Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with your identity provider, then protect administrator accounts and the services whose compromise would cause the most harm: business email, file storage, remote access, and privileged consoles. Confirm that your provider and employees’ devices support passkeys or FIDO2/WebAuthn security keys, test enrollment and account recovery with a small pilot, and only then require the stronger method for sensitive access. Exact settings vary by provider.

What makes MFA phishing-resistant?

Phishing-resistant MFA binds authentication to the legitimate service, rather than asking a person to type or approve a credential that a fake login page could capture. FIDO/WebAuthn passkeys and security keys are practical options. By contrast, a one-time code or push approval may still be relayed or tricked out of a user; even number matching is an interim improvement, not phishing resistance. CISA calls phishing-resistant MFA the gold standard.

How passkeys work

A passkey uses a public/private key pair unique to an account and service. The authenticator retains the private key, while the service registers the public key. At sign-in, the service sends a challenge that the authenticator signs after the user unlocks it locally. Because the credential is tied to the service for which it was registered, it is not presented to a lookalike phishing site. The FIDO Alliance describes this model in its passkey explainer.

1. Inventory accounts and prioritize protection

List your identity provider and the services staff use to sign in. Include email, file storage, VPN or other remote access, accounting and payroll, customer systems, and administrative consoles. Identify global administrators, IT support, executives, and employees who handle sensitive data. Begin enforcement with administrators and sensitive-data users, then broaden it to the rest of the business. CISA’s small-business MFA guidance specifically includes email, file storage, remote access, and privileged access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

2. Choose a supported FIDO method

Before buying keys or changing policy, check the identity provider’s current authentication-method support and the operating systems and devices employees actually use. FIDO security keys and passkeys can both provide phishing-resistant authentication, but availability and administration vary by provider and platform.

Hardware security keys

A hardware key is a physical authenticator that an employee uses during sign-in. It can be a useful option when the business wants a tangible credential or needs to control which authenticator is used. Confirm that the provider supports the key type and that staff can use it on their normal work devices.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Passkeys

Depending on the platform, passkeys may be stored on a device, a security key, or a passkey provider. Consider how employees will sign in across their work devices and how the business will handle loss or replacement. Microsoft distinguishes device-bound passkeys, stored on a single device or FIDO security key, from synced passkeys, which can be used on other devices authenticated with the passkey provider. Microsoft says synced passkeys do not support attestation; this may matter to organizations with specific credential-control requirements. Neither arrangement is the right choice for every business.

3. Pilot enrollment and recovery

Start with a small group that includes at least one administrator and employees using representative work devices. Test the whole sign-in and support experience before requiring the method broadly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Confirm users can register a passkey or security key and sign in from their regular devices.
  • Test the documented recovery route if someone loses a device or key, and make sure the business—not an informal workaround—controls that process.
  • Verify that users know where to get help and that support staff can resolve common enrollment problems.
  • Record which methods are enrolled and who is responsible for recovery and policy changes.

Enrollment prompts and recovery restrictions differ by provider, so do not assume one service’s screens or rules apply to another.

4. Configure the identity provider and enroll users

In a typical passkey enrollment, an employee signs in using an existing method, opens the provider’s account or security settings (or follows a provider prompt), starts passkey creation, and approves it with a local PIN, biometric, or external security key. In the FIDO model, the service registers the public key; the user’s local biometric data is not sent to the service.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Microsoft Entra example

Menu names and requirements can change. In Microsoft Entra ID, an Authentication Policy Administrator manages passkey profiles at Entra ID > Security > Authentication methods > Policies. The administrator configures allowed passkey types, creates profiles if needed, and targets a pilot group or all users. For sensitive resources, a Conditional Access authentication strength can require passkey sign-in. Microsoft’s documentation says passkeys are available in Entra ID Free and other Entra editions without an extra license; check its current passkey documentation for live requirements.

Microsoft currently documents a requirement for users to complete MFA shortly before registering a passkey, with a five-minute recent-MFA window, and lists operating-system and authenticator requirements. Check the live documentation for the supported configurations before rollout.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Enforce the method and review fallback

Once the pilot has validated enrollment, routine sign-in, and recovery, use provider policy controls to require phishing-resistant authentication for administrators and sensitive services. Expand coverage in stages. Review policy exclusions, legacy authentication, recovery routes, and any remaining SMS or voice codes. A weaker fallback can undermine a stronger primary sign-in, so reduce or remove SMS and voice where the service and tested recovery plan allow.

If passkeys or security keys cannot be deployed immediately, CISA identifies app-based one-time passwords and number-matching push as better interim choices than ordinary push or SMS, while noting that these methods remain vulnerable to phishing. Assign an owner and a migration date so the temporary method does not become the permanent end state. CISA’s phishing-resistant MFA fact sheet explains the distinction.

6. Train staff and maintain coverage

Tell employees what legitimate enrollment prompts look like, how to report a suspicious request, and where to go if a key or device is lost. Explain why the business is changing its sign-in rules. Keep the method inventory current, remove credentials for departing staff, and revisit provider policy when roles or devices change. CISA’s small-business guidance recommends communicating the reason for MFA and educating employees.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.