AI

Cyber Month: Move Your Burnaby Team to Passkeys in a Day

October 4, 2026 · 8 min read · Autana Solutions, Vancouver
Cyber Month: Move Your Burnaby Team to Passkeys in a Day — Autana Solutions

October is Cyber Security Awareness Month in Canada. The Communications Security Establishment runs it through its Get Cyber Safe campaign, and the 2025 launch led with the basics: strong passphrases, password managers, multi-factor authentication, and spotting phishing. Good advice. But there's one change a small Burnaby or New Westminster business can make in a single afternoon that does more than all of those combined. Move your team's main logins to passkeys.

Here's why that matters more in 2026 than it did two years ago, what the standards bodies actually say, and the step by step for Microsoft 365 and Google Workspace.

Why AI changed the phishing math

Most staff security training still teaches people to spot the fake email: bad grammar, odd phrasing, a slightly wrong logo. That worked when phishing was mass produced by hand.

The Canadian Centre for Cyber Security's National Cyber Threat Assessment 2025-2026 says cyber threat actors "are almost certainly using LLMs to improve social engineering attacks" and can "craft personalized phishing emails at scale with convincing and grammatically correct language." In plain terms, AI took away the typos. Your bookkeeper can't be expected to out-read a language model that has studied ten thousand real invoice emails.

So the fix can't depend on humans spotting fakes. It has to make the stolen credential worthless. That's exactly what a passkey does.

What a passkey actually is

The FIDO Alliance defines a passkey as "an authentication credential based on FIDO standards, that can be stored on your phone or computer, or in a hardware security key allowing a user to sign in to apps and websites with the same process that they use to unlock their device." Under the hood it's a public and private key pair. The website keeps the public half. The private half never leaves your device or your encrypted keychain, and it only answers a challenge from the real domain it was registered to.

That last part is the whole point. NIST's SP 800-63B, Revision 4, published in August 2025, calls this "verifier name binding" and names WebAuthn and FIDO2 as the example. It also says plainly that "authenticators that involve the manual entry of an authenticator output ... SHALL NOT be considered phishing-resistant." That covers the six digit codes from SMS and most authenticator apps. A fake login page can ask you to type those in. It can't ask your passkey to sign for the wrong domain.

The UK's National Cyber Security Centre reached the same conclusion. In its April 2026 announcement it said passkeys "are at least as secure as, and generally more secure than, pairing the strongest password with two-step verification," and it no longer recommends passwords where passkeys are available. Canada's own ITSAP.30.033 guidance, updated April 2026, notes that a breach of a website leaves the attacker with only a public key, which "cannot be used to authenticate or gain access without the corresponding private key."

The one afternoon plan

This assumes a team of roughly five to twenty people on either Microsoft 365 or Google Workspace. Larger or mixed environments take longer, and that's fine. The order below is deliberate.

  • Hour one, admin side. Turn passkeys on in your identity platform and decide whether you allow synced passkeys, device-bound passkeys, or both. Register your own passkey first and sign out and back in to confirm it works.
  • Hour two, the room. Get the team together for twenty minutes. Everyone creates a passkey on the device they use daily, then a second one on another device or a hardware key. Two is the minimum. One passkey is a lockout waiting to happen.
  • Hour three, the fallback. Confirm every person can still recover if they lose a phone. Then review who still has SMS codes enabled and plan to remove them for anyone with admin rights.
  • Before you leave. Write down which accounts are now passkey only, which still accept a password, and who owns the recovery process. That list is your Cyber Month deliverable.

Microsoft 365: what the docs say

Microsoft's how-to for enabling passkeys in Entra ID, last updated June 2026, states that passkeys "are available in all Microsoft Entra ID editions, including Microsoft Entra ID Free. No extra licenses are required." The path is Entra ID, then Security, then Authentication methods, then Policies, then Passkey (FIDO2).

Two details from that page matter for a small team. Microsoft now uses passkey profiles, so you can require device-bound passkeys for the owner and admins while letting sales and front desk staff use synced passkeys from Apple or Google. And users must have completed multi-factor authentication "within the past five minutes before they can register a passkey," so have everyone sign in fresh before the group session. Microsoft also says to "treat synced passkeys as phishing-resistant credentials but with the same security posture as other unattested authenticators." That's a fair caveat, not a reason to skip them.

Google Workspace: what the docs say

Google's admin page Allow users to skip passwords at sign-in, last updated October 1, 2026, puts the switch under Security, then Authentication, then Passwordless. Check the box labelled "Allow users to skip their password and authenticate with a passkey," then each user adds a passkey from their account's sign-in options.

