Why Passwordless
Compromised credentials remain one of the most common ways attackers get into a business. Passwords are phished, reused, leaked, guessed and brute-forced. Passwordless eliminates the shared secret entirely. There is nothing to steal, because the private key never leaves the device and is cryptographically bound to the real domain.
22%
of confirmed breaches involved stolen credentials (Verizon 2025 DBIR)
Zero
successful phishing attacks against 85,000+ Google staff since mandating FIDO security keys in 2017
Default
Microsoft Entra ID makes passkeys the default MFA and retires built-in SMS and voice, 2026
FIDO2 and Passkeys Explained
FIDO2 is the open standard behind modern passwordless. It uses public-key cryptography: your authenticator generates a unique key pair per service. The private key stays on the device, the public key goes to the service. During login you prove possession of the private key by signing a challenge. The signature is bound to the exact domain, so a phishing site cannot use it.
Passkeys are a FIDO2 credential that syncs across your devices through your Apple, Google, or Microsoft account. Same phishing resistance, better usability. iPhone, iPad, Mac, Android, Windows all support them.
New to passkeys? Start with our plain-English passkey guide.
Domain-bound
Signatures only work on the real domain. Phishing proxy fails.
No shared secret
Private key never leaves the device. Nothing for a breached service to leak.
Cross-vendor standard
Microsoft, Apple, Google, 1Password, Bitwarden, YubiKey all compatible.
Authentication Methods Compared
Hardware security keys (YubiKey, Feitian, Token2)
Pros
- + Highest assurance
- + Works on shared workstations
- + No cloud dependency
- + Best for admins and privileged accounts
Cons
- - Physical device required
- - Loss and theft risk
- - Requires backup key
Platform biometrics (Windows Hello, Face ID, Touch ID)
Pros
- + Always available
- + Smooth user experience
- + Device hardware-backed
- + No extra cost
Cons
- - Tied to the specific device
- - Lose device = need fallback
- - Biometric enrolment required
Synced passkeys (Apple, Google, Microsoft, 1Password)
Pros
- + Work across user devices
- + Very convenient
- + Phishing-resistant
- + Easy recovery via account
Cons
- - Cloud sync dependency
- - Provider account becomes critical
- - Less isolated than hardware keys
Authenticator app with number match (push)
Pros
- + Simple for staff
- + No extra hardware
- + Works on personal phones
Cons
- - Not strictly passwordless
- - Still phishable by AiTM without extra controls
- - Not FIDO2-grade
Rollout Plan
Start with admins
Global admins, privileged roles, finance. Deploy hardware keys first with a backup key each.
Windows Hello for Business across the fleet
For all Windows devices. Uses the TPM + biometric. Zero cost, deep Microsoft integration.
Passkeys for general staff
Enable passkey sign-in in Entra ID / Google / your IdP. Onboard during the next phishing awareness cycle.
Conditional Access to require phishing-resistant
Enforce for admins first, then sensitive apps (finance, payroll, source control).
Retire SMS and email codes
Block SMS and email MFA methods in the policy. Still allow authenticator app as fallback.
Monitor and adjust
Track sign-in methods used. Help staff who fall back to weaker methods.
Account Recovery (The Hard Part)
Passwordless is only as strong as its recovery path. Attackers target the recovery flow once they cannot phish the login.
- Register at least two authenticators per user (primary + backup key)
- Keep two break-glass global admin accounts with FIDO2 keys, stored physically in a safe
- Never fall back to SMS or email during recovery
- Help desk identity verification scripts. Video verify sensitive resets.
- Temporary Access Pass (TAP) in Entra ID for one-time re-registration
- Document the full recovery flow, review quarterly
Staff Adoption
Most resistance is fear, not capability. Frame it as easier, not different.
Lead with convenience
No passwords to remember. Face unlocks everything. Demo it at the kick-off session.
Mandate for admins, voluntary for staff (initially)
Admins first. Staff follow once they see it.
Quick-start cards
One page per device type. Keep in the laptop sleeve.
Super-user champions
One per team. They enrol first, help colleagues.
Common Mistakes
No backup authenticator
One lost key = locked-out user = help-desk nightmare. Always register two.
Fallback to SMS
Defeats the entire point. Block SMS and email MFA methods at the policy level.
No break-glass plan
Tenant-wide MFA failure locks everyone out including admins. Break-glass accounts are non-negotiable.
Shared workstations only have platform authenticator
Face ID does not work for shared machines. Hardware keys are required.
Passkeys without Conditional Access
Passkey works but legacy auth still accepts passwords. Conditional Access closes the loophole.
Common questions
What is passwordless authentication?
Why is it more secure?
Which protocol is used by hardware keys to support passwordless login?
What is Windows Hello for Business and how does it work?
How do I recover my account if I lose my security key or phone?
When should I use passkeys versus hardware security keys?
Does passwordless authentication satisfy ACSC Essential Eight requirements?
Can I disable password sign-in entirely after going passwordless?
Go Passwordless Safely
We deploy FIDO2 and passkey rollouts in Entra ID, Google Workspace, and Okta environments including staff training and break-glass recovery.

Remote Support