How businesses can better protect their accounts from phishing 

Passwords are still ubiquitous in businesses. At the same time, stolen or misused login credentials remain among the most common entry points for cyberattacks. The latest Verizon Data Breach Investigations Report 2026 shows that, across phishing, stolen login credentials and so-called pretexting, compromised identities are still involved in around 39 per cent of all data breaches. Against this backdrop, passwordless authentication methods such as FIDO2 are coming to the fore. They promise a new level of security, user-friendliness and scalability for modern businesses.

In an increasingly digital business world, passwords have become a risk. They are difficult to manage, easy to steal and often the cause of serious security incidents. Particularly in organisations that handle sensitive customer data and business-critical systems on a daily basis, a compromised password can have serious consequences. The need for a secure, user-friendly and scalable authentication solution is greater than ever.

FIDO2 and passkeys offer a modern alternative. Employees can log in, for example, using facial recognition, a fingerprint or a device PIN, without having to enter a password. For accounts requiring a particularly high level of protection, physical security keys can also be used. Passwordless authentication thus becomes not only more secure, but also simpler. However, this requires a well-planned implementation that is tailored to the existing IT landscape and the various user groups within the organisation.

What are FIDO2 and passkeys? 

FIDO2 is an open authentication standard developed by the FIDO Alliance (Fast Identity Online), an international industry consortium with members including Google, Microsoft and Apple. The aim of this alliance is to phase out passwords in the long term and replace them with secure, user-friendly authentication based on cryptographic keys. FIDO2 is based on WebAuthn, a standard from the World Wide Web Consortium, and the Client to Authenticator Protocol (CTAP). WebAuthn enables the use of cryptographic credentials in browsers and applications, whilst CTAP governs communication with the authenticator being used – such as a laptop, smartphone or physical security key.

Passkeys are the most common implementation of this principle today. Instead of a password, a cryptographic key pair is used: the public key is stored with the relevant service, whilst the private key remains securely stored on the device or authenticator and is never transmitted during login. The passkey is authorised using the same method used to unlock the device – facial recognition, fingerprint or device PIN. Biometrics therefore does not directly replace the password, but rather confirms locally that the authorised person is permitted to use the cryptographic key. Biometric data never leaves the device.

How does passwordless login work? 

When setting up a passkey, the device generates a unique key pair. The private key remains on the device, whilst the public key is stored with the corporate service. When logging in, the service sends a request to the device; the user confirms this via fingerprint, facial recognition or PIN, and the device signs the request with the private key.

The key factor is the link to the specific application or domain: A passkey for Microsoft 365 will not work on a fake login page with a similar-looking address. This makes passkeys significantly more resilient to traditional phishing attacks than passwords or transferable one-time codes.

ARE PHYSICAL FIDO2 SECURITY KEYS STILL NEEDED?

For most employees, an additional USB or NFC key is no longer strictly necessary. On modern, centrally managed devices, the passkey can be stored directly on a laptop or smartphone – for example, via Windows Hello for Business or passkeys in Microsoft Authenticator. Physical security keys are still useful, however:

  • Privileged accounts: Administrators and other accounts requiring special protection.
  • Emergency access: As a backup in case the primary device is lost or fails.
  • Shared workstations: For example, in shift work or at reception.
  • No device: Employees without a permanently assigned, suitable smartphone or laptop.

The physical key is therefore not the standard solution for all staff, but one of several options. Which option is used should depend on the security requirements, the user group and the existing device environment.

DEVICE-BOUND OR SYNCHRONISED PASSKEYS?

With device-bound passkeys, the private key remains on a specific device (e.g. in the laptop’s security chip) or a physical security key, from which it cannot be copied. This option offers a high level of control and is particularly suitable for managed work devices and privileged accounts.

Synchronised passkeys, on the other hand, are available across multiple devices via a supported provider (e.g. iCloud Keychain, Google Password Manager or an enterprise password manager). This enhances user-friendliness and simplifies switching between devices, but requires an assessment of the synchronisation and recovery processes used. Organisations must also ensure, via policy (MDM), that business passkeys do not end up in employees’ private cloud accounts.

Microsoft Entra ID supports both options and will make passkeys the default sign-in method from September 2026, gradually phasing out SMS and phone calls as multi-factor authentication methods. Microsoft recommends device-bound passkeys (e.g. FIDO2 security keys, passkeys in Microsoft Authenticator) for administrators and privileged roles, and synchronised passkeys for the rest of the workforce.

Greater security and less effort 

The most significant security benefit lies in protection against phishing and the misuse of stolen login details: without a reusable password, there is no password that can be entered on a fake website or used for other services following a data breach.

