Passkeys and password managers for small businesses
Passwords remain common, but businesses can reduce password risk by using password managers, unique credentials and stronger authentication. Passkeys and FIDO2-based methods can further reduce exposure to phishing where services support them.
6 practical answers.
### Should staff use a password manager?
A well-managed password manager can help staff create and store unique passwords rather than reusing memorable passwords across services. The password manager account itself should be strongly protected.
### What is a passkey?
A passkey uses public-key cryptography and a trusted device or security key instead of relying on a reusable password sent to a website. Correctly implemented passkeys are designed to resist common phishing techniques.
### Are passkeys the same as MFA?
A FIDO2 authentication can constitute MFA when local user verification such as a PIN or biometric is required as part of the sign-in.
### Should we change passwords regularly?
Avoid forcing arbitrary frequent password changes unless there is a specific reason or policy requirement. Focus on unique credentials, compromised-password response, strong authentication and secure account recovery.
### How should administrator passwords be handled?
Privileged accounts should be separate from routine user accounts where practical, use unique credentials, strong authentication and tightly controlled recovery methods.
### What if a service does not support passkeys?
Use the strongest supported MFA method, a unique password stored in an approved password manager and additional controls appropriate to the risk.