MFA Isn’t the End Game: Why Businesses Need to Start Thinking About Passkeys

Are passkeys replacing MFA? What UK businesses need to know

MFA still matters, but attackers have adapted. Passkeys offer a phishing-resistant route to stronger authentication, with less friction for users and a different set of rollout decisions for businesses.

Written by Jordan StewartCyber security and identity
Passkeys and phishing-resistant authentication for UK businesses

For years, multi-factor authentication has been the sensible answer to a fairly obvious problem: passwords aren’t enough.

Don’t get me wrong, that advice hasn’t suddenly become outdated, and if your business is still protecting important accounts with a password alone, MFA remains one of the most useful improvements you can make today.

But here comes the awkward second part to the MFA story... Attackers have adapted.

For as long as there’s been passwords, there’s been the ability to steal them. But now, one-time codes can be intercepted or relayed through convincing fake sign-in pages, and push notifications can be abused until a tired or distracted user taps “approve” simply to make them stop, making that extra step feel less like the finish line we once treated it as.

That’s why passkeys are moving from a consumer convenience into a serious business security conversation.

The NCSC has changed the direction of travel

You may recall that back in April this year, the National Cyber Security Centre announced that it would begin recommending passkeys wherever a service supports them, with traditional two-step verification remaining the fallback where they don’t. Read the NCSC’s passkey guidance.

It didn’t, and still doesn’t, mean organisations should switch off existing MFA tomorrow morning; it simply means the definition of strong authentication is moving to the point where you should be asking, “Are the authentication methods we use actually resistant to phishing?”

What is a passkey?

A passkey is a passwordless sign-in credential based on public-key cryptography. Instead of typing a secret that can be copied, you approve the sign-in using the device you already have, usually with a fingerprint, face scan or device PIN.

Behind the scenes, the service holds a public key. Your private key stays protected by your device or credential manager, and the two work together to prove you’re you, but the private key isn’t handed over during sign-in.

Crucially, the credential is tied to the genuine website or application. A convincing fake Microsoft 365 page may look right to a person, but it doesn’t have the right digital identity for the passkey to work, which is what makes passkeys phishing-resistant.

Does a passkey count as MFA?

It can. When a passkey requires user verification, it combines something you have, the cryptographic key on your device, with something you know or are, such as a device PIN, fingerprint or face scan.

In other words, the user may see a single smooth action, but the authentication can still involve multiple factors. Security doesn’t have to become more irritating to become stronger, which is quite a welcome change.

Why traditional MFA can still be phished

Most people imagine phishing as a fake page collecting a username and password, or a dodgy-looking email from ‘Micr0soft’, but modern phishing kits can go further, and be incredibly sophisticated. They can sit between the user and the real service, relaying credentials and one-time codes in real time, and push-based MFA can also be weakened by social engineering or repeated approval requests.

So, is every form of traditional MFA useless? No, not quite. An authenticator app is generally a better option than SMS, and any MFA is usually better than a password alone. But passwords, codes and approvals are things a person can still be persuaded to disclose or accept.

A passkey changes the game and tips the scales back in your favour, as there’s no reusable password to steal, and no six-digit code to type into the wrong page. The authentication is bound to the legitimate service, so the attacker can’t collect it in one place and replay it elsewhere.

Security isn’t the only business case

For a UK SME, the strongest security control isn’t much use if it creates a queue at the service desk, or if it can be quietly bypassed. Passkeys matter because they can improve security while reducing friction, i.e., your staff don’t need to remember another password, reach for a code or respond to an unexplained prompt.

Signing in can feel much more like you’re unlocking a phone or laptop, which means fewer password resets, fewer lockouts, and less time lost to authentication admin.

There’s also a governance benefit tied in, with identity sitting at the centre of Microsoft 365, cloud platforms, line-of-business applications, and remote access. Moving towards phishing-resistant authentication gives organisations a clearer way to reduce credential risk across that environment, rather than asking users to become perfect at spotting increasingly convincing sign-in pages.

