CIO Brief: Passkeys Make Phishing-Resistant MFA Affordable
Retrospective: this article looks back at events from May 2024, written in 2026 with the benefit of hindsight.
The short version: Since 2024, Microsoft lets employees use passkeys on their phones to sign in — the strongest common form of authentication, and immune to phishing. It used to require buying security keys for every user. Now it doesn't.
Why this changes the economics
Phishing-resistant authentication was previously reserved for administrators because of the cost and logistics of hardware keys. Passkeys in the Microsoft Authenticator app use phones employees already carry. The main costs are rollout effort and support.
The business impact
- Stops credential phishing, including the kits that bypass traditional MFA.
- Faster sign-in with face or fingerprint.
- Fewer password resets and help desk calls.
- Insurance and compliance expectations increasingly met.
Questions to ask your team
- What percentage of our employees use phishing-resistant sign-in today?
- What would it take to roll out passkeys to everyone?
- How would we handle employees without smartphones or who won't use personal devices?
- What's our process for lost phones?
What good looks like
Passkeys or other phishing-resistant methods for all administrators now, for high-risk roles within a quarter, and for everyone within a year — with a secure recovery process.
The decision
Set a target: a specific percentage of employees using phishing-resistant sign-in by year-end. It's one of the most effective security metrics you can track.
- Passkeys in Microsoft Authenticator Preview (May 2024): Phishing-Resistant MFA for Everyone Platform Changes
- How to Roll Out Device-Bound Passkeys in Entra ID How-To & Hardening
- Passkey Rollout Checklist: Registration, Recovery and Help Desk How-To & Hardening