All Guides
Passwordless Security

Passwordless Authentication: The End of Passwords

FIDO2, passkeys, hardware keys, and Windows Hello for Business. How passwordless actually works, which method fits which use case, and how to roll it out without breaking account recovery.

Last updated October 2026

Why Passwordless

Compromised credentials remain one of the most common ways attackers get into a business. Passwords are phished, reused, leaked, guessed and brute-forced. Passwordless eliminates the shared secret entirely. There is nothing to steal, because the private key never leaves the device and is cryptographically bound to the real domain.

22%

of confirmed breaches involved stolen credentials (Verizon 2025 DBIR)

Zero

successful phishing attacks against 85,000+ Google staff since mandating FIDO security keys in 2017

Default

Microsoft Entra ID makes passkeys the default MFA and retires built-in SMS and voice, 2026

FIDO2 and Passkeys Explained

FIDO2 is the open standard behind modern passwordless. It uses public-key cryptography: your authenticator generates a unique key pair per service. The private key stays on the device, the public key goes to the service. During login you prove possession of the private key by signing a challenge. The signature is bound to the exact domain, so a phishing site cannot use it.

Passkeys are a FIDO2 credential that syncs across your devices through your Apple, Google, or Microsoft account. Same phishing resistance, better usability. iPhone, iPad, Mac, Android, Windows all support them.

New to passkeys? Start with our plain-English passkey guide.

Domain-bound

Signatures only work on the real domain. Phishing proxy fails.

No shared secret

Private key never leaves the device. Nothing for a breached service to leak.

Cross-vendor standard

Microsoft, Apple, Google, 1Password, Bitwarden, YubiKey all compatible.

Authentication Methods Compared

Hardware security keys (YubiKey, Feitian, Token2)

Pros

  • + Highest assurance
  • + Works on shared workstations
  • + No cloud dependency
  • + Best for admins and privileged accounts

Cons

  • - Physical device required
  • - Loss and theft risk
  • - Requires backup key

Platform biometrics (Windows Hello, Face ID, Touch ID)

Pros

  • + Always available
  • + Smooth user experience
  • + Device hardware-backed
  • + No extra cost

Cons

  • - Tied to the specific device
  • - Lose device = need fallback
  • - Biometric enrolment required

Synced passkeys (Apple, Google, Microsoft, 1Password)

Pros

  • + Work across user devices
  • + Very convenient
  • + Phishing-resistant
  • + Easy recovery via account

Cons

  • - Cloud sync dependency
  • - Provider account becomes critical
  • - Less isolated than hardware keys

Authenticator app with number match (push)

Pros

  • + Simple for staff
  • + No extra hardware
  • + Works on personal phones

Cons

  • - Not strictly passwordless
  • - Still phishable by AiTM without extra controls
  • - Not FIDO2-grade

Rollout Plan

1

Start with admins

Global admins, privileged roles, finance. Deploy hardware keys first with a backup key each.

2

Windows Hello for Business across the fleet

For all Windows devices. Uses the TPM + biometric. Zero cost, deep Microsoft integration.

3

Passkeys for general staff

Enable passkey sign-in in Entra ID / Google / your IdP. Onboard during the next phishing awareness cycle.

4

Conditional Access to require phishing-resistant

Enforce for admins first, then sensitive apps (finance, payroll, source control).

5

Retire SMS and email codes

Block SMS and email MFA methods in the policy. Still allow authenticator app as fallback.

6

Monitor and adjust

Track sign-in methods used. Help staff who fall back to weaker methods.

Account Recovery (The Hard Part)

Passwordless is only as strong as its recovery path. Attackers target the recovery flow once they cannot phish the login.

  • Register at least two authenticators per user (primary + backup key)
  • Keep two break-glass global admin accounts with FIDO2 keys, stored physically in a safe
  • Never fall back to SMS or email during recovery
  • Help desk identity verification scripts. Video verify sensitive resets.
  • Temporary Access Pass (TAP) in Entra ID for one-time re-registration
  • Document the full recovery flow, review quarterly

Staff Adoption

Most resistance is fear, not capability. Frame it as easier, not different.

Lead with convenience

No passwords to remember. Face unlocks everything. Demo it at the kick-off session.

Mandate for admins, voluntary for staff (initially)

Admins first. Staff follow once they see it.

Quick-start cards

One page per device type. Keep in the laptop sleeve.

Super-user champions

One per team. They enrol first, help colleagues.

Common Mistakes

No backup authenticator

One lost key = locked-out user = help-desk nightmare. Always register two.

Fallback to SMS

Defeats the entire point. Block SMS and email MFA methods at the policy level.

No break-glass plan

Tenant-wide MFA failure locks everyone out including admins. Break-glass accounts are non-negotiable.

Shared workstations only have platform authenticator

Face ID does not work for shared machines. Hardware keys are required.

Passkeys without Conditional Access

Passkey works but legacy auth still accepts passwords. Conditional Access closes the loophole.

Common questions

What is passwordless authentication?
Authentication that replaces passwords with cryptographically bound methods: biometrics, hardware keys, and passkeys. The private key never leaves the device.
Why is it more secure?
No shared secret to phish. Signatures are bound to the real domain. Attacker cannot replay a captured credential.
Which protocol is used by hardware keys to support passwordless login?
FIDO2. Hardware security keys like YubiKey use the FIDO2 protocol (WebAuthn and CTAP2) to enable passwordless login. The key generates a public-private key pair per service. The private key never leaves the device, and the signed challenge is bound to the real domain so phishing proxies cannot reuse it. DMARC, SMTP and TLS are not authentication protocols for hardware keys. DMARC is for email sender validation, SMTP is for email transport, and TLS is for connection encryption.
What is Windows Hello for Business and how does it work?
Windows Hello for Business is Microsoft passwordless sign-in built into Windows 10 and 11. It uses the device TPM chip plus a biometric (face or fingerprint) or PIN to authenticate to Entra ID without a password. The credential is device-bound, hardware-backed, and free with existing Microsoft 365 licences.
How do I recover my account if I lose my security key or phone?
Register at least two authenticators per user so a lost device does not lock you out. Keep two break-glass global admin accounts with FIDO2 keys stored in a physical safe. Use Temporary Access Pass in Entra ID for one-time re-registration. Never fall back to SMS or email codes during recovery, and require video identity verification for sensitive resets.
When should I use passkeys versus hardware security keys?
Use hardware security keys for admins, privileged accounts, and shared workstations because they offer the highest assurance and work on any device. Use synced passkeys for general staff on their own devices because they are convenient, recover through the user cloud account, and still provide phishing-resistant sign-in. Most businesses deploy both: keys for admins, passkeys for everyone else.
Does passwordless authentication satisfy ACSC Essential Eight requirements?
Yes. The ACSC Essential Eight recommends phishing-resistant MFA at Maturity Level Two and above. FIDO2 security keys, Windows Hello for Business, and synced passkeys are all phishing-resistant because the cryptographic challenge is bound to the real domain. Moving to passwordless directly satisfies this requirement.
Can I disable password sign-in entirely after going passwordless?
Yes, but only after all users have registered at least one passwordless method and you have confirmed break-glass accounts work. Use Conditional Access in Entra ID to block legacy authentication and require phishing-resistant MFA for admins first, then roll out to all users. Monitor sign-in logs for a 30-day period before fully disabling password fallback.

Go Passwordless Safely

We deploy FIDO2 and passkey rollouts in Entra ID, Google Workspace, and Okta environments including staff training and break-glass recovery.