Passkeys vs security keys: which does your business actually need?
Most businesses need both, in roughly a ninety-ten split. Passkeys in Microsoft Authenticator, or Windows Hello for Business on managed devices, cover the general workforce: phishing-resistant, already licensed, no hardware to buy. FIDO2 security keys (YubiKey, Token2 and similar) earn their cost for administrators, break-glass accounts, shared-device users and roles with attestation requirements.
What each one is
Both are FIDO2 credentials, and both are phishing-resistant for the same reason: the credential is cryptographically bound to the service it was registered against, so it cannot be relayed to a fake login page. A passkey lives in software backed by a device's own secure hardware, typically in Microsoft Authenticator on a phone or in the Windows Hello container on a PC. A security key is a separate physical token that holds the credential and moves between devices. Microsoft's positioning matches this split: keys for highly regulated or elevated-privilege users, passkeys as the low-cost, low-friction credential for everyone else. See Microsoft's passwordless authentication guidance on Microsoft Learn.
Where passkeys win
Cost and coverage. Registering and using passkeys is included in every Microsoft Entra ID tier, and enforcement via Conditional Access authentication strengths comes with Entra ID P1, which Microsoft 365 Business Premium includes. There is no procurement, no distribution and no lost-token replacement cycle, because staff use the phone or laptop they already carry. With Microsoft making passkeys the Entra ID default from 1 September 2026, they are also the path of least resistance: see the SMS and voice retirement timeline.
Where hardware keys earn their cost
Four cases. Administrators and privileged or break-glass accounts, where attestation and a credential separate from any one device justify the spend. Frontline or shared-device users with no enrolled personal device. The Essential Eight workstation-logon requirement where Windows Hello for Business is not viable, such as genuinely shared PCs. And clients whose contracts mandate attested hardware credentials. Against those benefits sit real overheads: buying and shipping keys, lost-key helpdesk load, and recovery processes. That is why "keys for everyone" is usually the wrong answer for a 10 to 300 seat business.
The recovery question
Recovery, not registration, is the hard part of any passkey rollout. Device-bound passkeys do not sync, so a lost or replaced phone means re-registration; synced passkeys are easier to recover but cannot be attested, which some Defence-industry clients will not accept. Decide device-bound versus synced deliberately per business, stand up a Temporary Access Pass process for the helpdesk, enable Microsoft Entra self-service account recovery, and keep a small pool of spare security keys per site.
How Blue Arc IT Solutions helps
We design the split for each client (passkeys for the many, keys for the few), handle enforcement policy, and build the recovery runbooks before anyone loses a phone. Start at the passkeys for Microsoft 365 businesses hub, see the compliance detail in do passkeys meet Essential Eight ML2, or get in touch.
Last reviewed: 20 July 2026. Microsoft ships passkey platform changes monthly; check the Microsoft Learn link above for current behaviour before deployment.
Frequently asked questions
Are passkeys as secure as a YubiKey?
Both are phishing-resistant: the credential is bound to the service it was registered against and cannot be relayed to a fake login page. Hardware keys add attestation (cryptographic proof of the exact hardware holding the credential) and portability across devices, which matters for privileged accounts and some regulated environments, but for everyday users a device-bound passkey delivers the same phishing resistance at no hardware cost.
Do we need to buy security keys for every staff member?
No. Passkeys in Microsoft Authenticator and Windows Hello for Business cover the general workforce with hardware they already have. Keys are usually reserved for administrators, break-glass accounts, shared-device or frontline users without an enrolled personal device, and roles under attestation requirements.
What happens when someone loses their phone?
A device-bound passkey does not sync, so a lost or replaced phone means registering a new one. Plan for it: a helpdesk process issuing a Temporary Access Pass, Microsoft Entra self-service account recovery, and ideally a second registered method. A small pool of spare security keys per site is cheap insurance.