Passkeys: what are they and why are they safer than passwords?
A passkey is a modern, phishing-resistant way to sign in without having to enter a password every time. In this article, you will learn what passkeys are, how they work and why they are safer than traditional passwords.
Passwords have existed for decades, but they have one important problem: they can be guessed, stolen, reused or obtained through phishing.
Passkeys are designed to largely eliminate that problem. Instead of entering a secret password, you use a trusted device and confirm the sign-in, for example with:
- your fingerprint;
- facial recognition;
- Windows Hello;
- the PIN you use to unlock your device;
- a physical FIDO2 security key.
What exactly is a passkey?
Technically, a passkey consists of two cryptographic keys:
- a public key that is stored by the website or service;
- a private key that remains on your device, security key or supported credential manager.
When you sign in, your device uses the private key to prove that you have the correct passkey. The private key itself is not sent to the website.
A simple example
Suppose you want to sign in to Microsoft 365.
With a traditional password:
- you enter your email address;
- you enter your password;
- Microsoft checks whether the password is correct;
- you may then also need to confirm MFA.
With a passkey:
- you choose to sign in with your passkey;
- your device asks for, for example, Windows Hello, Face ID or your PIN;
- your device then uses the passkey to confirm the sign-in cryptographically;
- you are signed in without entering your password.
Why are passkeys safer than passwords?
1. You cannot simply provide a passkey to a phishing website
This is one of the most important benefits.
You may accidentally enter a password on a fake Microsoft login page. A passkey, on the other hand, is linked to the website or service for which it was created.
Your browser and operating system check this automatically.
A passkey created for a legitimate website cannot simply be used on a fake website with a different domain name.
As a result, according to Microsoft, passkeys are phishing-resistant.
2. There is no password for an attacker to steal
In a traditional attack, a criminal will often try to obtain your password.
This can happen, for example, through:
- phishing;
- a data breach;
- malware;
- password spraying;
- credential stuffing;
- a reused password from another website.
A passkey works fundamentally differently. The private key remains secured on your device or in the selected credential manager and is not sent to the service as a password.
3. Every passkey is unique to the service concerned
Many users use the same or a similar password on multiple websites.
If one website is hacked, attackers can then automatically try that password on other services.
4. No more complicated passwords to remember
A strong password must be long, unique and difficult to guess. That is secure, but not always practical for people.
With a passkey, you do not have to remember or enter such a password yourself.
You unlock the passkey using a trusted method on your device, for example:
- fingerprint;
- facial recognition;
- Windows Hello;
- a local PIN.
5. Passkeys can also provide strong MFA
In Microsoft Entra, FIDO2 passkeys can be a strong verification method. When the passkey is unlocked with biometrics or a PIN, you effectively combine possession of a trusted device with local user verification.
But what is the difference between this and my Windows Hello PIN?
A PIN and a passkey are not the same.
Your Windows Hello PIN is used to verify your identity locally on your device. That PIN can then provide access to a passkey that is securely stored on the device.
Where can a passkey be stored?
Depending on the device, service and your organisation's policy, a passkey can, for example, be stored:
- on a Windows device through Windows Hello;
- on an iPhone or iPad;
- on an Android device;
- in Microsoft Authenticator;
- in a supported password manager;
- on a physical FIDO2 security key.
Some passkeys are device-bound and remain on one specific device. Others can be securely synchronised between devices through a supported credential manager.
Your organisation determines which types of passkeys and storage methods are permitted. You will therefore not necessarily be able to use all of the options listed above.
Can I use passkeys for Microsoft 365?
Yes. Microsoft supports passkeys for both personal Microsoft accounts and Microsoft work and school accounts.
For a business account, your Microsoft 365 environment must be correctly configured for this by your organisation.
When your organisation allows passkeys for Microsoft 365, you can view the available sign-in methods via:
When your organisation supports this, you can register a passkey there via Add sign-in method.
Depending on the configuration, Microsoft may display options such as:
- Passkey;
- Passkey in Microsoft Authenticator;
- Windows Hello;
- a FIDO2 security key.
What if my laptop or smartphone is stolen?
Simply possessing the device is normally not enough to use the passkey.
The passkey usually first has to be unlocked with, for example:
- your PIN;
- fingerprint;
- facial recognition;
- another secure unlocking method.
Nevertheless, a lost or stolen device must always be reported to your IT administrator as soon as possible.
Have the device and the linked sign-in methods checked or revoked. Do not rely solely on the fact that the device is protected with a PIN or biometrics.
Does this mean that passwords will disappear?
That is ultimately the goal of passwordless authentication, but the transition will happen gradually.
Many organisations still use a combination of:
- passwords;
- Microsoft Authenticator;
- Windows Hello;
- passkeys;
- FIDO2 security keys;
- other MFA methods.
As more services support passkeys, the traditional password may become less and less important.
Why are passkeys interesting for businesses?
For organisations, passkeys are particularly interesting because they address two problems at the same time:
- they can significantly improve the security of user accounts;
- they can make signing in easier for users.
A well-configured passwordless environment can help reduce, among other things:
- password phishing;
- password reuse;
- MFA fatigue attacks;
- stolen or leaked credentials;
- password-related support requests.
For a business environment, it is necessary to determine which users and devices may use passkeys, which authentication methods are permitted, how recovery works and how this fits within the broader Microsoft 365 and Conditional Access policy.
Would you like to use passkeys within your organisation?
FLEXAMIT can help determine how passkeys and passwordless authentication can be introduced securely within your Microsoft 365 environment.
Would you like to know whether your current Microsoft 365 environment is ready for passkeys, or would you like to introduce this technology across your organisation?
Contact FLEXAMIT via:
sales@flexamit.com
In summary
- A passkey can replace a traditional password.
- The private key is not sent to the website.
- A passkey is linked to the genuine website or service.
- As a result, passkeys are much more resistant to phishing.
- You confirm the sign-in, for example, with your face, fingerprint or PIN.
- Passkeys can be stored on devices, in credential managers or on FIDO2 security keys.
- For Microsoft 365, your organisation determines which passkey methods you may use.
Comments
0 comments
Article is closed for comments.