Guide

Passkeys for nurseries: the plain-English guide

Passkeys go one step beyond two-factor authentication: they remove the password altogether, and with it the thing staff get tricked into typing.

Two-factor authentication makes a stolen password much less useful. Passkeys go one step further: they remove the password altogether. There is nothing to guess, nothing to reuse and nothing to type into a fake login page. Even if a member of staff clicks a convincing fake Microsoft link, their passkey simply will not work there.

This guide explains what a passkey is, why it is safer, and what moving to passkeys involves for a nursery. It is a direction of travel rather than a job for one afternoon, so think of this as the map.

What a passkey actually is

A password is a secret you type. Because it is typed, people can be tricked into handing it over, and because it is stored by the website, it can leak when that website is breached.

A passkey is different. It is a secure key stored on a device, unlocked with the same face, fingerprint or PIN you already use to unlock that device. When you sign in, your device and the website perform a cryptographic handshake that proves it is you. Nothing is typed, nothing is written down, and there is no secret sitting on a server waiting to be stolen in a breach.

If you have ever opened your banking app with your fingerprint, you already know what it feels like.

Why passkeys are phishing-resistant

Phishing is how most attacks on small businesses begin, and our guide to spotting phishing emails covers the warning signs. Passwords can be phished because they can be handed over: a convincing page asks for one, and a busy person types it in.

A passkey cannot be handed over in the same way. It is tied to the genuine website's address, so a fake Microsoft page that only looks like the real thing will not be offered the passkey. Phishing depends on tricking someone into typing a secret, and a passkey takes that step away.

That is why passkeys are described as phishing-resistant. They do not make staff immune to every trick, but even when someone clicks a bad link, the attacker cannot sign in as them with a stolen password. It is one layer of defence alongside the others in our cyber security work, and if the worst does happen, our guide on what to do if you've been hacked is the place to start.

How signing in with a passkey works

There are two common ways a nursery will use passkeys with Microsoft 365.

On the device itself. On a Windows computer, the passkey can be unlocked with Windows Hello: your face, your fingerprint or your PIN. On a phone or iPad, it is Face ID, a fingerprint or the device passcode. You choose the passkey option, unlock it the way you would unlock the device, and you are in.

Using your phone to sign in on another computer. If the passkey lives on your phone and you are at a room computer, the computer shows a QR code. You scan it with your phone, the phone and computer confirm they are near each other over Bluetooth, and you unlock the passkey on your phone with your face or fingerprint. No password is typed and no code is copied.

This is different from the push approval many staff already know from Microsoft Authenticator, where you type a password and then tap "Approve" or match a number on your phone. That is two-factor authentication, and it still starts with a password that can be phished. A passkey replaces the password entirely. Microsoft Authenticator can also hold a passkey, which is where some of the confusion comes from. If two-factor is still on your list, start with our guide to two-factor authentication on Microsoft 365.

Microsoft 365 supports passkeys for work accounts now, and most staff already carry a phone that can hold one.

The lost-phone question

The first objection is always the same: what happens if a phone is lost, broken or replaced?

The answer is to plan for it so that one device is never the only way in. Every person should have a second sign-in method set up, and your IT provider should be able to issue a new passkey quickly once they have confirmed who is asking.

Password managers such as Keeper, which we use, can create, store and sync passkeys across a person's devices, so signing into Keeper on a new phone brings the passkeys back with it. For personal accounts and many websites, that turns a lockout into a five-minute restore. For Microsoft 365 work accounts, it depends on how your organisation's Microsoft Entra passkey settings are configured. Some setups allow synced passkeys from a password manager; others only allow device-bound passkeys, such as those held in Microsoft Authenticator or on a hardware security key. Check with your IT provider before you plan around it.

Keeper does other jobs for a nursery too. It is our recommended answer to shared passwords and leavers, covered in our leavers checklist. One tool quietly doing several jobs.

The shared-device question

Nurseries are not offices. One room computer might be used by four or five members of staff in a single day.

Passkeys suit personal accounts, so shared devices need some thought rather than a blanket rollout. The usual answer is that each person signs in with their own account and their own passkey, often by scanning the QR code with their own phone. That is better practice than one shared login anyway, because you know who did what.

A genuinely shared, always-on account, such as a room display, needs its own conversation rather than forcing passkeys to fit. That is one of the reasons the move is phased. If the jargon is getting thick, our jargon buster explains the terms in plain English.

What a realistic rollout looks like

Expect a three to six month transition, not a week's task.

  1. Get the foundations in place. Two-factor authentication on every account, a password manager, and a named account for everyone. Our guide to strong Windows passwords covers the device side.
  2. Start with the people who have the most access. The owner and managers first, because their accounts matter most.
  3. Let it settle, then widen it. Learn the lost-phone and shared-device wrinkles with a small group, then roll out room by room without disrupting the day.

The aim is steady progress, not a dramatic weekend. Our Microsoft 365 support team can configure the settings and plan the stages with you.

The one thing to take away

Passkeys remove passwords, and with them the weakness of staff typing secrets into fake sites. They are phishing-resistant by design and Microsoft 365 supports them now. Plan for lost phones before they happen, start with the accounts that matter most, and treat it as a three to six month direction of travel. This is where everyone is heading: there is no need to rush to be first, and no reason to be last.

Questions

Does Microsoft 365 support passkeys?

Yes. Microsoft 365 work accounts can sign in with passkeys, including passkeys held in the Microsoft Authenticator app and on security keys. Which types your staff can use depends on how your organisation's Microsoft Entra settings are configured.

What happens to a passkey if a member of staff loses their phone?

Plan for it before it happens. Every person should have a second way to sign in, and your IT provider can issue a new passkey once their identity is confirmed. Synced passkeys in a password manager such as Keeper can make recovery quicker, where your Microsoft 365 setup allows them.

Is a passkey the same as approving a sign-in on my phone?

No. Approving a push notification in Microsoft Authenticator is two-factor authentication on top of a password. A passkey replaces the password and is unlocked with your device's face, fingerprint or PIN.

Can passkeys work on a shared room computer?

Yes, if each person signs in with their own account and their own passkey, for example by scanning a QR code with their phone. A genuinely shared account needs a separate conversation, which is one reason a phased rollout makes sense.

Want to know where your business stands?

Our free exposure check shows what an attacker can already see: leaked passwords, email spoofing and exposed systems. Fifteen minutes, nothing to install.

More guides