We've spent years trying to prove who we are online.
First, there were passwords, and we all chose “password1”. Then came increasingly complex password rules, resulting in passwords that were harder to remember but often reused across multiple accounts. If one password was stolen, several accounts could be put at risk.
Password managers improved things by generating and storing unique passwords for every website. But even the strongest password has one weakness: it can still be stolen, by tricking someone into entering it on a convincing fake website.
Multi-factor authentication (MFA) added another layer of protection through text messages, emails, phone calls or authentication apps. It's far better than relying on passwords alone, but cyber criminals have continued to evolve their tactics.
That's why Microsoft is encouraging organisations to move to passkeys, a new authentication method designed to be both more secure and easier to use.
What is a passkey?
Think of a passkey as a digital VIP pass.
Instead of entering a password and then a one-time code, you simply prove it's you using your device:
- Your fingerprint
- Face recognition
- A PIN on your device
- A security key
A quick tap, scan or glance and you're signed in.
Unlike passwords, passkeys stay securely linked to your device. They can't be reused across multiple accounts, written on sticky notes or accidentally entered on a fake login page.
In practice, this means signing in to Microsoft 365 with the same fingerprint, face scan or PIN you already use to unlock your laptop or mobile device.
Why is Microsoft making the change?
Traditional MFA is effective, but cyber criminals have become increasingly skilled at creating fake login pages, intercepting authentication codes and bombarding users with approval requests until one is accepted by mistake.
Passkeys remove many of these opportunities because there is no password to steal and no code for a criminal to intercept or trick a user into approving.
Users love passkeys too
Security isn't the only benefit.
Passkeys make signing in faster and simpler. Instead of waiting for a code or resetting a forgotten password, users can unlock access with a fingerprint, facial recognition or PIN.
That means less time spent:
- Signing in
- Waiting for authentication codes
- Resetting passwords
- Contacting IT for login support
For busy employees, it's simply a better experience.
What does this mean for Microsoft 365 users?
Microsoft has announced that passkeys will become the default sign-in method from September 2026.
Organisations still using SMS or phone-based authentication are being encouraged to move to passkeys, as Microsoft's SMS and voice authentication services are due to retire in February 2027.
It is a positive change. Businesses that start exploring passkeys today can make the transition gradually, helping users get comfortable with the new experience while strengthening security at the same time.
The bottom line
Passwords and MFA have played an important role in protecting Microsoft 365 accounts, but Microsoft believes passkeys are the future.
They're more secure, easier to use, and designed for the way modern businesses work.
For Microsoft 365 organisations, getting ahead of the change now means a smoother transition, happier employees and stronger protection against today's cyber threats.
Want to understand what passkeys mean for your business?
The Resolve team can help you review your Microsoft 365 security, prepare for password-less sign-ins and create a smooth migration plan for your users. Call us on 0114 2134 555 or email us on solutions@resolve.co.uk