MFA Isn’t the End Game: Why Businesses Need to Start Thinking About Passkeys
Are passkeys replacing MFA? What UK businesses need to know
MFA still matters, but attackers have adapted. Passkeys offer a phishing-resistant route to stronger authentication, with less friction for users and a different set of rollout decisions for businesses.
For years, multi-factor authentication has been the sensible answer to a fairly obvious problem: passwords aren’t enough.
Don’t get me wrong, that advice hasn’t suddenly become outdated, and if your business is still protecting important accounts with a password alone, MFA remains one of the most useful improvements you can make today.
But here comes the awkward second part to the MFA story... Attackers have adapted.
For as long as there’s been passwords, there’s been the ability to steal them. But now, one-time codes can be intercepted or relayed through convincing fake sign-in pages, and push notifications can be abused until a tired or distracted user taps “approve” simply to make them stop, making that extra step feel less like the finish line we once treated it as.
That’s why passkeys are moving from a consumer convenience into a serious business security conversation.
The NCSC has changed the direction of travel
You may recall that back in April this year, the National Cyber Security Centre announced that it would begin recommending passkeys wherever a service supports them, with traditional two-step verification remaining the fallback where they don’t. Read the NCSC’s passkey guidance.
It didn’t, and still doesn’t, mean organisations should switch off existing MFA tomorrow morning; it simply means the definition of strong authentication is moving to the point where you should be asking, “Are the authentication methods we use actually resistant to phishing?”
What is a passkey?
A passkey is a passwordless sign-in credential based on public-key cryptography. Instead of typing a secret that can be copied, you approve the sign-in using the device you already have, usually with a fingerprint, face scan or device PIN.
Behind the scenes, the service holds a public key. Your private key stays protected by your device or credential manager, and the two work together to prove you’re you, but the private key isn’t handed over during sign-in.
Crucially, the credential is tied to the genuine website or application. A convincing fake Microsoft 365 page may look right to a person, but it doesn’t have the right digital identity for the passkey to work, which is what makes passkeys phishing-resistant.
Does a passkey count as MFA?
It can. When a passkey requires user verification, it combines something you have, the cryptographic key on your device, with something you know or are, such as a device PIN, fingerprint or face scan.
In other words, the user may see a single smooth action, but the authentication can still involve multiple factors. Security doesn’t have to become more irritating to become stronger, which is quite a welcome change.
Why traditional MFA can still be phished
Most people imagine phishing as a fake page collecting a username and password, or a dodgy-looking email from ‘Micr0soft’, but modern phishing kits can go further, and be incredibly sophisticated. They can sit between the user and the real service, relaying credentials and one-time codes in real time, and push-based MFA can also be weakened by social engineering or repeated approval requests.
So, is every form of traditional MFA useless? No, not quite. An authenticator app is generally a better option than SMS, and any MFA is usually better than a password alone. But passwords, codes and approvals are things a person can still be persuaded to disclose or accept.
A passkey changes the game and tips the scales back in your favour, as there’s no reusable password to steal, and no six-digit code to type into the wrong page. The authentication is bound to the legitimate service, so the attacker can’t collect it in one place and replay it elsewhere.
Security isn’t the only business case
For a UK SME, the strongest security control isn’t much use if it creates a queue at the service desk, or if it can be quietly bypassed. Passkeys matter because they can improve security while reducing friction, i.e., your staff don’t need to remember another password, reach for a code or respond to an unexplained prompt.
Signing in can feel much more like you’re unlocking a phone or laptop, which means fewer password resets, fewer lockouts, and less time lost to authentication admin.
There’s also a governance benefit tied in, with identity sitting at the centre of Microsoft 365, cloud platforms, line-of-business applications, and remote access. Moving towards phishing-resistant authentication gives organisations a clearer way to reduce credential risk across that environment, rather than asking users to become perfect at spotting increasingly convincing sign-in pages.
Passkeys aren’t a magic wand
Passkeys solve an important problem, but they don’t solve every security problem, and a compromised or poorly managed device will always pose a risk. Session tokens can still be targeted after a legitimate sign-in, as not every legacy application supports modern authentication. Equally, joiners, movers and leavers still need proper identity processes, and recovery still needs to be designed carefully, especially when a device is lost or replaced.
There’s also a choice to make between synced passkeys, which can follow a user across devices through a credential manager, and device-bound credentials or physical FIDO2 security keys. Synced passkeys can be practical for many everyday users. Device-bound methods may suit administrators, executives and regulated roles that need tighter assurance.
The right answer does depend on a whole host of factors, including your systems, risk profile, device ownership model and compliance obligations. Buying a box of security keys before working any of that out? Well, that’s a good way to create an expensive drawer full of security keys.
What should businesses do now?
This should be treated as a managed transition, not a password bonfire. A sensible starting point looks like this:
Map where authentication matters most
Start with Microsoft 365 or Google Workspace, remote access, finance systems, privileged admin portals and any service holding sensitive client or employee data. Record which applications support passkeys or other phishing-resistant methods, and which still depend on passwords and one-time codes.
Check identity and device readiness
Review supported operating systems, managed and unmanaged devices, browsers, identity platforms and conditional access policies. Passkeys work best when device management, patching and identity governance are already being looked after.
Choose the right credential for each group
The lowest-risk office user and a global administrator don’t necessarily need the same setup. Consider synced passkeys for supported mainstream use cases, with device-bound credentials or FIDO2 security keys for privileged and higher-assurance roles.
Design recovery before rollout
Ask what happens when someone loses a phone, replaces a laptop or can’t access their usual credential manager. Recovery shouldn’t fall back to a weak helpdesk conversation. Define identity checks, backup methods, revocation and emergency access before users enrol.
Pilot with real users and real workflows
Test across different roles, devices, locations and accessibility needs. Include the awkward cases: shared workstations, contractors, travel, replacement devices and older applications. A technically successful sign-in isn’t the same as an operationally successful rollout.
Keep existing MFA while you close the gaps
Traditional MFA remains a valuable fallback for services that don’t yet support passkeys. The aim is to reduce reliance on phishable methods over time, not to remove a working control before its replacement is ready.
Three passkey questions business leaders are likely to ask
Are passkeys more secure than passwords and MFA codes?
Will passkeys work with Microsoft 365?
Should we replace MFA with passkeys now?
The end game is stronger identity, not another acronym
MFA was never meant to be a badge you earned once and forgot about. It was a response to the weaknesses of passwords. Passkeys are the next response to the weaknesses attackers have learned to exploit in traditional MFA.
For many UK SMEs and mid-market organisations, this isn’t yet a project that can be completed in a week. It’s a direction to start planning for now, so review what your identity platform already supports, understand where passwords and phishable MFA still protect critical access, and put recovery, devices and user experience into the same conversation as security.
The goal here is to make that proof much harder for someone else to steal.
Move towards phishing-resistant access without creating a rollout headache
Fifosys can help you assess authentication risk, identity-platform readiness and a phased route towards phishing-resistant access that fits the way your business actually works.
Talk to our team
Review your current authentication setup, priority identities and the practical steps towards stronger access.
Cyber Security
See how identity, endpoint, email and cloud security fit into a layered security approach.
