For years, text-message verification codes have been a standard way businesses added another layer of protection to employee and customer accounts. You log in, receive a six-digit code, enter it, and move forward.
It was a major improvement over passwords alone. But in today’s threat environment, SMS-based two-factor authentication is no longer the strongest, or the simplest option.
That is why businesses are taking a closer look at passkeys.
The shift isn’t just about stronger security. It’s also about making authentication easier to manage, reducing login friction for employees, and giving businesses better control over who has access to their systems.
Why text-message codes are losing ground
SMS verification is still far better than having no multi-factor authentication at all. The problem is that it was not designed to stop some of today’s most common attacks.
Criminals can use phishing emails and convincing fake login pages to trick users into entering both a password and texted verification code.
They can also use SIM swapping, where an attacker tricks a mobile carrier into transferring someone’s phone number to a device they control. With personal information increasingly available through data breaches, phishing, and online sources, these attacks have become easier to carry out. Once an attacker controls the number, they can receive the victim’s calls and texted security codes.
The National Institute of Standards and Technology (NIST) notes that SMS and other out-of-band authentication methods are not phishing-resistant.
SMS also creates everyday friction: codes can arrive late, employees change numbers, mobile service is unavailable, or users simply must stop and retrieve a code.
What makes passkeys different?
A passkey is a safer, easier way to sign in without typing a password. Instead, you use something you already use to unlock your device, like Face ID, a fingerprint, or a PIN.
Passkeys also help protect against phishing. Because a passkey only works with the real website or application it was created for, it won’t work on a fake login page designed to steal your information.
For businesses, password managers can make passkeys much easier to manage. Instead of credentials being tied to individual employees, a business can centrally manage passwords and passkeys, control who has access, share credentials when needed, and remove access when someone leaves the company.
What we see businesses using
There are many password managers available, and we see different solutions depending on a company’s needs and environment.
Common options include Keeper, 1Password, Bitwarden, Dashlane, NordPass, Proton Pass, KeePass, and Password Safe.
The specific tool is only part of the decision. Businesses should consider who controls access, how credentials are securely shared, how quickly access can be removed, and whether passwords, passkeys, and authentication can be centrally managed.
That’s where a password manager fits into the bigger security picture: the business should control who has access to its accounts, not individual employees.
Where can businesses use passkeys?
Passkeys are becoming available across many of the tools businesses use every day, including Microsoft 365, OneDrive, Microsoft Entra ID, Google Workspace, and other business applications and online accounts.
You don’t have to switch everything at once. Start with the accounts that need the most protection and expand from there.
Faster Logins. Fewer IT Headaches.
Passkeys aren’t just more secure. They can also make signing in faster and easier for employees.
According to the FIDO Alliance’s 2025 Passkey Index, passkey sign-ins averaged 8.5 seconds, compared with 31.2 seconds for traditional methods like email verification and text codes. Passkeys also had a 93% sign-in success rate, compared with 63% for other methods.
Organizations using passkeys also reported 81% fewer login-related help-desk incidents.
For businesses, the benefit is simple: employees spend less time dealing with login problems, and IT spends less time fixing them.
The right role for SMS 2FA
This does not mean businesses should turn off SMS authentication overnight.
SMS-based 2FA can still serve as a fallback in some situations. But for privileged accounts, financial systems, business email, remote access, and other high-value resources, businesses should evaluate stronger options where available.
A practical transition includes enabling passkeys in supported systems, using authenticator apps or hardware security keys as appropriate backup options, keeping SMS where necessary, and giving employees clear guidance on the change.
A Smarter Way to Sign In
Passkeys make signing in easier for employees while giving businesses stronger protection against phishing and better control over access.
For companies still relying heavily on passwords and text-message codes, the transition doesn’t have to happen all at once. Start with the accounts that matter most, put the right tools in place, and build from there.
BNC helps Dallas businesses evaluate their current security and authentication setup and create a practical plan for making access simpler and more secure.