not want the recovery process to be nothing more than immediately removing authentication methods because someone asked me to.


The person requesting the reset needs to be appropriately verified. Otherwise, the authentication recovery process itself can become a social engineering opportunity.

Depending on the Microsoft environment and what methods the user still has available, an administrator may be able to use a Temporary Access Pass to allow the user to register a new passwordless authentication method. Microsoft designed TAP specifically to help bootstrap passwordless authentication and to assist with recovery when a strong authentication method is lost or unavailable. A passkey strategy therefore needs a recovery strategy.


What Happens if Someone Loses a YubiKey?

Physical security keys create a similar operational question.

If I decide an account is sensitive enough that I want a YubiKey involved, I also need to think about what happens if that key is lost, damaged or sitting on a desk three hours away when I need access.


For a business deploying hardware security keys, I would want the recovery process decided before distributing the keys. That may include deciding whether certain users receive more than one key, how backup authentication methods are controlled, who owns the hardware, how the keys are inventoried and what happens when an employee leaves.

Security controls still have to work on Monday morning when something goes wrong.


What Happens to a Passkey When an Employee Leaves?

Offboarding is another reason I do not think businesses should adopt passkeys without thinking about where the credentials are being stored.


If an employee has business passkeys inside a company-controlled authentication environment, the business has one set of administrative options. If the employee has been saving business credentials into a personal Apple Account or personal password manager, the situation may look very different.


The exact controls depend on the authentication method and provider, which is why I do not want to make a blanket statement that all passkeys can be centrally revoked or managed in exactly the same way.


Before rollout, I would want to answer some basic questions. Which credentials belong to the company? Which devices are permitted to store them? Are personal credential managers allowed? What happens to those credentials when an employee leaves? How does the business remove access? What recovery methods exist, and who is authorized to use them?

Those are governance questions as much as technical ones.


Do Passkeys Mean We Can Stop Using Password Managers?

Not yet, and probably not for quite a while.

A small business may have dozens of applications, vendor portals, banking sites, equipment interfaces and other systems that all support different authentication methods. Some may support passkeys. Some may support MFA but still require a password. Others may have older authentication models that the business cannot immediately change.

A password manager can therefore continue to have an important role even as passkey adoption grows. The role may evolve from simply storing passwords to managing a broader collection of credentials, depending on the platform the business chooses.

The important thing is to avoid assuming that every password manager handles passkeys, administration, sharing and recovery in the same way. Those capabilities need to be verified for the specific product and plan the business is using.

Should a Small Business Move Everyone to Passkeys Right Now?

I would not start by turning everything on for every employee.

I would start by understanding the environment.


Which authentication methods are employees using today? Who still relies on SMS or voice? Which employees use Microsoft Authenticator? Which computers are company managed? Are employees using personal phones for authentication? Are passkeys going to be device bound, synced or a mixture? Are there administrators or other sensitive accounts where a physical security key makes sense? What happens when someone gets a new phone? What happens when someone loses one? What happens when an employee leaves?


Microsoft provides the technology, but the business still has to decide how it will be used.

This is also why I think the upcoming Microsoft changes are a good reason to review the Microsoft 365 environment instead of treating passkeys as an isolated project. Authentication is connected to Microsoft Entra ID, Conditional Access, device management, administrative roles and the way employees access company information.


I cover that larger management problem in Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment?. If you are not sure which authentication methods your users have registered or what policies are currently controlling access, that is also something I look at during a Microsoft 365 Tenant Security Review and Microsoft 365 Audit.


Why Does Phishing-Resistant Authentication Matter?

MFA is still an important security control, but I do not want a business owner to think every form of MFA provides exactly the same protection.


Attackers have adapted to MFA. Some phishing attacks attempt to capture credentials and authentication sessions rather than simply stealing a password. Other attacks rely on users approving prompts they did not initiate. That is one of the reasons Microsoft is pushing organizations toward authentication methods designed to resist phishing rather than relying indefinitely on SMS, voice and other phishable methods.


