A passkey is a modern and phishing-resistant way to sign in without having to enter a password every time. In this article, you will learn what passkeys are, how they work, and why they are more secure than traditional passwords.
Passwords have existed for decades but have a major problem: they can be guessed, stolen, reused or obtained through phishing.
Passkeys are designed to largely eliminate that problem. Instead of typing a secret password, you use a trusted device and confirm the sign-in for example with:
- your fingerprint;
- facial recognition;
- Windows Hello;
- the PIN code you use to unlock your device;
- a physical FIDO2 security key.
What exactly is a passkey?
A passkey technically consists of two cryptographic keys:
- a public key that is stored by the website or service;
- a private key that remains on your device, security key or supported credential manager.
When you sign in, your device uses the private key to prove that you have the correct passkey. The private key itself is not sent to the website.
A simple example
Suppose you want to sign in to Microsoft 365.
With a traditional password:
- you enter your email address;
- you type your password;
- Microsoft checks whether the password is correct;
- you may then have to confirm MFA.
With a passkey:
- you choose to sign in with your passkey;
- your device requests, for example, Windows Hello, Face ID or your PIN code;
- your device then uses the passkey to cryptographically confirm the sign-in;
- you are signed in without typing your password.
Why are passkeys more secure than passwords?
1. You cannot simply give a passkey to a phishing website
This is one of the most important advantages.
You can accidentally enter a password on a fake Microsoft login page. A passkey, however, is linked to the website or service for which it was created.
Your browser and operating system check this automatically.
A passkey created for a genuine website cannot simply be used on a fake website with a different domain name.
Because of this, passkeys are phishing-resistant according to Microsoft.
2. There is no password that an attacker can steal
In a traditional attack, a criminal often tries to obtain your password.
This can happen via:
- phishing;
- a data breach;
- malware;
- password spraying;
- credential stuffing;
- a reused password from another website.
A passkey works fundamentally differently. The private key remains protected on your device or in the chosen credential manager and is not sent as a password to the service.
3. Every passkey is unique to the respective service
Many users use the same or a similar password on multiple websites.
If one website is hacked, attackers then try that password automatically on other services.
4. No more remembering complicated passwords
A strong password must be long, unique and hard to guess. That is secure but not always practical for people.
With a passkey, you do not have to remember or type such a password yourself.
You unlock the passkey with a trusted method on your device, for example:
- fingerprint;
- facial recognition;
- Windows Hello;
- a local PIN code.
5. Passkeys can simultaneously provide strong MFA
With Microsoft Entra, FIDO2 passkeys can form a strong authentication method. When the passkey is unlocked with biometrics or a PIN code, you effectively combine possession of a trusted device with local user verification.
But what is the difference with my Windows Hello PIN?
A PIN code and a passkey are not the same.
Your Windows Hello PIN is used to locally verify yourself on your device. That PIN can then grant access to a passkey securely stored on the device.
Where can a passkey be stored?
Depending on the device, the service and your organisation’s policy, a passkey can for example be stored:
- on a Windows device via Windows Hello;
- on an iPhone or iPad;
- on an Android device;
- in Microsoft Authenticator;
- in a supported password manager;
- on a physical FIDO2 security key.
Some passkeys are device-bound and remain on one specific device. Others can be securely synchronised between devices via a supported credential manager.
Your organisation determines which types of passkeys and storage methods are allowed. You will therefore not necessarily be able to use all the options above.
Can I use passkeys for Microsoft 365?
Yes. Microsoft supports passkeys for both personal Microsoft accounts and for Microsoft work and school accounts.
For a business account, your Microsoft 365 environment must be properly configured by your organisation.
When your organisation allows passkeys for Microsoft 365, you can view available sign-in methods via:
If your organisation supports this, you can register a passkey there via Add sign-in method.
Depending on the configuration, Microsoft may show options such as:
- Passkey;
- Passkey in Microsoft Authenticator;
- Windows Hello;
- a FIDO2 security key.
What if my laptop or smartphone is stolen?
Possession of the device alone is normally not enough to use the passkey.
The passkey usually must first be unlocked with, for example:
- your PIN code;
- fingerprint;
- facial recognition;
- another secure unlocking method.
Still, a lost or stolen device should always be reported to your IT administrator as soon as possible.
Have the device and linked sign-in methods checked or revoked. Do not rely solely on the fact that the device is protected by a PIN or biometrics.
Does this mean passwords will disappear?
That is ultimately the goal of passwordless authentication, but the transition happens gradually.
Many organisations still use a combination of:
- passwords;
- Microsoft Authenticator;
- Windows Hello;
- passkeys;
- FIDO2 security keys;
- other MFA methods.
As more services support passkeys, the traditional password can become less important.
Why are passkeys interesting for companies?
For organisations, passkeys are especially interesting because they address two problems at once:
- they can significantly increase the security of user accounts;
- they can make signing in simpler for users.
A well-configured passwordless environment can help reduce:
- password phishing;
- password reuse;
- MFA fatigue attacks;
- stolen or leaked credentials;
- password-related support requests.
For a business environment, it must be determined which users and devices may use passkeys, which authentication methods are allowed, how recovery works and how this fits within the broader Microsoft 365 and Conditional Access policy.
Do you want to use passkeys within your organisation?
FLEXAMIT can help determine how passkeys and passwordless authentication can be securely implemented within your Microsoft 365 environment.
Do you want to know if your current Microsoft 365 environment is ready for passkeys or do you want to roll out this technology organisation-wide?
Contact FLEXAMIT via:
sales@flexamit.com
In summary
- A passkey can replace a traditional password.
- The private key is not sent to the website.
- A passkey is linked to the real website or service.
- Because of this, passkeys are much more resistant to phishing.
- You confirm sign-in for example with your face, fingerprint or PIN code.
- Passkeys can be stored on devices, in credential managers or on FIDO2 security keys.
- For Microsoft 365, your organisation determines which passkey methods you may use.
Comments
0 comments
Article is closed for comments.