Microsoft, Apple, and Google have all committed to passkeys as the future of authentication. The FIDO Alliance reports that passkey support is now available on over 4 billion devices. The promise is compelling: no passwords to forget, no phishing to fall for, no credential stuffing to defend against.
But is passwordless authentication realistic for a 20-person company with legacy systems, third-party integrations, and a limited IT budget? At Metaluxo we have assessed passkey readiness for several SMEs. The answer is nuanced.
What passkeys actually are
A passkey is a cryptographic key pair stored on your device. The private key never leaves the device. The public key is registered with the service. When you log in, the service sends a challenge, your device signs it with the private key, and the service verifies the signature.
The result is phishing-resistant authentication. There is no password to type into a fake site. There is no secret to steal from a database breach.
Where passkeys work today
Google Workspace and Microsoft 365 both support passkeys for consumer accounts. Enterprise support is rolling out but may require additional licensing.
Apple ID and iCloud support passkeys natively on Apple devices.
GitHub, Dropbox, and 1Password support passkeys for personal accounts.
Password managers (1Password, Bitwarden, Dashlane) can store and sync passkeys across devices.
Where passkeys do not work yet
Legacy on-premise applications — most business software written before 2022 does not support WebAuthn or FIDO2.
Third-party integrations — if your CRM, accounting software, or support platform does not support passkeys, you still need passwords for those systems.
Shared accounts — passkeys are device-bound. A shared login for a team tool requires each team member to register their own passkey, which many platforms do not support.
Recovery — if you lose your device, recovering passkeys depends on your ecosystem (iCloud Keychain, Google Password Manager, etc.). Cross-platform recovery is still inconsistent.
The pragmatic SME approach
For most SMEs, the right answer in 2025 is not “go passwordless today.” It is “prepare for passwordless while hardening what you have.”
- Enable passkeys where supported. Start with Google, Microsoft, and any SaaS tools that offer it.
- Enforce MFA everywhere else. TOTP or hardware keys for every system that does not support passkeys.
- Audit your password inventory. Know which systems still require passwords and why.
- Plan the migration. When a system adds passkey support, migrate it. Do not wait for a company-wide switchover.
At Metaluxo we assess authentication strategies for SMEs as part of our vCISO engagements. If you are considering passwordless and want to know what is realistic for your stack, book a free 30-minute consultation and we will map your readiness.