At the same time, logging in becomes simpler: there is no longer any need to create, remember or reset complex passwords. This also reduces the workload on support teams, as password resets are among the most common enquiries received by the service desk. However, this gives rise to new processes relating to device registration, device changes and the recovery of lost access details – these must be taken into account from the outset.

Fido2 as part of a zero-trust strategy 

Strong authentication is a key component of modern zero-trust architectures: every access attempt must be verifiably linked to a uniquely confirmed identity. FIDO2 provides better protection against phishing and credential theft during the login process.

However, a successful login alone is not enough. Organisations must also verify which device is being used to access the system, what its security status is, and which applications or data the user is authorised to access. FIDO2 therefore does not replace authorisation management, endpoint protection or the monitoring of suspicious activity, but rather strengthens a key part of the security architecture.

How to ensure a successful launch 

A successful implementation begins with an analysis of the existing environment: Which identity platform, devices, operating systems and line-of-business applications are in use, and which of these support FIDO2 or passkeys? 

Suitable user groups and areas of application are then defined. It is often advisable to start by securing privileged accounts or applications requiring particular protection, and then to expand the solution step by step.

The recovery process is particularly important: If a device is lost, it must be possible to set up new access quickly without creating an easier attack vector. Identity verification by support staff, the handling of replacement devices and the blocking of lost authenticators must therefore be clearly regulated – as must the controlled use of weaker fallback methods. Last but not least, clear communication is essential: staff should know why the login process is changing, how it works and what to do if a device is lost.

WHERE ARE THE LIMITS?

FIDO2 and passkeys offer a very high level of protection against traditional phishing attacks and the reuse of stolen passwords. However, this does not make a company invulnerable: a compromised end device, a stolen active session, incorrectly granted permissions or exploited software vulnerabilities remain areas of risk in their own right – according to the latest DBIR, the latter are in fact the most common point of entry. Social engineering targeting the service desk and insecure recovery processes also remain potential points of attack.

When implemented correctly, however, FIDO2 significantly reduces a particularly frequently exploited risk and is therefore an important, but not the sole, component of IT security.
 

MTF: Your partner for modern authentication 

The introduction of passkeys affects not only the login process itself, but also the management of identities and endpoints, the security of privileged accounts, and clear support and recovery processes. MTF supports organisations in analysing their existing environment and developing a suitable strategy for passwordless authentication – from the integration of FIDO2 and Windows Hello for Business, through the configuration of Microsoft Entra ID and Intune, to the selection of appropriate authenticators for different user groups.

Contact us and play an active part in shaping the path to a passwordless future.

FAQs 

  1. How secure are passkeys compared to passwords? 
    Passkeys offer significantly better protection against traditional phishing attacks, as no reusable passwords or login codes are transmitted. The private key remains on the device and is tied to the respective service.
     
  2. Does every employee need a physical security key? 
    No. On modern devices, a passkey can be stored directly and authorised via biometrics or a device PIN. Physical keys are particularly suitable for privileged accounts, critical systems and emergency access.
     
  3. What happens if a device is lost? 
    The stored passkey or authenticator must be removed or blocked in the identity system. A new device is then registered via a predefined and tested recovery process.
     
  4. Can passkeys be used on multiple devices? 
    Synchronised passkeys can be available on multiple devices. Device-bound passkeys, on the other hand, remain stored on a specific device or security key. Which option is permitted depends on the organisation’s security requirements and policies.
     
  5. Is fingerprint authentication automatically FIDO2? 
    No. The fingerprint initially only verifies identity locally. During a FIDO2 login, it releases the cryptographic passkey; biometric data is not transmitted to the application in the process.
     
  6. Is FIDO2 compatible with Microsoft 365? 
    Yes. Microsoft Entra ID and Microsoft 365 support various FIDO2-based sign-in methods, including passkeys, Windows Hello for Business and physical security keys. The exact level of support may vary depending on the operating system, application and client.
     
  7. Is FIDO2 compliant with data protection regulations? 
    FIDO2 is designed to be privacy-friendly, as private keys and biometric data remain on the device. Whether a specific implementation meets all legal requirements depends on the overall solution, the providers used and the organisational processes.
     
  8. What is the difference between a passkey and a physical FIDO2 security key? 
    Both are based on the same FIDO2 standard. A passkey stores the cryptographic key directly on a laptop or smartphone, whilst a physical security key stores it on an external device. Which option is appropriate depends on the user’s role, device setup and security requirements.

Also interesting 

Do you have Questions ?

Ümit Celebi
Key Account Manager