Three things the page is explicit about. Turning this on "doesn't deactivate or remove the user's existing password." Users "don't need to be enrolled into 2-Step Verification" to use a passkey, and enrolling a passkey doesn't turn 2SV on either. And if you ever flip the setting to "Allow passkeys on hardware security keys only," any passkeys stored on phones or laptops stop working, so enrol the keys first. Monitoring who has actually enrolled is only available through the investigation tool on certain editions, so a shared spreadsheet may be your reporting tool.

On the device side, Google's account help lists Windows 10, macOS Ventura, ChromeOS 109, Android 9 and iOS 16 or later, with Chrome 109, Safari 16, Edge 109 or Firefox 122 and up. Apple, for its part, says "any Apple Account using iCloud Keychain requires two-factor authentication" and that the keychain is "end-to-end encrypted with strong cryptographic keys not known to Apple" in its passkey security note.

Why this matters for your AI tools too

If you've installed an AI phone agent, an AI inbox assistant, or any automation that reads your calendar and CRM, those systems log in with a service account or an owner's account. That account is now the most valuable login in the building. Everything your AI employee can see, an attacker holding its credentials can see. Put a device-bound passkey on the owner account that grants those integrations, and review the connected apps list on the same afternoon.

Where this doesn't apply

Be honest about the limits, because the standards bodies are.

NIST says syncable authenticators "SHALL NOT be used at AAL3," its highest assurance level, because the private key has to be exportable to sync. If you handle something that genuinely needs that bar, your admins need device-bound passkeys or hardware keys, not iCloud or Google Password Manager.

The Canadian Centre for Cyber Security warns that if a personal cloud account "has weak security or a weak authentication method itself, the passkey can be more easily obtained," and that relying parties can't easily tell a hardware-backed passkey from a cloud-synced one. A passkey synced to a staffer's personal Apple account is only as strong as that Apple account.

Passwords usually stay. Google says so outright, and the CCCS calls the leftover password a "residual risk." Passkeys shrink the attack surface. They don't remove it until you disable the fallback, and most small businesses can't do that on day one.

Shared devices and shared accounts don't fit well. A front desk tablet used by six people, a generic info@ mailbox, a point of sale terminal: these need a different design, often a hardware key kept in a drawer. Older computers without a secure enclave or TPM may not be able to hold a passkey at all, which the CCCS also flags.

And some of your vendors won't support passkeys yet. Your accounting platform, your supplier portal, your payroll provider. For those, the NCSC's advice stands: use a password manager and keep two-step verification on.

Sources

  • NIST, "Digital Identity Guidelines: Authentication and Authenticator Management," SP 800-63B Revision 4, 2025. https://pages.nist.gov/800-63-4/sp800-63b.html
  • FIDO Alliance, "Passkeys," accessed October 2026. https://fidoalliance.org/passkeys/
  • Microsoft Learn, "How to enable passkeys (FIDO2) in Microsoft Entra ID," updated June 2026. https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2
  • Google Workspace Help, "Allow users to skip passwords at sign-in," updated October 1, 2026. https://knowledge.workspace.google.com/admin/users/allow-users-to-skip-passwords-at-sign-in
  • Google Account Help, "Sign in with a passkey instead of a password," accessed October 2026. https://support.google.com/accounts/answer/13548313?hl=en
  • Apple Support, "About the security of passkeys," 2024. https://support.apple.com/en-ca/102195
  • Canadian Centre for Cyber Security, "Cyber security considerations for passkeys (ITSAP.30.033)," 2026. https://www.cyber.gc.ca/en/guidance/cyber-security-considerations-passkeys-itsap30033
  • Canadian Centre for Cyber Security, "National Cyber Threat Assessment 2025-2026," 2024. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026
  • Communications Security Establishment Canada, "Cyber Security Awareness Month 2025," 2025. https://www.canada.ca/en/communications-security/news/2025/10/cyber-security-awareness-month-2025.html
  • UK National Cyber Security Centre, "Leave passwords in the past: passkeys are the future," 2026. https://www.ncsc.gov.uk/sites/default/files/2026-06/NCSC-Leave-passwords-in-the-past---passkeys-are-the-future.pdf

If you'd like a second set of hands for that afternoon, or you want to make sure the accounts behind your AI employee are locked down properly, book a free call with Autana. We work with businesses across Burnaby, New Westminster and Metro Vancouver, and we're happy to walk through your setup before you touch a single setting.

passkeyscyber securityphishingMicrosoft 365Google WorkspaceBurnaby

Want an AI employee for your business?

We install a 24/7 AI worker for businesses in Vancouver, Burnaby, and beyond. Book a free Discovery Call.

Book a call →

Keep reading