Passkeys for UK SMEs: What They Change for Microsoft 365 Sign-Ins (and What to Do This Quarter)

Passwords are still the most common way people access Microsoft 365. Passkeys are designed to be easier to use and far more resistant to phishing than passwords, we explain what they change for Microsoft 365 sign-ins.

Blog Main Image

Passwords are still the most common way people access Microsoft 365, line-of-business apps and cloud services. Unfortunately, they're also still one of the easiest things for criminals to exploit, not because your team is careless, but because phishing and social engineering have become extremely polished.

Many UK SMEs have already taken an important step by enabling multi-factor authentication (MFA). That's good progress. But there's a catch: not all MFA gives the same level of protection. Attackers have learned how to trick people into approving prompts, steal one-time codes, or bypass weaker sign-in methods.

That's why passkeys are getting so much attention.

Passkeys are designed to be easier for people to use and far more resistant to phishing than passwords. In this article we'll explain what passkeys are, what they change for Microsoft 365 sign-ins, and what a sensible rollout looks like for a small business.

What Is a Passkey (in Plain English)?

A passkey is a modern sign-in method that uses public-key cryptography and a device you already have (such as a phone or laptop) to prove it's really you.

Instead of typing a password, you typically choose your account, then approve the sign-in on a device using Face ID / Touch ID, Windows Hello, or a hardware security key.

Behind the scenes, the "secret" part of the credential stays on the device. That's a big shift from passwords, which can be typed into a fake website or reused across services.

The UK National Cyber Security Centre (NCSC) has published guidance explaining passkeys and how they help reduce password-related risk.

Why Passkeys Matter to UK SMEs

Most successful attacks against small businesses are not Hollywood-style technical hacks. They're "low effort, high reward" approaches: phishing emails that lead to fake sign-in pages, credential stuffing (reusing leaked passwords), and attacks that target an owner or manager account, then move into finance.

If an attacker can get a Microsoft 365 sign-in, the business impact can be immediate: access to email threads and invoices (payment redirection fraud), access to SharePoint/OneDrive documents (data loss and extortion), access to Teams messages (internal impersonation), and a stepping stone into other systems via password reuse.

Passkeys help because they are much harder to steal and replay via phishing. Even if a staff member clicks a convincing link, a passkey sign-in won't "hand over" a reusable password.

"We Already Have MFA, Aren't We Covered?"

MFA is still one of the best improvements you can make. But it's important to understand that some MFA methods are easier for criminals to defeat than others.

For example, attackers may pressure someone into approving repeated push prompts (prompt fatigue), capture one-time codes via a fake login page, or use man-in-the-middle phishing tools to relay credentials and MFA in real time.

This is why security guidance increasingly recommends phishing-resistant authentication for higher-impact accounts. Passkeys are one route to that stronger protection.

Where Passkeys Fit in Microsoft 365 / Entra ID

In Microsoft environments, identity is typically managed through Microsoft Entra ID (formerly Azure AD). Your Microsoft 365 sign-ins, Conditional Access rules and authentication methods sit here.

Microsoft has been expanding passkey support in Entra ID, including synced passkeys and passkey management via authentication policies.

In practical terms, this means many organisations can begin planning for passkeys as part of their sign-in strategy rather than treating them as a consumer-only feature.

The key point for SMEs: passkeys are not a "flip a switch and forget it" change. They sit alongside other controls like Conditional Access, device compliance and admin role protection.

What to Do First: Start With Your Highest-Impact Accounts

A sensible approach is to tier your accounts by business impact.

Start with business owners/directors, finance (anyone who can approve payments or manage supplier details), Microsoft 365 / Entra admins, and anyone with access to sensitive personal data.

These accounts are the ones most likely to be targeted and the ones where a compromise causes the biggest damage. For these accounts, your goal is to reduce phishing risk, reduce the chance of "weak recovery" being used to take over the account, and reduce the blast radius if something still goes wrong.

Build a Rollout Plan Your Team Can Actually Follow

Passkeys fail in the real world when they're introduced as a technical change without considering day-to-day work.

A practical rollout plan includes:

1) Decide which sign-in methods you will allow. Different organisations choose different combinations depending on risk and reality. The key is to avoid a situation where strong methods exist but weaker methods remain available for the same accounts.

2) Pilot with a small group. Pick 5-10 people across roles and devices. Make sure you cover iPhone and Android, Windows laptops (with Windows Hello), and any shared or kiosk devices.

3) Document "what happens if I lose my phone?" Account recovery is often where good security falls apart. If recovery is too easy, attackers will aim for it. If it's too hard, staff will avoid the new method. Write a one-page internal process covering who to contact, what checks are done before recovery is approved, and how quickly it will be handled.

4) Include leavers and role changes. When someone leaves, access needs to be removed quickly and predictably. Your joiner/mover/leaver process should cover disabling the account and sessions, removing admin roles, checking mailbox rules and forwarding, and validating that finance approval workflows are intact.

Don't Stop at Authentication: Add Guardrails With Conditional Access

Even strong authentication benefits from good access rules.

For Microsoft 365, Conditional Access can help you block sign-ins from countries your business doesn't operate in, require compliant devices for certain apps, enforce stronger methods for admin portals, and reduce risk from "impossible travel" and suspicious logins.

This is how you turn "good sign-in" into "good sign-in in the right context".

Backups and Recovery Still Matter (Even With Better Logins)

Improving sign-ins reduces the chance of compromise, but it doesn't eliminate it.

If ransomware or a major incident hits, you still need to restore data quickly and safely. The ICO highlights the importance of disaster recovery, business continuity, and testing your control environment, including backups, in the context of ransomware preparedness.

For many SMEs, the most valuable "insurance" is knowing what is backed up (and what isn't), having at least one backup that cannot be altered by an attacker, and regularly testing restores, not just checking that a job ran.

A Simple Next-Step Checklist for This Quarter

If you want a low-drama, high-impact plan, start here:

  • List your high-impact accounts (owner, finance, admins)
  • Review your current MFA methods and remove weaker options where appropriate
  • Pilot passkeys with a small group and capture the support issues early
  • Review Conditional Access to block obviously risky sign-ins
  • Write account recovery and leaver steps so it's not made up during an incident
  • Test a restore from your backups (pick one system and actually restore it)

How Managed Technology Group Can Help

Managed Technology Group helps UK SMEs build security that fits how people actually work: pragmatic, well-documented, and supportable.

If you're considering passkeys, we can review your Microsoft 365/Entra sign-in setup, recommend a practical authentication baseline, tighten Conditional Access without slowing your team down, and improve recovery processes so a lost phone doesn't become a crisis.

It's all part of our approach: Your Technology, Managed the Right Way.

If you'd like, we can run a short workshop to map your current sign-in methods and agree the safest "next quarter" plan for your business.

Ready to Work With an IT Company That Actually Gives a Damn?

Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.

IT Review Consultation