All Articles

One Identity, Zero Passwords: The Sign-In Setup Every SEQ Business Should Copy

Michael Jordison Michael Jordison
·

You turned on multi-factor authentication, so you feel covered. Here’s the uncomfortable bit: the attacker who wants into your business was counting on you doing exactly that, and the type of MFA most firms switched on does almost nothing to stop them.

In 2023 and 2024, the busiest attack against Australian small businesses wasn’t some zero-day exploit. It was a fake login page. The staff member typed their password, tapped “approve” on their phone like they’d been trained to, and handed the whole session to a criminal sitting in the middle. MFA was on the entire time. It didn’t matter.

If your sign-in still involves a password and a tap, you’re protecting against the threats of 2015. Let’s fix that.

Why your current MFA is weaker than you think

Not all MFA is equal, and the gap between the weak kind and the strong kind is enormous.

  • SMS codes: trivial to phish, and vulnerable to SIM swapping. A code you can read aloud is a code you can be tricked into giving away. The ACSC has been telling people to move off SMS for years.
  • Push approvals (“tap to approve”): killed the old “MFA fatigue” spam problem once Microsoft added number matching, but they do not stop a phishing site. The user still enters credentials on a fake page and still approves the prompt, because as far as they can tell, the login looks real.
  • One-time codes from an app: better than SMS, still phishable. The six digits go into the fake page right alongside the password.

The technique tying all of these together is adversary-in-the-middle (AITM) phishing. Off-the-shelf kits like Evilginx, EvilProxy and Tycoon 2FA sit between your staff member and the real Microsoft login, relay everything in real time, and walk away with the session token, the thing that says “this person is already logged in.” Once they have it, they don’t need the password or the MFA prompt again. We wrote about how that token theft works and how to defend it in Microsoft just made Token Protection more affordable.

The point: “we have MFA” is no longer the same sentence as “we’re protected from phishing.”

What actually stops phishing: passkeys

There is exactly one category of authentication that defeats this by design, and it’s phishing-resistant MFA. The most practical version for a small business is a passkey.

A passkey is built on FIDO2 and WebAuthn, which is a mouthful, so here’s what it means in plain terms. Instead of a shared secret you type in, your device holds a private cryptographic key that never leaves it. When you sign in, your browser checks the exact web address you’re on and only releases the credential to the genuine domain. There is nothing to type, nothing to read aloud, and nothing to paste into a lookalike page.

That last part is the whole game. A passkey simply will not work on a fake site, because the fake site has the wrong address and the browser refuses to play. The AITM kit that beats SMS and push approvals hits a brick wall. There’s no password to relay and no code to steal, so there’s nothing for the criminal to sit in the middle of.

You also stop typing passwords entirely. You unlock with the fingerprint or PIN already on your phone, and you’re in. Faster for your staff, and unphishable. That’s the rare security upgrade that people actually thank you for.

Device-bound versus synced: why device-bound wins for business

Here’s where most “just use passkeys” advice gets lazy, because there are two kinds and they are not equally suited to a business.

  • Synced passkeys live in a consumer cloud, like Apple’s iCloud Keychain or Google Password Manager, and copy themselves across all of a person’s devices. Convenient for your personal Netflix login. For a business, it means your work credential is now duplicated across a staff member’s personal phone, personal laptop and personal cloud account, governed by their personal password, outside anything you control.
  • Device-bound passkeys never leave the single device they were created on. The private key is generated on that phone and stays there, full stop. Nothing syncs to a personal cloud. If you want access from another device, you enrol another device deliberately.

For a regulated SE QLD business handling client data, device-bound is the stronger choice. You get higher assurance about where the credential actually lives, and you remove the “it copied itself to a personal iCloud account I’ve never seen” problem. This matters for your obligations under the Privacy Act, and it matters when a cyber insurer or an auditor asks you to demonstrate control over how staff authenticate.

Why Microsoft Authenticator passkeys are the sweet spot

You can buy hardware security keys, and they’re excellent. But for most small businesses the practical answer is sitting in a free app your staff already have on their phones: Microsoft Authenticator now stores device-bound passkeys.

This is the combination that’s hard to beat:

  • Phishing-resistant by design, because it’s a FIDO2 passkey doing the same unphishable thing a hardware key does.
  • Device-bound, because the passkey stays in Authenticator on that one phone and does not sync off to a consumer cloud.
  • You almost certainly already pay for it. If you run Microsoft 365 Business Premium, you’ve got Entra ID P1, Conditional Access and the full passkey capability already in your licence. No new product, no new line item.
  • No extra hardware to buy, lose or post out to the staff member working from the Gold Coast office two days a week.

