Every password login works the same way: you hand a secret to a website and hope it ends up in the right hands. Attackers know this, which is why so much crime is built around tricking you into typing that secret somewhere you should not. A passkey removes the secret from the deal entirely.
How a passkey works, in plain terms
When you create a passkey for a site, your phone or laptop makes two matching keys. One stays locked on your device and never leaves it. The other sits with the website. At sign-in, the site sends a puzzle only your key can solve, you approve it with your fingerprint, face or device PIN, and you are in. Nothing gets typed, so there is nothing to intercept, guess or write on a sticky note.
This is an industry standard called FIDO, and Apple, Google and Microsoft have all built it into their phones, laptops and browsers. The device in your pocket can already do this.
Why they are so much harder to attack
A passkey only works on the real website it was created for. Land on a convincing fake and it simply refuses, so the phishing email that would have caught your password has nothing to catch. If the website itself gets breached, the attacker finds only your public key, which is useless on its own. And because every passkey is unique and made automatically, weak and reused passwords stop being your problem.
There is a local angle worth taking seriously. SIM swap fraud is one of the most common attacks in South Africa, and it works by hijacking your phone number so the one-time SMS codes protecting your accounts get delivered to a criminal instead. A passkey does not travel over your phone signal at all. The approval happens on the device in your hand, so a stolen number gets an attacker nowhere. It is the same reasoning behind our banks moving their approvals from SMS into their apps.
This is not a fringe idea any more
The FIDO Alliance's October 2025 Passkey Index found that more than a quarter of all sign-ins now use a passkey, and 93% of accounts are already eligible for one. They are quicker too: Microsoft measures a passkey sign-in at about 3 seconds, against roughly 69 seconds for a password plus a texted code. Multiply that by a team signing in every day and it stops being a rounding error.
What this means for your business
If you are on Microsoft 365, passkeys are already included. Staff can sign in with a passkey held in the Microsoft Authenticator app, a hardware security key, or the device itself. You do not have to switch everything overnight, and you should not: the sensible rollout starts with the accounts that would hurt most, which usually means email and anything with admin rights, then widens from there.
- Start with your main email account and your banking, where a stolen login costs the most
- Move admin accounts off SMS codes first, then the rest of the team
- Keep a fallback method registered, so a lost phone is an inconvenience rather than a lockout
Passkey support sits inside the Microsoft 365 licence you already have. Setting it up properly for a small team is a morning's work, not a project. We include it in our security baseline.