If you want a broader look at the Microsoft controls surrounding authentication, I cover identity, Conditional Access, email security, devices and other areas in Microsoft 365 Security for Small Business: What Actually Needs to Be Configured.

And if you are reading this because you think someone may already have access to an account, the priority changes. My guide My Small Business Was Hacked. What Should I Do Right Now? walks through the immediate response considerations for compromised Microsoft 365 accounts, computers, Business Email Compromise, phishing, ransomware and financial fraud.


What Should a Small Business Review Before Rolling Out Passkeys?

I would want answers to these questions before treating passkey deployment as finished:

  • Which authentication methods are employees using today?

  • Who still relies on SMS or voice authentication?

  • Which users need synced passkeys and which, if any, need device-bound credentials?

  • Are business passkeys allowed in personal password managers or personal credential accounts?

  • Who owns physical security keys?

  • Are administrators or other sensitive accounts handled differently?

  • What happens when an employee gets a new phone?

  • What happens when the old phone has already been erased or traded in?

  • How does IT verify an employee's identity before resetting authentication?

  • Who is authorized to issue a Temporary Access Pass?

  • What happens if a YubiKey is lost?

  • What authentication options remain if a phone is lost or damaged?

  • How are obsolete authentication methods removed?

  • What happens to business passkeys when an employee leaves?

  • Are the company's authentication decisions documented somewhere?

Those questions are not meant to make passkeys sound complicated. Most employees should ultimately have a relatively simple sign-in experience. The complexity belongs in the planning and management behind that experience, not on the employee trying to open Outlook on Monday morning.


Passkeys Are Easier When the Business Plans for the Messy Parts

I still like passkeys. In fact, I am more interested in them now than when I wrote the original version of this article in 2025. They address some of the weaknesses that have made passwords and traditional authentication methods such persistent targets, and Microsoft's current direction makes it clear that small businesses using Microsoft 365 are going to see more of them.


What has changed for me is that I think the conversation needs to go beyond whether passkeys are safer than passwords.


I want to know where the passkey lives. I want to know who controls it. I want to know what happens when the phone containing it falls into a lake, gets traded in at the Apple Store or disappears on a business trip. I want to know what happens when an employee leaves. I want to know whether a sensitive administrator account deserves a different authentication approach from an everyday employee account. And I want a recovery process that does not become the easiest way for an attacker to bypass everything we just put in place.

That is the part of passwordless authentication that a small business can easily miss.

The technology can make signing in easier and harder to phish at the same time. But like most things I work with in Microsoft 365, enabling the feature is only the beginning. Someone still needs to understand it, configure it, document it and have a plan for what happens when normal people do normal things, including buying a new phone without calling IT first.


ADDITIONAL RESOURCES

Microsoft Learn: Passkeys by Default and Retirement of Microsoft-Provided SMS and Voice Authentication

Microsoft's current guidance on the transition toward passkeys and the retirement of Microsoft-provided SMS and voice authentication.https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement


Microsoft Learn: Passkeys in Microsoft Entra ID

Microsoft's technical overview of synced and device-bound passkeys and current Entra passkey support.https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2


Microsoft Learn: Transfer Microsoft Authenticator to a New Phone

Microsoft's current process for moving Authenticator to a replacement phone, including what happens to work accounts and passkeys.https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-transfer-authenticator-new-phone


Microsoft Learn: Temporary Access Pass

Microsoft guidance for using a time-limited Temporary Access Pass to register or recover passwordless authentication methods.https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass


Microsoft Learn: Windows Hello for Business

Microsoft's current documentation explaining Windows Hello for Business and its device-bound authentication model.https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/


Microsoft Learn: FIDO2 Security Keys

Microsoft guidance for authentication using physical FIDO2 security keys.https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-security-key-sign-in


Yubico: FIDO2 and Passkeys

Technical information from Yubico about FIDO2 credentials and YubiKey authentication.https://docs.yubico.com/software/yubikey/tools/authenticator/auth-guide/fido2.html


1Password: Save and Sign In With Passkeys

Current 1Password documentation covering passkey storage and use.https://support.1password.com/save-use-passkeys/

Comments


bottom of page