You’re not adding a tool. You’re switching on something you’re already funding, and replacing the weakest part of your security with one of the strongest.

The perfect complement: Windows Hello on compliant devices

The passkey in Authenticator covers the phone in your pocket. The other device your staff use all day is the work computer in front of them, and that’s where Windows Hello for Business comes in.

Windows Hello is built on the same phishing-resistant FIDO2 foundation as a passkey, except the credential is tied to that specific PC through its hardware security chip (the TPM). Your staff member signs in to the machine with their face, fingerprint or PIN, and that unlock flows straight through to Microsoft 365 and everything behind it. No password, and the same “won’t work on a fake site” protection you get from the phone passkey.

Pair that with a device compliance rule, where only a company-managed, encrypted, up-to-date PC is allowed to reach your data, and you’ve closed the loop. The login is unphishable and the thing it’s logging in from is verified as one of yours. Phone passkey plus Windows Hello on a compliant device is the combination we put on most client setups: one strong, passwordless sign-in whether they’re at the desk or on the move.

Where Essential Eight fits

Multi-factor authentication is one of the eight mitigation strategies in the ACSC’s Essential Eight, and the bar has moved. The framework now explicitly calls for phishing-resistant MFA at the higher maturity levels for people signing in to important systems. SMS codes and ordinary push approvals do not meet that bar. Passkeys do.

So this isn’t only a security upgrade, it’s a compliance one. If you’re working toward Essential Eight Maturity Level 2 or beyond, or you’re being asked about it by a tender, an insurer or a larger client, phishing-resistant passkeys are exactly the kind of control that answers the question properly instead of with a box-tick. If Essential Eight is new to you, start with Essential Eight Level One, explained for small firms.

One identity for everything

Strong sign-in is only half the win. The other half is making sure there’s only one front door.

The goal is simple: every system your staff use sits behind a single Entra ID identity, reached with one passkey. Microsoft 365, your line-of-business apps, your file storage, your finance tools, the lot, all signed into through one identity using single sign-on. Your staff member unlocks once with a passkey and everything opens. No password sticky notes, no twelve different logins, no shadow accounts on random web apps that nobody remembers.

Two things get dramatically better the moment you do this:

  • Onboarding and offboarding become one switch. When someone joins, you grant the identity. When someone leaves, you disable that one identity and every connected system slams shut at once. No frantic checklist of fourteen separate accounts to chase down while a former employee still has access. We covered building that process in the golden onboarding process for remote and BYOD teams.
  • You can see and control everything from one place. One identity means one set of access logs, one set of Conditional Access rules, one place to enforce that only a phishing-resistant passkey gets you in.

This is the part that turns “we use strong logins” into an actual security posture. The strength of the passkey plus the discipline of one identity is the setup. While we’re here, if anyone on your team still thinks modern MFA is annoying, point them at why MFA fatigue is dead.

What you should do this month

  1. Find out what kind of MFA you’re actually on. If the honest answer is SMS codes or plain push approvals, treat that as a gap to close, not a job done.
  2. Confirm your licensing. If you’re on Microsoft 365 Business Premium, you already have everything you need for passkeys and Conditional Access. Most SE QLD businesses are sitting on this and not using it.
  3. Roll out device-bound passkeys in Microsoft Authenticator, starting with the people who have the most access: directors, finance, and anyone who can move money or touch client data.
  4. Set a Conditional Access policy that requires phishing-resistant authentication for those important sign-ins, so a weaker method can’t quietly creep back in.
  5. Consolidate the rest of your apps behind single sign-on so there’s one identity to protect and one identity to switch off when someone leaves.

You don’t need a bigger budget for this. You need to switch on the strong version of what you’re already paying for, and stop running the weak version next to it.

If you’re not sure where your sign-in actually stands today, that’s a fair question to ask out loud. No sales pitch, just a straight answer. Passwordless identity and phishing-resistant MFA are standard on every Novaguard managed cyber security plan, not an add-on you have to ask for.

Michael Jordison

Want to know where you are actually exposed?

A Cyber Business Review tells you what an attacker would find first and what to fix in what order. Independent, and no switch required.

More on this: Cybersecurity articles · Managed Cybersecurity