ExplainerScams & security

Passkeys explained for small business: what they replace, where they work and where they don't

What a passkey is, how it differs from passwords and 2FA, what Google, Microsoft and Apple support, where passkeys help, their limits, and what to do first.

A passkey is a way to sign in without typing a password. The account still has a secret, but you never see it, type it or reuse it. This explainer sets out what the vendors say passkeys are, how they differ from passwords and from two-factor authentication (2FA), what Google, Microsoft and Apple support, and where they fall short. It is written for owners and office managers, not IT staff.

What a passkey is

The FIDO Alliance, the industry group behind the standard, says passkeys are “FIDO cryptographic credentials that are tied to a user’s account on a website or application”. You approve a sign-in “with the same process that they use to unlock their device”, such as a fingerprint, face scan or PIN.

Microsoft explains the mechanism this way: your device generates a pair of keys, a private key and a public key. The private key stays on your device and the public key is registered with the service. Apple says the public key is stored on the service’s server and the server never learns what the private key is.

Google says your biometric data, used for fingerprint or face unlock, “stays on your device and is never shared with Google”.

How a passkey differs from a password

In general, a password is a shared secret: you know it, the service checks it, and anyone who gets it can use it. That is why passwords can be phished, guessed, reused and leaked.

A passkey has no secret for you to hand over. Microsoft says passkeys are resistant to phishing because they are bound to specific domains, so a passkey for a genuine site can’t be used on a fraudulent lookalike. The FIDO Alliance calls them “phishing-resistant”, and Apple describes them as “designed so that there are no shared secrets”. Google says passkeys “can’t be shared, copied, written down, or accidentally given to someone else”.

For a business, that last point matters. A passkey can’t be pasted into a shared spreadsheet or read out to a caller pretending to be from the bank.

How it differs from 2FA

In general, traditional two-factor authentication asks for a password and then a second proof, such as a code from an app or a text message. Our guide to two-factor authentication across business accounts covers those methods.

A passkey works differently. Google says that if your account has 2-Step Verification, a passkey bypasses the second authentication step, because it verifies that you own the device. On our reading, a passkey is one step that does the work of two, and the phishing resistance comes from the key, not from an extra code someone could be tricked into reading out.

What Google, Microsoft and Apple support

Google. Google lists these requirements for using passkeys: Windows 10, macOS Ventura or ChromeOS 109 or later on computers, Android 9 or iOS 16 or later on phones, or a hardware security key that supports FIDO2. Browsers listed are Chrome 109, Safari 16, Edge 109 and Firefox 122 or later. Google also says that on Android and in Chrome, signing in with a password saved in Google Password Manager may create a passkey automatically, and you can turn that off in Chrome’s settings.

Microsoft. Microsoft says you can create passkeys and save them either in a synced credential manager such as Microsoft Password Manager, or as device-bound passkeys that stay on one device. Windows Hello supplies the PIN, fingerprint or face check on Windows. Microsoft notes that Microsoft Password Manager is available in Edge version 142 and newer with a personal profile.

For work and school accounts, Microsoft’s Entra documentation says passkeys are available in all Entra ID editions, including the free one, with no extra licences. It says Entra supports synced passkeys and device-bound passkeys on FIDO2 security keys and in Microsoft Authenticator. Administrators can set which types are allowed and can require passkeys for sensitive resources.

Apple. Apple says passkeys sync across your Apple devices through iCloud Keychain, which is “end-to-end encrypted with strong cryptographic keys not known to Apple”. It says any Apple Account using iCloud Keychain requires two-factor authentication, and that passkeys can be recovered through iCloud Keychain escrow, protected by your Apple Account password, a text message to your registered phone number and your device passcode.

Where passkeys help

  • Phishing. A fake login page can’t collect something you never type.
  • Password reuse. Microsoft says a passkey is bound to the specific site it was created for.
  • Speed. Apple describes passkeys as faster to sign in with and easier to use, and Microsoft describes them as removing complicated password creation.

Where passkeys don’t help, or need care

  • Work accounts may not accept a passkey alone. Google says Google Workspace users “may not be able to sign in with just a passkey”, although passkeys can work as a second factor or for recovery. Microsoft says availability for work accounts depends on organisational policy.
  • Not every service offers them. Microsoft says availability depends on whether the website or app supports passkeys. Keep your existing password and 2FA where a service has no passkey option.
  • Synced passkeys are only as safe as the account that syncs them. Microsoft advises treating synced passkeys as phishing-resistant, but with “the same security posture as other unattested authenticators”. Apple says its design protects passkeys even if an Apple Account is compromised. Google Password Manager and iCloud Keychain accounts still need their own strong protection.
  • Shared logins are awkward. A passkey is tied to a person’s device or credential manager. If several staff use one shared login, work out whose passkey it is before switching. This is our reading, not a vendor statement.
  • Guests. Microsoft says Entra passkey registration isn’t supported for guest users, including B2B collaboration users.
  • Lost devices. Google says to sign in to your Google Account from another device and remove the passkey on the lost or stolen device.

What to do

Passkeys are an upgrade, not a reason to drop other protections. Do the accounts that can reset all the others first, then work outward. The checklist is our reading of the vendor guidance. It isn’t a legal or compliance requirement. If you’re also tightening your wider setup, see what to do in the first hour after a business email account is hacked.

Checklist

  • Create a passkey for your main email account. Open your Google or Microsoft account security settings and add a passkey, on a phone or computer with Android 9 or later, iOS 16 or later, Windows 10 or later or macOS Ventura or later.
  • Keep a second sign-in method on that account. Leave an authenticator app or backup option in place until you’ve signed in with the passkey on more than one device.
  • Ask your IT provider or Workspace or Microsoft 365 administrator whether passkeys are allowed for staff. Google says Workspace users may not be able to sign in with only a passkey, and Microsoft Entra lets administrators choose which passkey types are permitted.
  • Check where each passkey is stored. For each business-critical account, record whether its passkey is in iCloud Keychain, Google Password Manager, Microsoft Password Manager or a hardware security key, and name the person whose device or account unlocks it.
  • Buy or nominate a hardware security key for owners and administrators (our suggestion). Google lists FIDO2 hardware keys as supported, and Microsoft Entra supports them as device-bound passkeys.
  • Write down the lost-phone steps. Sign in from another device and remove the lost device’s passkey (Google’s stated step), then confirm the account’s recovery phone number and recovery email are current.
  • Turn on two-factor authentication where a service has no passkeys. Set up an authenticator app on each account that has no passkey option.
  • Protect the account that syncs your passkeys. Apple says iCloud Keychain needs two-factor authentication on the Apple Account. Confirm 2-Step Verification (Google) or two-step verification (Microsoft) is on, and that the recovery phone number and email are current, for the account that holds your synced passkeys.