Security and Convenience - You can have it all!

Australia, Feb 11, 2026

Passkeys, Phishing-Resistant MFA, and the Next Evolution of Identity in Microsoft Entra.

For years, security teams have been forced into a compromise.

Stronger authentication often meant more friction for users - Extra prompts, more steps, increased service desk calls.

In 2026, that trade-off is finally disappearing.

With the maturity of Passkeys in Microsoft Entra, organisations can now deliver authentication that is both highly secure and remarkably simple for end users.

The New Baseline: Phishing-Resistant MFA

Not all MFA is created equal.

Traditional methods such as SMS, phone call, or push notifications can still be intercepted, replayed, or socially engineered. Modern identity strategies increasingly focus on phishing-resistant authentication.

Passkeys provide this capability by design.

Because the authenticator only releases credentials to the legitimate service, passkeys cannot be used on look-alike phishing sites.  

Passkeys also inherently meet multi-factor authentication requirements, combining something you have (the device) with something you are or know (biometric or PIN).  

Microsoft-supported phishing-resistant methods today include:

  • FIDO2 Security Keys
  • Microsoft Authenticator passkeys
  • Platform passkeys using biometrics (Windows Hello, Apple FaceID, Android Biometrics)

These options provide a much stronger assurance level than legacy MFA methods.

Passwordless Authentication - Secure and Seamless

Passkeys enable true passwordless authentication in Microsoft Entra.

If there is one thing that users hate, it’s having to remember long, complex and unique passwords to access work resources.

Passkeys allow a user to sign in with no password at all, they simply authenticate on their mobile device or hardware key using biometric or PIN. 

Topic

Related Insights