Two-factor authentication makes a stolen password much less useful. Passkeys go one step further: they remove the password altogether. There is nothing to guess, nothing to reuse and nothing to type into a fake login page. Even if a member of staff clicks a convincing fake Microsoft link, their passkey simply will not work there.
This guide explains what a passkey is, why it is safer, and what moving to passkeys involves for a nursery. It is a direction of travel rather than a job for one afternoon, so think of this as the map.
What a passkey actually is
A password is a secret you type. Because it is typed, people can be tricked into handing it over, and because it is stored by the website, it can leak when that website is breached.
A passkey is different. It is a secure key stored on a device, unlocked with the same face, fingerprint or PIN you already use to unlock that device. When you sign in, your device and the website perform a cryptographic handshake that proves it is you. Nothing is typed, nothing is written down, and there is no secret sitting on a server waiting to be stolen in a breach.
If you have ever opened your banking app with your fingerprint, you already know what it feels like.
Why passkeys are phishing-resistant
Phishing is how most attacks on small businesses begin, and our guide to spotting phishing emails covers the warning signs. Passwords can be phished because they can be handed over: a convincing page asks for one, and a busy person types it in.
A passkey cannot be handed over in the same way. It is tied to the genuine website's address, so a fake Microsoft page that only looks like the real thing will not be offered the passkey. Phishing depends on tricking someone into typing a secret, and a passkey takes that step away.
That is why passkeys are described as phishing-resistant. They do not make staff immune to every trick, but even when someone clicks a bad link, the attacker cannot sign in as them with a stolen password. It is one layer of defence alongside the others in our cyber security work, and if the worst does happen, our guide on what to do if you've been hacked is the place to start.
How signing in with a passkey works
There are two common ways a nursery will use passkeys with Microsoft 365.
On the device itself. On a Windows computer, the passkey can be unlocked with Windows Hello: your face, your fingerprint or your PIN. On a phone or iPad, it is Face ID, a fingerprint or the device passcode. You choose the passkey option, unlock it the way you would unlock the device, and you are in.
Using your phone to sign in on another computer. If the passkey lives on your phone and you are at a room computer, the computer shows a QR code. You scan it with your phone, the phone and computer confirm they are near each other over Bluetooth, and you unlock the passkey on your phone with your face or fingerprint. No password is typed and no code is copied.
This is different from the push approval many staff already know from Microsoft Authenticator, where you type a password and then tap "Approve" or match a number on your phone. That is two-factor authentication, and it still starts with a password that can be phished. A passkey replaces the password entirely. Microsoft Authenticator can also hold a passkey, which is where some of the confusion comes from. If two-factor is still on your list, start with our guide to two-factor authentication on Microsoft 365.
Microsoft 365 supports passkeys for work accounts now, and most staff already carry a phone that can hold one.
The lost-phone question
The first objection is always the same: what happens if a phone is lost, broken or replaced?
The answer is to plan for it so that one device is never the only way in. Every person should have a second sign-in method set up, and your IT provider should be able to issue a new passkey quickly once they have confirmed who is asking.
Password managers such as Keeper, which we use, can create, store and sync passkeys across a person's devices, so signing into Keeper on a new phone brings the passkeys back with it. For personal accounts and many websites, that turns a lockout into a five-minute restore. For Microsoft 365 work accounts, it depends on how your organisation's Microsoft Entra passkey settings are configured. Some setups allow synced passkeys from a password manager; others only allow device-bound passkeys, such as those held in Microsoft Authenticator or on a hardware security key. Check with your IT provider before you plan around it.
Keeper does other jobs for a nursery too. It is our recommended answer to shared passwords and leavers, covered in our leavers checklist. One tool quietly doing several jobs.
The shared-device question
Nurseries are not offices. One room computer might be used by four or five members of staff in a single day.
Passkeys suit personal accounts, so shared devices need some thought rather than a blanket rollout. The usual answer is that each person signs in with their own account and their own passkey, often by scanning the QR code with their own phone. That is better practice than one shared login anyway, because you know who did what.
A genuinely shared, always-on account, such as a room display, needs its own conversation rather than forcing passkeys to fit. That is one of the reasons the move is phased. If the jargon is getting thick, our jargon buster explains the terms in plain English.
What a realistic rollout looks like
Expect a three to six month transition, not a week's task.
- Get the foundations in place. Two-factor authentication on every account, a password manager, and a named account for everyone. Our guide to strong Windows passwords covers the device side.
- Start with the people who have the most access. The owner and managers first, because their accounts matter most.
- Let it settle, then widen it. Learn the lost-phone and shared-device wrinkles with a small group, then roll out room by room without disrupting the day.
The aim is steady progress, not a dramatic weekend. Our Microsoft 365 support team can configure the settings and plan the stages with you.
The one thing to take away
Passkeys remove passwords, and with them the weakness of staff typing secrets into fake sites. They are phishing-resistant by design and Microsoft 365 supports them now. Plan for lost phones before they happen, start with the accounts that matter most, and treat it as a three to six month direction of travel. This is where everyone is heading: there is no need to rush to be first, and no reason to be last.