Thought leadership: Passkeys are here, but are they the end of the authentication story?
Published: 23 September 2026 by Daniel Mitchell
Passwords have been dying for a very long time.
We have been told for years that their replacement is just around the corner and that “passwordless” authentication is the future. In 2026, however, I think we can finally say that something has genuinely changed.
Passkeys have moved from being an interesting emerging technology to something businesses need to understand and actively plan for.
The UK Government’s National Cyber Security Centre (NCSC) now recommends using passkeys wherever they are available. Microsoft is also accelerating their adoption across Microsoft 365 and Entra ID, with passkeys becoming the default authentication method and Microsoft moving away from SMS and voice authentication, thankfully.
That direction is sensible. Passkeys solve some very real weaknesses in passwords and traditional MFA. But I am not convinced the discussion should end there, particularly for administrators and other high-value accounts.
Why Passkeys are an improvement
Traditional authentication has several weaknesses. Passwords can be guessed, reused, stolen in data breaches or handed over voluntarily to a convincing phishing website. Adding MFA makes this significantly better, but some forms of MFA are themselves vulnerable.
An attacker operating a sophisticated phishing site can potentially capture a password and persuade someone to enter a one-time authentication code. Push notifications can be abused through MFA fatigue. SMS presents its own risks around interception and SIM swapping.
Passkeys work differently. Rather than transmitting a secret that can be copied, the device holds a cryptographic private key. The website or service holds the corresponding public key. When you log in, your device proves that it possesses the private key without actually sending it.
Crucially, that credential is also tied to the genuine website. That makes properly implemented passkeys extremely resistant to conventional phishing. A convincing fake Microsoft login page cannot simply collect your passkey and replay it somewhere else.
The NCSC now recommends passkeys ahead of passwords and traditional two-step verification where available, while Microsoft is actively moving Entra ID users away from SMS and voice authentication. For Microsoft 365 users, passkeys are becoming the default rather than the exception.
But is a passkey really two factors?
This is where I think the conversation becomes more interesting. At first sight, a passkey login on a phone or laptop can feel like a single action. I open my laptop, I authenticate with Touch ID, Face ID or perhaps a PIN. The passkey stored on that same device then signs me into Microsoft 365. Where are the two factors?
Technically, they are there, the cryptographic passkey represents something I have. My biometric or PIN represents something I am or something I know. The NCSC specifically regards a FIDO2 credential requiring user verification as genuine MFA, noting that the two factors do not need to reside on separate devices.
I don’t disagree with that definition, but I do think there is a distinction between two factors and two independently held things. And I believe that distinction matters.
One device, one point of trust
Imagine that my laptop contains my passkey and the same laptop provides the biometric or PIN used to unlock it. Cryptographically, there are two factors. Operationally, however, I have placed a great deal of trust in one physical device.
That does not make passkeys insecure. A well-managed modern device with hardware-backed credentials, encryption and strong biometric protection is an extremely strong authentication platform and far more resistant to phishing than a password plus a six-digit code.
For most users, that is probably a very sensible balance. For the Global Administrator of a Microsoft 365 environment containing an organisation’s email, files, identities and security controls, I think the standard should be higher.
The distinction becomes more important when passkeys are synchronised. With Google Password Manager, for example, a passkey can be stored against a Google Account and made available on other devices signed in to that account. Apple provides a similar model through iCloud Keychain. That convenience is one of the great strengths of passkeys. Lose a phone or replace a laptop and you do not necessarily lose access to your credentials.
But the trust boundary has moved. I am no longer relying solely on the security of one device. I am also relying on the security, recovery controls and device enrolment around the Google or Apple account that synchronises those credentials.
Imagine a user whose Microsoft 365 passkey is held in Google Password Manager. If an attacker were able to compromise that Google account sufficiently to enrol another trusted device, the concern is no longer simply whether the original laptop has been stolen. The security of the Microsoft 365 credential has become partly dependent on the security of the separate account used to synchronise it.
That does not mean synced passkeys are weak. Microsoft itself describes them as phishing-resistant and suitable for most users, but Microsoft also recommends considering device-bound passkeys, including FIDO2 security keys, for administrators and highly privileged users.
This distinction is a very clear indicator of a potential weakness and is important.
The physical key still has a place
This is why I remain a strong advocate of physical FIDO2 security keys such as YubiKeys for high-value accounts.
A physical security key creates real separation. The credential remains bound to the key rather than being synchronised through another account or sitting inside the laptop being used.
Lose the laptop and the authentication credential can still be in your pocket. For privileged access, that separation is valuable.
In my view, a physical FIDO2 key remains about as close as we currently get to a practical authentication gold standard for normal business use. That does not necessarily mean every employee needs a YubiKey, it means authentication methods should reflect the level of access and risk. I think it’s a mistake for businesses to look for a single answer that applies to everyone.
For most organisations, I would broadly divide users into three groups.
- For general users, synced passkeys on properly managed company devices represent a significant security improvement and should increasingly become standard practice.
- For senior staff and users with access to particularly sensitive information, I would consider device-bound passkeys and stronger conditional access controls.
- For administrators and other highly privileged accounts, I would still favour a physical FIDO2 security key, ideally with a separate backup key securely held.
The bigger problem may be recovery
There is another area businesses should not overlook. We spend a great deal of time discussing how someone authenticates when everything is working normally. Attackers increasingly understand that account recovery can be the softer route in.
What happens when somebody loses their device?
Who is allowed to reset their authentication?
What proof of identity is required?
Can the helpdesk, IT manager or IT Administrator be socially engineered into registering a new authentication method?
There is little value in strong day-to-day authentication if an attacker can simply persuade an administrator to bypass it. As organisations adopt passkeys, identity recovery procedures need to become part of the same conversation. Strong authentication needs strong recovery.
But I would resist treating ‘passkeys’ as a single level of assurance. A synced passkey on a personal device, a device-bound credential on a managed laptop and a FIDO2 security key physically held by an administrator are not operationally equivalent.
For the people holding the keys to the kingdom, I still prefer an actual key.
What should businesses do now?
If your organisation still relies heavily on passwords, SMS codes or push-based MFA, I would start planning the move to phishing-resistant authentication now, but don’t simply enable passkeys and consider the job complete.
Decide which type of passkey is appropriate for which users, identify your privileged accounts, consider physical FIDO2 keys for those accounts and review how identity recovery works when somebody loses access.
Authentication is changing quickly. The opportunity is not simply to remove passwords, but to build a stronger identity model around what replaces them.
Lifeline IT works with organisations to review Microsoft 365 security, identity and access controls, including MFA, passkeys, Conditional Access and privileged account protection. If you would like us to review whether your current authentication model is appropriate for the level of risk in your organisation, please get in touch.
REPORT AN INCIDENT
To access the Lifeline IT support portal and log an incident, login below.
STAY UPDATED
Sign up to our newsletter for informative news about the IT and technology landscape
Offices
Head Office
Unit 8 Stirling Industrial Centre, Stirling Way,
Borehamwood, Herts, WD6 2BT
European Office
3rd Floor, Rokin 92-96, 1012 KZ Amsterdam
Regional Office
Trinity Court, Trinity Street, Peterborough, PE1 1DA
Copyright © 2026 Lifeline IT Solutions Ltd. All rights reserved.|Website Design & Development by Viridian Partnership
