A familiar-looking email arrives: your account needs attention, and you must sign in to fix it. The page looks convincing. You enter your password, then supply the verification code it requests.
Unfortunately, stronger passwords alone cannot solve the problem of entering your credentials into the wrong website. Passkeys take a different approach. They let you prove that you own an account without typing a reusable password into the sign-in page.
For Knoxville and East Tennessee businesses, that makes passkeys worth understanding—especially when email accounts provide access to customer conversations, invoices, and sensitive documents.
What is a passkey?
A passkey is a digital credential created for a particular account and service. Instead of sharing a password, your device uses cryptographic keys to prove that you are allowed to sign in. The service holds the public part; your authenticator controls the private part.
You usually authorize its use with a fingerprint, facial recognition, or a device PIN. That local check unlocks the credential. It does not mean the website receives your fingerprint or that your phone’s PIN becomes your online password.
From an employee’s perspective, the process can feel much simpler: choose the passkey option, approve the sign-in, and continue working.
Why does this help against phishing?
Passkeys are tied to the service they were created for. A fraudulent website impersonating that service cannot simply collect the passkey and reuse it the way it might collect a password or one-time code. That connection to the legitimate service is a central reason passkeys are described as phishing-resistant.
This is a meaningful improvement, but it does not make an account invulnerable. Malware on a device, stolen authenticated sessions, and weak recovery procedures can still create problems. Businesses still need device protection, updates, and sensible access controls.
Employees should also continue reporting suspicious messages. A passkey protects a sign-in; it cannot judge whether an invoice or payment instruction is legitimate.
Can we use them with Microsoft 365?
Microsoft Entra ID, the identity service used for Microsoft 365 work accounts, supports passkeys. Available options include FIDO2 security keys, Microsoft Authenticator, and supported native or third-party passkey providers. Administrators control which options employees can register and use.
Microsoft lists passkey authentication as available across Entra ID editions, including Free. Additional controls and services may have their own licensing requirements, so a deployment should be reviewed against the organization’s actual environment.
Compatibility matters, too. For Microsoft Authenticator passkeys, Microsoft currently lists Android 14 or later and iOS 17 or later. Certain cross-device workflows require Bluetooth and internet connectivity. Testing employees’ actual phones, computers, and browsers should come before a company-wide change.
Where does the passkey live?
There are two broad approaches.
A device-bound passkey stays on a particular authenticator, such as a hardware security key. This can be useful when a business wants tighter control over where credentials exist.
A synced passkey can be made available across devices through a supported credential provider. This can improve convenience when employees replace or switch devices. It also makes the security and recovery of the provider account part of the business’s decision.
Neither approach should be chosen solely because it sounds more convenient or more technical. The right choice depends on employee workflows, account sensitivity, and how the company manages devices.
What if someone loses their phone or security key?
Plan for that before enrollment.
Where supported and permitted by policy, a second registered authenticator can provide another way to sign in. The business also needs a documented process for verifying an employee’s identity, removing a lost credential, and enrolling a replacement. Recovery deserves the same care as normal sign-in.
Our recommendation is to rehearse the process with a test account. Ask: if this employee loses their phone tomorrow morning, who helps them, what evidence verifies their identity, and how quickly can they return to work?
Start with a manageable pilot
A sensible rollout begins with a small group representing different jobs and devices. Include someone who works remotely, someone who changes computers frequently, and someone who needs occasional assistance signing in.
Have the group test everyday tasks and recovery scenarios. Provide short enrollment instructions, explain what legitimate prompts look like, and record any compatibility problems. Then expand in stages.
Enabling passkeys and requiring their use are separate decisions. Administrators should review permitted fallback methods and access policies as part of the rollout.
Passkeys offer businesses a practical opportunity to improve account protection while reducing password friction. CNS can help assess your Microsoft 365 environment, choose an appropriate approach, and plan a rollout that keeps employees productive.
