Passkeys vs Passwords and SMS Codes: What Changes for Your Users

Passkeys compared with passwords and SMS codes by phishing resistance

Short answer: a passkey replaces the password and the SMS code with a cryptographic key pair. The private key stays on the user’s device or in their credential manager and is unlocked with a fingerprint, face or PIN; Microsoft Entra ID only stores the public key. A passkey only answers the real sign-in domain and there is no secret to type or intercept, so it is phishing-resistant. Passwords, SMS codes and push approvals are not.

Why passwords and SMS codes are no longer enough

Passwords and one-time codes share the same weakness: they are secrets a person can be tricked into handing over. Modern phishing kits sit between the user and the real sign-in page (adversary-in-the-middle), relay the password and the SMS code in real time and keep the session token. SMS adds its own risks, such as SIM swapping and message interception, and push approvals can be abused with prompt bombing.

That is why Microsoft is retiring the SMS and voice it delivers for Microsoft Entra ID and is making passkeys the default. The dates and the migration plan are in How to migrate users from SMS and voice MFA to passkeys.

How a passkey sign-in works

How a passkey sign-in works in Microsoft Entra ID: challenge, local unlock with biometrics or PIN, signed response and verification with the public key
Only a signature travels. The private key and the biometric never leave the user's device.

Passkeys are built on the FIDO2 and WebAuthn standards. When a user registers, the device creates a unique key pair for that account. At sign-in:

  1. Microsoft Entra ID sends a random challenge that is tied to the real sign-in domain.
  2. The user unlocks the passkey locally with face, fingerprint or PIN. The biometric is checked on the device and is never sent to Microsoft.
  3. The device signs the challenge with the private key and returns the signature.
  4. Microsoft Entra ID verifies it with the public key it stored at registration.

A look-alike domain gets nothing it can reuse: the passkey will not answer for it, and a stolen signature is useless for a new challenge. One gesture covers both factors, something you have (the key) and something you are or know (the unlock).

Passwords, SMS codes and passkeys side by side

Comparison of passwords, SMS codes, Authenticator push and passkeys by phishing resistance and user experience
Only passkeys resist phishing. Authenticator push improves on SMS but still relies on a password and a user decision.
PasswordSMS or voice codePasskey
What the user doesTypes a secretTypes a password and a codeUnlocks with face, fingerprint or PIN
What an attacker can stealThe passwordThe password and the code, in real timeNothing reusable
Phishing-resistant MFA strengthNoNoYes
After the 2027 retirementStill needs a second factorOnly through a customer-managed providerDefault method

Synced or device-bound passkeys?

Synced passkeys compared with device-bound passkeys in Microsoft Entra ID
Both types are phishing-resistant. Choose by persona, not by preference.

Synced passkeys live in a credential manager such as iCloud Keychain, Google Password Manager or another passkey provider and follow the user to a new phone. They remove most help desk calls for lost devices, which makes them the right default for the majority of employees. They do not support attestation, so you cannot restrict them to specific authenticator models.

Device-bound passkeys never leave the device that created them: a passkey in Microsoft Authenticator, a passkey on Windows or a FIDO2 security key. With attestation and key restrictions you can allow only approved models, which is what administrators and other privileged roles should use. The trade-off is that a new device means a new registration, usually with a Temporary Access Pass.

In Microsoft Entra ID you do not have to choose one for everybody: passkey profiles let you allow synced and device-bound passkeys for most users and device-bound only, with attestation, for administrators.

What changes for users

Registering a passkey

On a phone, the recommended path is Microsoft Authenticator: add the work account, choose to create a passkey, complete MFA once and enable Authenticator as a passkey provider in the phone settings. Users can also start from Security info on a computer and finish on the phone. Passkeys in Authenticator require iOS 17 or later and Android 14 or later, with Android 15 recommended.

Signing in every day

  • On the phone itself: choose the passkey and unlock it. No code, no app switching.
  • On a computer: use Windows Hello on a managed PC, a security key, or the phone through a QR code. Cross-device sign-in needs internet and Bluetooth on both devices.
  • On a new phone: synced passkeys come back with the credential manager; device-bound passkeys are registered again, usually with a Temporary Access Pass from the help desk.

What changes for IT

  • Enable Passkey (FIDO2) and design passkey profiles per persona.
  • Run a registration campaign and set up Temporary Access Pass for onboarding and recovery.
  • Allow the cross-device endpoints on the network without inspection and check OS and Authenticator versions.
  • Update help desk scripts for identity verification before issuing a Temporary Access Pass.
  • Require the Phishing-resistant MFA authentication strength with Conditional Access, starting with administrators. See how to require phishing-resistant MFA.

Three myths worth clearing up

  • “Biometrics are sent to Microsoft.” They are not. The face or fingerprint only unlocks the key on the device.
  • “Authenticator push is phishing-resistant.” It is not. A passkey stored in Microsoft Authenticator is; a push approval is not.
  • “Passkeys are a consumer feature.” Synced and device-bound passkeys are generally available for work accounts in Microsoft Entra ID.

How Synergy Advisors helps

Our security experts help you choose the right passkey types per persona, prepare devices and the help desk, and move users off SMS without disruption. Explore our Passwordless offering or check your starting point with the readiness checklist.

Sources

Frequently asked questions

Is a passkey the same as MFA?

A passkey satisfies MFA on its own: possession of the private key plus a local biometric or PIN. In Conditional Access it counts toward the Phishing-resistant MFA strength.

Are biometrics sent to Microsoft?

No. The biometric is checked on the device and only unlocks the private key. Microsoft Entra ID receives a signature and stores only the public key.

What happens if a user loses their phone?

Synced passkeys return when the user signs in to their credential manager on the new phone. Device-bound passkeys are registered again, usually with a Temporary Access Pass issued by the help desk.

Do passkeys work on Windows, Mac, iOS and Android?

Yes. Microsoft Entra ID supports passkeys on Windows, macOS, iOS, Android, ChromeOS and Linux in current browsers, with some platform limitations for security keys over NFC or Bluetooth.

Talk to our experts

Ready to take the next step?

A Synergy Advisors expert can help you assess where you are today and plan what comes next in your Microsoft security journey.

Scroll to Top