Blue curved vector shape
30 Sep 2026

Are Passwords Finally on Their Way Out?

A simple guide to passkeys, biometrics and Windows Hello

Passwords have become one of those frustrations businesses have simply learned to live with.

People forget them, reuse them, write them down, get locked out, and sometimes enter them into convincing fake websites.

That’s why Microsoft is steadily moving towards a world where passwords become much less important.

The good news is that the replacement could actually make life easier for users as well as more secure.

What's wrong with passwords?

The fundamental problem with a password is simple:

Somebody else can steal it.

A criminal might obtain it from a data breach, guess it or persuade an employee to enter it into a fake Microsoft login page.

Multi-factor authentication (MFA) has helped enormously by adding another check, such as an approval through an app or a code sent by SMS.

But criminals have adapted. That’s why Microsoft is now encouraging businesses to move towards phishing-resistant authentication.

In simple terms, that means using a method that is much harder for an employee to accidentally hand over to a criminal.

What is Windows Hello?

You may already be using it. Windows Hello allows you to sign into your computer using your: Face, Fingerprint or PIN

For a business, Windows Hello for Business combines this convenient experience with strong authentication.

Instead of entering a Microsoft password every morning, an employee can sit down, look at their laptop and be signed in.

Importantly, their face or fingerprint isn’t simply being sent across the internet as a replacement password. It unlocks a secure credential associated with that device.

So the experience is simple: Look at laptop → laptop recognises you → you’re in.

What is a passkey?

A passkey is another way of removing the traditional password from the login process.

The easiest way to understand the benefit is through phishing.

Imagine an employee receives an email saying: “Your Microsoft 365 password expires today. Click here.”

The link takes them to a website that looks exactly like Microsoft.

With a traditional password, they could type it into the fake website and give it directly to a criminal.

With a passkey, there isn’t a reusable password for the employee to hand over.

The passkey is designed to authenticate with the genuine service.

That’s why passkeys are described as phishing-resistant.

So are passwords disappearing?

Not overnight. Businesses still use plenty of applications and websites that rely on passwords, and that’s unlikely to change immediately.

But Microsoft’s direction is clear. Rather than continually asking: “How can we make passwords more complicated?”

The industry is increasingly asking: “Why are we using a password at all?”

Microsoft recommends stronger, phishing-resistant authentication methods such as Windows Hello for Business and passkeys wherever practical.

And there are some important changes coming.

Microsoft is moving away from SMS authentication

Many Microsoft 365 users currently receive a six-digit SMS code when signing in.

It’s familiar and it’s certainly better than relying on a password alone.

But Microsoft no longer considers SMS strong enough for where it wants authentication security to go.

Microsoft has therefore begun moving users towards passkeys and plans to retire its own SMS and voice authentication service for most users from 1 February 2027.

There are exceptions and alternative arrangements for particular accounts and organisations, but the message for most small businesses is straightforward:

If your employees still rely on SMS codes to access Microsoft 365, now is the time to start planning an alternative.

What about Microsoft Authenticator?

Microsoft Authenticator isn’t simply disappearing.

The important distinction is that Microsoft is increasingly encouraging phishing-resistant authentication.

For a typical business user with a company Windows laptop, that could mean using Windows Hello for Business.

Passkeys provide another option, while physical FIDO2 security keys can be appropriate for certain users and situations.

You don’t need to choose one method for everybody.

The right approach depends on how your employees work.

Will this make life harder for employees?

It shouldn’t. This is perhaps the most attractive part of the change.

Traditionally, better security has meant more inconvenience:

Another password. Another code. Another approval. Another prompt.

Modern authentication can potentially give us better security with less effort.

Compare:

Traditional login

Enter email → enter password → receive SMS → find phone → enter code → continue.

With:

Windows Hello

Look at laptop → continue.

For the employee, it’s easier.

For the business, it’s considerably harder to phish.

That’s a rare security win-win.

What should a small business do now?

You don’t need to remove everyone’s passwords next week.

A sensible migration should be gradual.

1. Find out what you're using now

Who still uses SMS? Who uses Microsoft Authenticator? Who already uses Windows Hello?

2. Check your computers

Make sure company devices are properly managed, supported and ready for Windows Hello and modern authentication.

3. Protect administrator accounts first

Accounts capable of making major changes to Microsoft 365 should have particularly strong authentication.

4. Test before rolling out

Start with a small group of users, make sure everything works and then gradually extend it across the business.

5. Explain the change

Don’t surprise employees with an unfamiliar Microsoft prompt.

A simple message beforehand can prevent confusion:

“Microsoft is changing the way you sign in. We’re moving away from SMS codes to a more secure method that should also make signing in easier.”

Don't panic, but don't ignore it

If terms such as passkeys, Windows Hello and FIDO2 mean very little to you, that’s fine.

You shouldn’t need to become an expert in authentication to run your business.

What matters is understanding that Microsoft is changing the way users authenticate, SMS is being phased out as a Microsoft-provided authentication method, and somebody needs to plan how your business will move to the new approach.

Done properly, the result should be:

Fewer passwords to remember.

Fewer codes to type.

Less opportunity for criminals to steal credentials.

And an easier experience for your employees.

Is your business ready?

FOS.net can review how your Microsoft 365 users currently sign in, identify who is still relying on older authentication methods and put together a sensible plan for moving towards Windows Hello and passkeys.

You don’t need to understand all the technology. You just need to make sure somebody is looking after it.

FOS.net logo dark