
Passwords are the weak point in most businesses. People reuse them, write them on sticky notes, and type them into convincing fake login pages without a second thought. Passkeys are the technology built to fix exactly that — and for most Australian businesses, it’s worth starting the rollout now.
What Is a Passkey?
A passkey replaces your password with your device’s own security. Instead of typing something in, you prove it’s you the same way you unlock your phone — a fingerprint, face scan, or PIN.
When you set up a passkey for a website or app, your device creates two matching keys. The private key stays locked on your device and never leaves it. The public key is stored by the website. When you sign in, the site sends a challenge that only your private key can answer. Your device confirms with your fingerprint or PIN, and you’re in — no password typed, no password stored.
This approach is built on a standard called FIDO, which Apple, Google, and Microsoft all support.
Why Passkeys Are Harder to Attack
A password is a secret you share with a website every time you log in — and that’s exactly what attackers target. A passkey has no shared secret, and that one difference solves most of the problem.
They Can’t Be Phished
A passkey only works on the real website it was created for. Land on a convincing fake, and the passkey simply won’t work. Given that phishing is how most breaches begin, this matters enormously — and aligns with what the ACSC recommends under the Essential Eight’s multi-factor authentication controls.
Nothing to Steal in a Breach
The website only holds your public key, which is useless without your device. If a company gets hacked, there’s no password list to grab and test against your other accounts.
Nothing to Reuse or Forget
Each passkey is unique to one site and generated automatically. Weak and reused passwords stop being a risk.
Where You Can Use Passkeys Today
Support has grown quickly. You can already use passkeys with Microsoft, Google, and Apple accounts, along with a growing number of banks, password managers, and business tools. Apple, Google, and Microsoft have all built passkey support into their phones, laptops, and browsers.
There are two types worth knowing:
- Synced passkeys are backed up to your Apple, Google, or Microsoft account, so they work across all your devices and survive a lost phone.
- Device-bound passkeys stay on a single physical device — the most locked-down option, and a common choice for sensitive or privileged accounts.
Should Your Business Use Them?
For most businesses, yes. And you don’t need to switch everything overnight.
If you’re running Microsoft 365, passkeys are already available through Microsoft Entra at no extra cost. Staff can sign in using a passkey stored in Microsoft Authenticator, a physical security key, or their own device. It also meets the intent of MFA requirements under the Privacy Act and Notifiable Data Breaches scheme — a passkey covers two authentication factors in a single step.
Microsoft notes that passkey sign-in takes around three seconds, compared to roughly 69 seconds for a password plus a traditional MFA code. Across a whole team, that adds up fast.
A Practical Starting Point
- Enable passkeys for your most sensitive accounts first — administrators, finance staff, and anyone with access to critical systems.
- Let others add a passkey alongside their existing login so the transition is gradual and low-risk.
- Set up a backup for everyone — a second device or security key — so a lost phone doesn’t mean a lockout.
A Few Things to Plan For
Passkeys aren’t a set-and-forget fix. A couple of things are worth thinking through:
- Account recovery — if someone loses their only device with no backup, they can get locked out. Synced passkeys or a second registered device prevent this, but need to be set up in advance.
- Legacy systems — some older platforms still rely on passwords, so you’ll run both side by side for a while.
- Shared devices or accounts — passkeys are tied to a person and their device, so shared logins need a separate plan.
Ready to Make the Switch?
Passkeys are one of the most effective steps you can take to reduce credential-based risk — and with Microsoft Entra already included in M365, the infrastructure is likely already there.
If you’d like help planning a rollout that keeps your team productive and nobody locked out, get in touch with The IT TechNinjas or learn more about our Safe to Scale programme.
