During the MS EMS Summit we sat down with a group of people for CloudHour. A good conversation, with several different angles, about passkeys and MFA more broadly. But watching that conversation turn technical, right there in the room, it struck me how fast we ended up in the technical corner. Software versus hardware bound passkeys, phishing resistant MFA, the path to safer authentication.
All relevant. All worth discussing. But what we, as tech people, tend to forget: the end user is, for a large part, still stuck on username, password and MFA via SMS or that familiar six digit code. In some regions the Authenticator app already comes baked in for the user, in plenty of others it still doesn’t. While we’re talking about device binding and phishing resistance, the user is logging in with the exact same flow as five years ago.
Still in that conversation, I asked myself a question that stuck. What if there’s also a what’s in it for me, a WIIFM, for that user?
We talk tech, the user talks about hassle
That’s the core of why this discussion sometimes feels weird. We, as security people, weigh up risk and technology: how resistant a method is to phishing, how strong the proof of identity needs to be, how tightly an account is bound to one device. The user weighs something completely different. Do I have to learn something new again, what happens if I lose my phone, and why would I bother if password plus SMS works just fine.
That’s not stubbornness. Research across nine major passkey providers in 2025 found that on average 93 percent of accounts were already eligible for a passkey, but only 36 percent had actually registered one, and just under 26 percent of all logins actually went through a passkey. The technology is there. Adoption is lagging way behind it.
And that’s exactly where the WIIFM comes in, the what’s-in-it-for-me of the end user, not the organization. The strongest reason to switch isn’t “you’re now better protected”. That feels abstract and far away to a user. The strongest reason is: it’s faster, it succeeds more often on the first try, and you can’t accidentally hand your password to a fake website. FIDO’s own numbers show what that means for the user in concrete terms. 8.5 seconds for a passkey login versus 31.2 seconds for the traditional route, and a 93 percent success rate versus 63 percent. Microsoft sees similar gaps for consumer accounts: 98 percent successful sign-ins with a passkey versus 32 percent with a password, eight times faster.
That’s the story that convinces a user. Not the story we discussed at CloudHour.
Why people don’t automatically pick the safest option
Here’s the part that’s less technically exciting, and exactly why I want to bring it up anyway: psychology. People weigh a small effort they feel right now against a risk that only shows up much later, and uncertainly at that. An extra registration step costs time and attention immediately. Phishing resistance might never visibly pay off, until the moment it does.
A few mechanisms play into that: security fatigue, where people are simply worn out by every new security measure. Loss aversion and recovery anxiety, the fear of losing access to your account if your phone breaks or goes missing, which weighs heavier than an abstract phishing risk. And status quo bias: people trust the password flow they’ve known for twenty years, and experience a new workflow as more complex, even when it objectively isn’t.
The conclusion that follows is an uncomfortable one for our field. More awareness training doesn’t fix this. A bad recovery flow stays bad after a webinar. What does work is a good default, a credible recovery path, and a user who notices the benefit the first time, instead of just the hassle.
Security that fits, not security that fights
That’s become the core of it for me. Not “How do we convince the user to do something extra for security?” Instead, “How do we make sure the safe route also happens to be the easiest route, so the user picks it because it works better, not because he has to?”
Concretely, that means the safe method as the default, not something to opt into. Registration at the moment the user is already in the flow, not a separate task he has to plan for. One clear success experience instead of an unclear transition period. And a recovery path that explains what happens if you lose your phone, before the user has to ask that question himself.
And this is where it actually gets hopeful. Jan Bakker recently wrote about a number of changes Microsoft is rolling out in how Entra guides users towards a passkey, and it lines up exactly with what I mean above. Where a user previously had to register a weaker method first before he could add a passkey, that requirement disappears in phases starting this October, with Windows Hello, macOS SSO and Authenticator following early next year as the last step. Where registration used to end in a failed attempt because the offered type didn’t match the organization’s policy, that’s already been fixed. Since late August, registration lines up better with that policy, and a passkey that’s already local to the user’s device gets priority. None of these are new security measures. They’re pieces of friction disappearing, right at the moment a user first encounters passwordless.
Put that next to the change I mentioned earlier. Starting September 1st, 2026, Microsoft automatically turns on a passkey profile for everyone currently using SMS or voice, with a non mandatory prompt to register one. From February 1st, 2027, that prompt becomes mandatory for anyone without another method: you’ll need to register a passkey to keep signing in. Here too, the default is shifting, not the question to the user.
Where things stand now
The technology for passwordless and phishing resistant MFA is ready. That was never really up for debate at CloudHour either. What isn’t ready yet is how we offer that technology. As long as we keep the conversation in the technical corner, passwordless stays a security project instead of an improvement people actually want.
So the question isn’t whether passkeys are technically better. The question is whether we offer them in a way that makes users never want to go back.
Thanks for reading, if you made it this far. It’s not the flashiest topic, but I’m convinced this approach is what drives real adoption.
Resources
Passkeys by default and retirement of Microsoft-provided SMS and voice authentication


