Passkeys and Conditional Access without disrupting your team

Passwords are still how most Irish firms sign in to Microsoft 365, and they are the part attackers beat most easily. Here is the order we roll out passkeys and conditional access so the change lands without a week of support calls.

A laptop displaying a sign-in screen sits on a white desk next to papers, a pen, and two small black devices.

In short

Passkeys replace the password with a key held on your staff's own device, unlocked by fingerprint, face or PIN. Conditional access decides when that proof is enough. Roll them out in order: a small pilot, then privileged accounts, then team by team, with your conditional access policies in report-only mode first. Block legacy authentication last. Allow six to eight weeks for a forty person firm.

Your team signs in to Microsoft 365 with a password and a six digit code. That combination is beaten routinely now, because the code can be relayed through a fake sign-in page or approved by a tired person at eight in the morning. Passkeys and conditional access close both gaps, and the reason most firms have not moved is fear of the disruption rather than doubt about the security.

Why the password is now the weakest part of your sign-in

A password is a secret your staff can be talked into handing over. Every phishing kit sold today is built on that fact, and the better ones sit between your employee and the real Microsoft login, passing the password and the authentication code straight through in real time. The employee sees the genuine sign-in screen, because it is the genuine sign-in screen. The attacker keeps the session and walks in.

We see the aftermath more often than the attempt. A mailbox starts forwarding invoices to an address nobody recognises, or a supplier rings about bank details that changed. If you want the warning signs, we wrote them up in spotting a hijacked mailbox early.

The point to hold on to is this. Adding a code to a password makes the attack harder, not impossible. Removing the password removes the thing that can be handed over.

What a passkey is, and what changes for staff

A passkey is a pair of cryptographic keys. The private half never leaves the device it was created on, and it unlocks with a fingerprint, a face scan or the device PIN. The public half sits with Microsoft. Signing in means the device proves it holds the private key, and no secret is typed, sent or shown on screen.

Two properties matter to a business owner. Nothing exists for an employee to give away, and the passkey is bound to the real Microsoft domain, so a lookalike sign-in page gets nothing at all. The FIDO Alliance, the industry body behind the standard, has the technical detail if you want it.

For staff, the daily experience gets shorter. Thumb or face, and they are in. Say that out loud in your rollout email, because most people expect a security change to cost them time.

Conditional access is the rule, the passkey is the key

Passkeys change how someone proves who they are. Conditional access decides when that proof is enough. It is the policy engine inside Microsoft Entra ID, and it looks at each sign-in against your rules: this person, on this device, from this country, reaching this application.

The rules worth having in a small firm are few:

  • Require phishing-resistant sign-in for anyone holding administrative rights.
  • Block sign-ins from countries you never trade with.
  • Require a managed, compliant device for access to finance systems and shared files.
  • Block legacy authentication protocols, which cannot enforce any of the above.

One caution before you budget. Conditional access sits behind a paid Entra ID tier, and which Microsoft 365 bundles include that tier changes. Confirm what your current licences cover before you plan around them, because the answer differs between two firms of the same size. Microsoft's own conditional access documentation is the reference to check it against.

The rollout order that avoids a support queue

Order is what decides whether this costs you a fortnight of complaints.

  1. Pilot with two or three people. Whoever runs IT, plus one director who will tell you honestly if it feels awkward. Register passkeys, leave the old method in place, and run for a week.
  2. Move the accounts that matter most. Global administrators, finance, and anyone who can move money or change bank details. These are the accounts an attacker wants, and the group is small enough to help in person.
  3. Roll out by team, not all at once. One department a week. Send the instructions the day before, and have someone free for the first hour of the morning.
  4. Run the conditional access rules in report-only mode first. Every policy can log what it would have blocked without blocking it. Leave it there for a week and read the log. It will show you the printer, the scanner and the old line of business application you had forgotten about.
  5. Block legacy authentication last. Only once the report-only log is clean. This is the step that breaks things, and by now you know exactly what it will break.

Allow six to eight weeks end to end for a firm of forty people. Most of that is waiting rather than working.

The three things that go wrong

The shared computer. Reception desks, practice front offices, the PC in the workshop. A passkey lives on a device or in a personal account, and neither suits a machine four people use. The answer is usually a security key each, on a lanyard, or a hard look at why the account is shared at all. Decide this before the rollout reaches that desk, not during.

The employee with no company phone. Some staff will not register a work credential on a personal device, and you cannot compel them to. Budget for a small number of hardware security keys and the argument goes away.

The locked-out administrator. If a conditional access policy applies to every account including yours, and something goes wrong with it, nobody can sign in to fix it. Keep at least one break-glass administrator account excluded from every policy, with a long password held somewhere physical, and test quarterly that it still works. This is the most common self-inflicted outage of the whole project.

Where to start this month

Two jobs, both short. Open the sign-in logs in Entra and count how many sign-ins still use legacy authentication, because that number sets your timeline. Then list the accounts that can change a bank detail or approve a payment, and put those at the front of the queue.

For firms in regulated trades, this does useful work on paper as well. Article 32 of the GDPR requires security appropriate to the risk, and moving privileged accounts to phishing-resistant sign-in is a decision worth recording in whatever file you keep for the Data Protection Commission. We take the same approach with accountancy and legal practices and financial services firms, where the audit question comes round every year.

If you would rather not run the rollout yourself, it is part of what we do under managed IT. Tell us the size of your team and we will give you a realistic timeline. Get in touch.

What is a passkey, and is it safer than a password?

A passkey is a cryptographic key stored on your phone or laptop and unlocked with a fingerprint, face scan or PIN. It is safer than a password because there is no secret to type or share, and the key only works on the genuine Microsoft sign-in domain. A fake login page cannot collect anything useful from it.

Do we need to buy hardware security keys?

Not for most staff. Modern iPhones, Android phones, Macs and Windows laptops can hold passkeys already, so the majority of your team needs no new hardware. Buy physical security keys for two cases: people who will not use a personal device for work sign-in, and shared computers where no single person owns the machine.

Will passkeys work on a shared practice or reception computer?

Not comfortably. A passkey belongs to a person and their device, while a shared reception PC is used by several people through one account. The usual fix is a hardware security key for each person who works that desk, so each signs in as themselves. The alternative is to stop sharing the account, which is better practice anyway.

What Microsoft 365 licence do we need for conditional access?

Conditional access is part of a paid Microsoft Entra ID tier rather than a standalone purchase, and which Microsoft 365 bundles include that tier has changed more than once. Check your own tenant's licence assignments, or ask your IT provider to confirm, before you build a plan that assumes you already have it.

What happens if someone loses the phone their passkey is on?

They cannot sign in with that passkey again, which is the point. Register a second method for every user before the first one is enforced, whether that is a passkey on a laptop or a hardware key kept in the office. Your administrator can then remove the lost device's passkey and enrol a replacement the same day.

All blog posts

Start with a free IT review.

You'll get a clear picture of where you're exposed today, and what it looks like to have your whole IT covered as one managed system. No obligation.