Most Ontario businesses spent the last few years turning on multi-factor authentication, pushing staff to use authenticator apps, and enforced MFA across the board. For a while, that was enough.
Unfortunately, it isn't anymore. Attackers have adapted to MFA, and the codes and push notifications that once protected most SMB accounts today can be intercepted (or bypassed) in real time. Passkeys are the industry's response to that problem, and they are quickly becoming supported by Microsoft 365, Google Workspace, Apple, and most major business platforms you interact with.
Why "We Have MFA" is the New Starting Line
Traditional MFA was built on a simple idea: even if someone steals your password, they still need your second factor, which is stored safely on your personal device.
Modern phishing doesn't care how secure your codes are. New-age scams like adversary-in-the-middle phishing puts a fake login page between your employee and the real Microsoft or Google sign-in. Once the employee enters their password and approves their push notification or types in the six-digit code, the attacker's proxy passes it all through. Then, the attacker walks away with a valid employee session and never needed to break or hack anything.
SMS codes, authenticator app codes, and push approvals are all vulnerable to this. So is MFA fatigue, where an attacker who already has a password spams push requests until someone taps "Approve" to make them stop.
What a Passkey Actually Is
A passkey is a sign-in credential built on the FIDO2 and WebAuthn standards. Put in simpler terms, instead of a shared secret like a traditional password, passkeys use a cryptographic key pair.
When you create a passkey for a service (like M365 or Google Workspaces), your device generates two keys. The public key is stored by the service, and the private key stays on your device, or in a secure password manager. The next time you sign in, the service sends a 'challenge' to your device, and attempts to sign it with the private key. Once the service verifies the signature, it'll sign you into the service.
From the user's side, signing in looks similar to unlocking their phone. From a security standpoint, three things change:
- There's nothing to steal from the service provider. The service provider (Micorosft, Google) only holds your public key. A breach of that service doesn't expose a credential anyone can reuse.
- There's nothing to type, so there's nothing to phish. Your passkey is bound to the exact domain it was created for. If an employee lands on a fake, but real looking Microsoft login page, their device won't offer the passkey simply because the domain doesn't match the saved-passkeys domain. The browser does the checking that the employee used to be responsible for.
- There's nothing to reuse. Every passkey is unique to one service. The habit of using one password across ten sites disappears completely.
Synced vs. Device-Bound Passkeys
This distinction matters more for businesses than for consumers.
Synced passkeys are stored in a credential manager such as iCloud Keychain, Google Password Manager, or a business password manager like 1Password or Bitwarden. They follow the user across their devices, which makes them convenient and easy to recover if a phone is lost.
Device-bound passkeys live on a single piece of hardware and can't be copied. This includes hardware security keys like YubiKeys, Windows Hello for Business, and passkeys stored in Microsoft Authenticator. They are harder to lose control of and easier to audit.
For most SMB staff, synced passkeys managed through a company-controlled password manager are a sensible fit. For administrators, finance staff, and anyone with access to sensitive systems, device-bound passkeys are the stronger choice. The one thing to avoid is company credentials quietly syncing into employees' personal Apple or Google accounts, where your business has no visibility or control when that person leaves.
Does a Passkey Replace MFA?
No. It replaces the weak versions of MFA. Passkeys don't remove the need for MFA in your environment. They replace the password-plus-code combination with a single step that is stronger than both.
Is It Better Than Passwords or Traditional MFA?
Compared against traditional passwords alone, it isn't close. Passwords can be guessed, reused, leaked in breaches, and phished. Passkeys are resistant to all four.
Compared with traditional MFA, passkeys win on the threat that matters most right now: real-time phishing. An authenticator code or push approval can be relayed or bypassed by an attacker. A passkey can't, because it won't respond to the wrong domain (website address).
Where traditional MFA still has a role is coverage, since not every system your business relies on supports passkeys yet, and those systems still need protection. In scenarios like these, a strong password paired with MFA is still highly recommended, until Passkeys are supported.
The Real Difficulties of Adopting Passkeys
Passkeys are a clear improvement, but rolling them out in an SMB isn't a magic switch you flip. These are the issues we see most often:
Legacy and line-of-business applications. Microsoft 365 and Google Workspace support passkeys. But, your ERP, practice management system, older VPN, or on-premises server may not. Those systems will need to stay on traditional MFA, or sit behind a single sign-on platform that does support passkeys.
Leaving the old door open. A business enrolls everyone in passkeys but leaves password-plus-SMS enabled as a fallback. Real phishing resistance only arrives when you enforce passkeys through policy (such as Conditional Access) and remove weaker methods for the accounts that matter.
Account recovery. When someone loses their phone or security key, you need a process to verify their identity and issue a new credential. If that process is "call the help desk and give your name," you've built a social engineering path around your strongest control. Recovery needs to be designed before rollout, not after the first lost device.
Shared workstations and shared accounts. Passkeys are tied to individuals. Front desks, shop floor terminals, and shared mailboxes with a common password don't fit that model need to be restructured first.
Device ownership. If staff use personal phones for work sign-in, you need a clear policy on where company passkeys are stored and what happens when the employee leaves.
Why SMBs Should Adopt Passkeys
For most SMBs, the recommendation is to start now, starting small.
Accounts that attackers target first are also the accounts that are easiest to move to passkeys: global administrators, finance staff and business owners. Protecting those with device-bound passkeys and enforcing it through policy closes the most common path to business email compromise and ransomware, usually within a few weeks and with minimal cost to your business.
Moving Past the Password with Keystone
Passkeys are the most meaningful improvement to everyday sign-in security in years, but the benefit depends entirely on how they're deployed. Enforcing them through policy and retiring weak fallback methods are where most businesses need help.
Keystone Technologies helps Ontario businesses assess their current authentication setup, identify which accounts and systems are ready for passkeys, and roll them out in a way that strengthens security without disrupting the people who have to use it every day.
To find out where your business stands, visit keystonetech.ca, call 519-451-1793, or email info@keystonetech.ca.
