What Are Passkeys (vs. Passwords), and Should Your Business Use Them?
- Jul 16
- 5 min read

Have you noticed more websites asking whether you'd like to "sign in with a passkey"? Well, you’re not alone and will continue to see this pop up because Apple, Google and Microsoft are all moving toward passwordless authentication. The primary reason is because traditional passwords have become one of the weakest links in cybersecurity. They're often reused, easily forgotten and remain a common target for phishing attacks and data breaches. So, does that mean passwords are going away? Not quite—but passkeys are quickly becoming a smarter, more secure way to sign in.
So, What Exactly is a Passkey?
Think of a passkey as a replacement for a password. Instead of remembering and typing a password, you verify your identity using something you're already familiar with:
Face ID
Fingerprint
Windows Hello
Device PIN
Behind the scenes, your device creates two digital (cryptographic) keys: one stays securely on your device and the other is shared with the website or application. During sign-in, those keys verify your identity without ever sending a reusable password across the internet. That means there's no password for someone to steal in a phishing email or recover from a breached database.
Why Are Passkeys More Secure?
Because there isn't a reusable password to steal, passkeys eliminate many of the risks associated with traditional passwords:
They get reused across multiple accounts.
They're often weak or predictable.
They can be stolen through phishing emails.
They may be exposed in third-party data breaches.
Employees frequently forget them, resulting in password reset requests.
Unlike traditional passwords, passkeys are tied to the specific website or application where they were created. If someone accidentally visits a fake website, the passkey simply won't work. For businesses, that adds another layer of protection against one of the most common ways attackers attempt to gain unauthorized access.
Are Passkeys Better Than Multi-Factor Authentication?
Not exactly. In many cases, passkeys can be multi-factor authentication. When you sign in with a passkey, you're typically using:
Something you have: your trusted device
Something you are: your fingerprint or face, or something you know: your device PIN
This creates a strong authentication experience without requiring users to enter a password and then approve a second authentication prompt.
What Are the Downsides to Using Passkeys?
Rather than applying isolated fixes, Focus IT developed a phased modernization strategy designed to address the firm's immediate challenges while creating a scalable foundation for future growth. The engagement focused on four key areas:
Not Every Application Supports Them Yet: Adoption is growing quickly, but many legacy business applications still rely on passwords, so most organizations will transition gradually.
Device Management Becomes More Important: Because passkeys are tied to trusted devices, organizations need a clear process for replacing lost phones, stolen laptops, damaged devices and employee departures. Strong recovery procedures are just as important as strong authentication.
Shared Accounts Become More Challenging: Passkeys reinforce a best practice many organizations should already be following: each employee should have (and use only) their own account. Shared logins make it difficult to know who accessed what, which can complicate offboarding and weaken accountability.proactive support to ensure systems continued to align with business needs as the firm evolved.
Where Should Passkeys Be Stored?
For businesses, company-managed credential storage is generally preferable to relying on employees' personal accounts. Passkeys can be stored in several different ecosystems, including:
Apple iCloud Keychain
Google Password Manager
Microsoft Authenticator
Business password managers such as 1Password
Organizations should establish clear standards so work credentials aren't scattered across unmanaged personal devices.
Building a Long-Term Passkey Strategy
A bigger question isn't simply whether to use passkeys, it's how to manage them over the long term. For most organizations, we recommend:
Use a Central Identity Provider: Whether it's Microsoft Entra ID, Google Workspace or another identity platform, your identity provider should remain the central source of authentication and access management.
Use Company-Managed Devices: Whenever possible, employees should use managed laptops and mobile devices that IT can secure, monitor and recover if they're lost or replaced.
Have Backup Authentication Methods: Don't rely on a single passkey. Employees should have an approved recovery option, such as:
A second enrolled device
Microsoft Authenticator
A FIDO2 security key
An established identity verification process
Documentation and Recovery Procedures are Key: Consider what happens when an employee loses a phone, replaces a laptop or leaves the company. Planning for those situations ahead of time minimizes downtime while keeping your environment secure.
Should Companies Continue Using a Password Manager?
Even as companies adopt passkeys, password managers still play an important role for applications and credentials that haven't yet moved to passwordless authentication. Business password managers remain valuable for:
Legacy applications
Service accounts
API keys
Software licenses
Secure business notes
Should Your Business Switch to Passkeys?
For many organizations the answer is probably yes, but that doesn't mean replacing every password tomorrow. The best approach is to introduce passkeys where they're supported while following a thoughtful rollout plan. Like any security initiative, the technology is only one part of the solution. How you implement and manage it is what ultimately determines its success.
From an employee perspective, over time most people will likely appreciate using passkeys because they no longer have to remember complex passwords or respond to repeated authentication prompts. Signing in with Face ID, Windows Hello or a fingerprint is typically faster and easier, which improves both security and the user experience. When security is easier, employees are more likely to use it consistently.
Cybersecurity Training is Still Important
Passkeys dramatically reduce phishing risk, but they don't eliminate cybercrime. Employees still need to recognize the potential for business email compromise, invoice fraud, social engineering (phishing, vishing, etc.), QR code scams and other attacks that don't rely on stolen passwords. Security awareness remains an essential part of any cybersecurity program.
Focus IT’s Recommendation
Passkeys are one of the most significant improvements to business authentication in years. They make signing in faster, reduce password fatigue and significantly improve protection against phishing and credential theft. That said, they’re not a silver bullet and strong cybersecurity still depends on the core fundamentals:
Managed devices
Identity governance
Access controls
User awareness training
Thoughtful IT planning
The goal isn't simply to eliminate passwords, it's to build an authentication strategy that's secure, practical and sustainable as your business grows.
Ready to discuss implementing passkeys? Schedule your free consultation today.
Focus IT, a trusted provider of cybersecurity awareness training and managed IT services for professional services firms in New York City, announces the expansion of its comprehensive employee cybersecurity training program. As law firms, financial services companies, architecture practices and other professional services organizations in NYC face unprecedented cyber threats in 2025, Focus IT's training program is designed to educate entire teams across industries. This empowers them with the knowledge necessary to recognize and prevent sophisticated AI-powered attacks.




