Should UK businesses move from passwords to passkeys?

Yes, UK businesses should begin moving towards passkeys, but a phased approach is more practical than trying to eliminate passwords immediately. Legacy applications, third-party systems and some recovery processes may still require passwords, so organisations need a transition strategy that supports both methods.

Passwords remain a common authentication method, but phishing, password reuse, credential stuffing and stolen credentials can expose business accounts. Passkeys offer a more secure alternative based on public-key cryptography rather than shared passwords, making them a practical preferred authentication method where applications and identity systems support them.

What are passkeys?

Passkeys are passwordless credentials based on FIDO2 standards and public-key cryptography. They allow users to authenticate using a device or credential manager, often with a fingerprint, facial recognition or device PIN.

During registration, a cryptographic key pair is created. The private key is kept by the user’s authenticator, while the corresponding public key is registered with the website or service. During sign-in, the private key is used to prove possession without sending a password to the service.

This design provides an important security advantage: a passkey is tied to the service for which it was created, making it resistant to common credential-phishing techniques. Microsoft describes Entra passkeys as origin-bound and phishing-resistant credentials.

Passkeys can be either synced across trusted devices through a credential manager or device-bound, where the credential remains tied to a particular device or security key. The appropriate approach depends on the organisation’s security requirements, users and device environment.

Why are passwords still a security concern?

Passwords remain widely used because they are supported by almost every online service and business application. However, they create several security challenges.

Common risks include:

  • Password reuse across different services
  • Weak or predictable passwords
  • Phishing and credential theft
  • Credential stuffing after data breaches
  • Password sharing
  • Attackers obtaining passwords through malware or social engineering

A strong password policy can reduce some of these risks, but it cannot make a password inherently resistant to phishing. If an employee is persuaded to enter a valid password into a fraudulent website, an attacker may be able to use that credential.

Where passkeys are unavailable, the NCSC recommends continuing to use strong passwords and 2-step verification rather than leaving accounts unprotected.

How do passkeys improve authentication security?

The main advantage of passkeys is that they change how authentication credentials are created and used.

Protection against phishing

A conventional phishing page can imitate a legitimate login page and ask the victim to enter their password. A passkey works differently because the cryptographic credential is bound to the legitimate service.

As a result, entering a passkey on a fraudulent website does not simply give an attacker a reusable password. This is one of the reasons the NCSC recommends passkeys wherever they are available.

No password to reuse

Passkeys are not shared secrets that users create and reuse across multiple websites. Each passkey is associated with the service for which it was registered.

This removes an important weakness of password-based authentication, particularly where users reuse credentials across business and personal accounts.

Simpler sign-in

Users can normally authorise a passkey using the same method they use to unlock their device, such as a fingerprint, face recognition or PIN.

The NCSC also reports that passkey logins can be substantially faster than traditional username, password and 2-step verification processes.

Passkeys vs passwords: what is the difference?

FeaturePasskeysPasswords
AuthenticationPublic-key cryptographyShared secret
Phishing resistanceDesigned to resist phishingVulnerable to phishing
Password reuseNot applicableCommon risk
User interactionDevice, biometric or PINPassword entry
Credential storagePrivate key held by authenticatorPassword stored or verified by service
CompatibilityIncreasing but not universalVery widespread
Recovery considerationsDepends on passkey type and account setupPassword reset/recovery process


The key distinction is not simply convenience. Passkeys change the underlying authentication model from a reusable secret to a cryptographic credential.

Should businesses replace passwords immediately?

For most organisations, an immediate complete replacement is unlikely to be practical.

Businesses should first identify which applications and services support passkeys and determine which authentication methods are appropriate for different groups of users.

A phased approach could look like this:

  1. Audit existing authentication methods across critical systems, cloud platforms and business applications.
  2. Identify supported services where passkeys can already be introduced.
  3. Prioritise high-risk accounts, particularly administrators and users with access to sensitive systems.
  4. Pilot the rollout with a small group of users.
  5. Test recovery procedures for lost, replaced or unavailable devices.
  6. Expand adoption gradually once the process has been tested.

This approach allows organisations to improve authentication security without creating unnecessary disruption.

What about Microsoft Entra ID and Microsoft 365?

Microsoft Entra ID supports both synced and device-bound passkeys, including passkeys stored in supported credential managers, Microsoft Authenticator and FIDO2 security keys. Organisations can also use passkey profiles and Conditional Access policies to control how passkeys are deployed.

This is particularly relevant for UK businesses using Microsoft cloud services.

Microsoft is also making passkeys increasingly central to the Entra authentication experience. From 1 September 2026, Microsoft began rolling out passkeys as the default authentication experience for users enabled for SMS or voice authentication. Microsoft-provided SMS and voice authentication delivery is scheduled for retirement from 1 February 2027, subject to the exceptions and arrangements described in Microsoft’s current guidance.