Passkeys aren’t a magic wand

Passkeys solve an important problem, but they don’t solve every security problem, and a compromised or poorly managed device will always pose a risk. Session tokens can still be targeted after a legitimate sign-in, as not every legacy application supports modern authentication. Equally, joiners, movers and leavers still need proper identity processes, and recovery still needs to be designed carefully, especially when a device is lost or replaced.

There’s also a choice to make between synced passkeys, which can follow a user across devices through a credential manager, and device-bound credentials or physical FIDO2 security keys. Synced passkeys can be practical for many everyday users. Device-bound methods may suit administrators, executives and regulated roles that need tighter assurance.

The right answer does depend on a whole host of factors, including your systems, risk profile, device ownership model and compliance obligations. Buying a box of security keys before working any of that out? Well, that’s a good way to create an expensive drawer full of security keys.

What should businesses do now?

This should be treated as a managed transition, not a password bonfire. A sensible starting point looks like this:

01

Map where authentication matters most

Start with Microsoft 365 or Google Workspace, remote access, finance systems, privileged admin portals and any service holding sensitive client or employee data. Record which applications support passkeys or other phishing-resistant methods, and which still depend on passwords and one-time codes.

02

Check identity and device readiness

Review supported operating systems, managed and unmanaged devices, browsers, identity platforms and conditional access policies. Passkeys work best when device management, patching and identity governance are already being looked after.

03

Choose the right credential for each group

The lowest-risk office user and a global administrator don’t necessarily need the same setup. Consider synced passkeys for supported mainstream use cases, with device-bound credentials or FIDO2 security keys for privileged and higher-assurance roles.

04

Design recovery before rollout

Ask what happens when someone loses a phone, replaces a laptop or can’t access their usual credential manager. Recovery shouldn’t fall back to a weak helpdesk conversation. Define identity checks, backup methods, revocation and emergency access before users enrol.

05

Pilot with real users and real workflows

Test across different roles, devices, locations and accessibility needs. Include the awkward cases: shared workstations, contractors, travel, replacement devices and older applications. A technically successful sign-in isn’t the same as an operationally successful rollout.

06

Keep existing MFA while you close the gaps

Traditional MFA remains a valuable fallback for services that don’t yet support passkeys. The aim is to reduce reliance on phishable methods over time, not to remove a working control before its replacement is ready.

Three passkey questions business leaders are likely to ask

Are passkeys more secure than passwords and MFA codes?
Against common credential attacks such as phishing and credential reuse, yes. The NCSC assesses that FIDO2 credentials, including passkeys, are as secure or more secure than traditional MFA methods seen in common use. They still need sensible device security, credential management and recovery.
Will passkeys work with Microsoft 365?
Microsoft Entra ID supports FIDO2 passkeys and other phishing-resistant methods, but the available options and user experience depend on your tenant configuration, devices, operating systems and policies. Rollout should be tested in a controlled group before enforcement.
Should we replace MFA with passkeys now?
Don’t frame it as an overnight replacement. Keep MFA where passkeys aren’t supported, then phase in phishing-resistant methods where they’re practical. Prioritise important identities and well-supported platforms, while building secure onboarding and recovery around them.

The end game is stronger identity, not another acronym

MFA was never meant to be a badge you earned once and forgot about. It was a response to the weaknesses of passwords. Passkeys are the next response to the weaknesses attackers have learned to exploit in traditional MFA.

For many UK SMEs and mid-market organisations, this isn’t yet a project that can be completed in a week. It’s a direction to start planning for now, so review what your identity platform already supports, understand where passwords and phishable MFA still protect critical access, and put recovery, devices and user experience into the same conversation as security.

The goal here is to make that proof much harder for someone else to steal.

Jordan Stewart
Jordan StewartFifosys insights, news and practical technology guidance for UK business leaders.
Planning your next step?

Move towards phishing-resistant access without creating a rollout headache

Fifosys can help you assess authentication risk, identity-platform readiness and a phased route towards phishing-resistant access that fits the way your business actually works.

Previous
Previous

What Changed in AI This Week? Claude Cowork in Chrome, ChatGPT Business Pricing, UK Ads and Cyber AI

Next
Next

What Changed in AI This Week? GPT-5.6, Rogue AI Agents, Claude in Slack and the EU AI Act