Businesses using Entra ID should therefore review their current authentication methods rather than waiting until a change creates an operational problem.

Organisations that need help reviewing identity controls and wider security requirements can also consider professional cyber security consultancy.

What challenges should businesses consider?

Passkeys can strengthen authentication, but implementation still requires planning.

Legacy applications

Some older applications and infrastructure may not support passkeys. These systems may need to continue using passwords or another authentication method until they can be upgraded or replaced.

Device management

Businesses need clear policies around company-managed devices, personal devices, credential managers and security keys. The right approach may differ between ordinary users, administrators and highly privileged accounts.

Account recovery

Recovery deserves particular attention. Employees can lose devices, replace phones or become unable to access their normal authentication method.

Organisations should define secure recovery procedures before expanding passkey adoption. Recovery should not simply reintroduce a weak authentication method that undermines the security benefits of the original passkey deployment.

Contractors and third parties

External users, contractors and suppliers may have different devices and authentication capabilities. Their access should be considered during implementation rather than treated as an afterthought.

How should UK businesses introduce passkeys?

A successful rollout should form part of a broader identity and cyber security programme.

Businesses should consider:

  • Start with sensitive accounts: Prioritise administrators and users with access to critical systems.
  • Check application compatibility: Identify which business applications already support passkeys.
  • Choose the appropriate passkey type: Consider synced or device-bound credentials based on the organisation’s security and operational requirements.
  • Review recovery: Establish secure procedures for lost devices and account recovery.
  • Test before scaling: Run a controlled pilot and resolve usability or support issues.
  • Monitor authentication: Continue reviewing unusual sign-in activity and access patterns.
  • Educate employees: Explain how passkeys work and what users should do if they lose a device or notice suspicious activity.

Microsoft currently recommends device-bound passkeys for administrators and highly privileged users in relevant Entra scenarios, while synced passkeys can provide greater convenience for many standard users.

Passkeys should complement wider security controls

Moving to passkeys does not remove the need for other security measures.

Businesses still need appropriate access controls, device security, software updates, monitoring, incident response and security testing. Authentication is one part of an organisation’s overall security architecture.

For example, a vulnerability assessment can help identify weaknesses across systems, applications and networks that may exist alongside authentication risks. Gradeon’s cyber security vulnerability assessment service covers the identification and prioritisation of weaknesses across IT environments.

Similarly, organisations should consider how stronger authentication fits into their wider data breach resilience planning.

What should businesses do when passkeys are not available?

Businesses should not weaken security simply because a particular application does not support passkeys.

For services that still require passwords, organisations should continue using strong, unique passwords and appropriate 2-step verification or MFA. The NCSC specifically recommends this approach where passkeys are not available.

Over time, IT teams can identify applications that create unnecessary dependence on password authentication and consider whether those systems can be upgraded, replaced or placed behind stronger access controls.

This makes password reduction an ongoing identity strategy rather than a single migration project.

Frequently asked questions

Are passkeys more secure than passwords?

Passkeys are designed to provide phishing-resistant authentication and avoid many of the risks associated with reusable passwords. The NCSC recommends using passkeys over passwords wherever they are available.

Do passkeys completely replace passwords?

Not yet for every business. Some applications, legacy systems and recovery processes may still require passwords. Organisations can reduce password dependence gradually while maintaining appropriate protection for systems that still use them.

Can businesses use passkeys with Microsoft 365?

Yes. Microsoft Entra ID supports passkeys for organisational authentication, including synced and device-bound options. Organisations can configure passkey profiles and authentication policies according to their requirements.

Are passkeys the same as two-factor authentication?

Passkeys provide strong authentication and can satisfy multifactor authentication requirements when combined with local user verification such as a device PIN or biometric. Their main security advantage is that they are designed to resist phishing rather than relying on a shared secret or one-time code.

What should a business do before moving to passkeys?

Start by reviewing existing authentication methods, identifying compatible applications, prioritising sensitive accounts, selecting suitable passkey types and testing account recovery. Businesses should also communicate the change clearly to employees before expanding the rollout.

Moving towards passwordless authentication

Passkeys provide UK businesses with a practical way to reduce their reliance on passwords and strengthen protection against phishing and credential theft. The technology is already supported across many modern devices and services, and the NCSC recommends using passkeys wherever they are available.

However, businesses do not need to treat passwordless authentication as an overnight migration. A more practical approach is to introduce passkeys where they provide clear security benefits, maintain strong controls for systems that still require passwords, and gradually modernise older authentication processes.

For organisations reviewing their wider identity, infrastructure and cyber security controls, the move towards passkeys can become part of a broader programme for improving security resilience rather than a standalone technology project.