Microsoft is setting a timeline for enterprises to phase out SMS-based authentication.
According to official Microsoft Entra ID documentation, Microsoft-provided SMS and voice authentication services will be retired for most users on February 1, 2027, while Global Administrators and external users will have until July 1, 2027. Microsoft recommends that organizations migrate in advance to phishing-resistant authentication methods such as passkeys and Windows Hello for Business to avoid login disruptions. Organizations with specific requirements can also configure customer-managed telecommunications providers to continue using SMS or voice authentication.
Passkeys can be stored on a phone or on a separate physical security key. With the former, users typically authenticate using fingerprint or facial recognition on the phone; with the latter, authentication requires a separate hardware device.
So how should users choose between the two?
Our view is simple: a passkey on your phone is well suited to everyday sign-ins. For accounts connected to funds, sensitive information, or enterprise privileges, it is worth considering adding a separate physical security key as well. The key questions are where your login credentials are stored and whether you still have another reliable way to access your account if your primary device is lost or unavailable.
Regardless of which option you choose, passkeys are becoming an increasingly important way to sign in to online accounts. So how are they different from the passwords and SMS verification codes we are familiar with?
Verification Codes Can Be Relayed. Passkeys Verify the Website.
Imagine this scenario.
Mark receives an email claiming that his corporate email account is about to be deactivated. He clicks the link, and the logo, layout, and login form all look familiar. He enters his password, then types in the verification code that has just arrived on his phone, believing that he has completed a secure authentication process.
But if the page is a phishing site, an attacker may be able to relay the password and verification code he enters to the legitimate website in real time. The code was indeed sent to Mark’s phone, but the person completing the login may be someone else.
The problem is that Mark has to determine for himself whether the website is genuine, while the verification code can be copied and relayed.

(An attacker relays authentication information through a fake website in real time to steal the user’s login session. Image source: Microsoft Security Blog.)
Passkeys change this process. They use cryptographic credentials associated with a specific website, and authentication is completed jointly by the browser, operating system, and authenticator. Even if a fake website looks identical to the real one, a site with a different domain cannot directly use the legitimate site’s passkey to authenticate.
Whether the passkey is stored on a phone or on a FIDO2 physical security key, the shared value is the same: they reduce the extent to which account security depends on users successfully recognizing a fake website every single time.
They Are All Called Passkeys, but the Credentials May Be Stored in Different Places
Using a fingerprint or facial recognition to sign in on a phone may look like the same action every time, but the passkey behind it can be stored in different ways. Depending on whether credentials can be synchronized across devices, passkeys can generally be divided into synced passkeys and device-bound passkeys.
Synced Passkeys: Switch Devices and Keep Using Them
These passkeys are encrypted and synchronized across supported devices through a credential management service. Common examples include passkeys stored in Apple iCloud Keychain, Google Password Manager, and 1Password.
For example, Mark creates a passkey on his iPhone and saves it to iCloud Keychain. Once synchronization is enabled, he can also use that passkey on a Mac signed in to the same Apple account, without creating a new passkey specifically for that computer. If he replaces his phone, he can usually continue using the synchronized passkey as long as he can restore access to the relevant account and satisfy the required verification steps.
Device-Bound Passkeys: The Credential Stays on the Device Where It Was Created
The private key for this type of passkey is not synchronized to other devices. Passkeys stored on FIDO2 physical security keys fall into this category. Phones can also store device-bound passkeys—for example, credentials created by Microsoft Authenticator for work or school accounts.
If Mark stores a passkey on a physical security key, he will need to use that key whenever he signs in on a compatible computer or phone. The credential remains on the security key and is not copied simply because he signs in from another device. If the key is lost, he will need to regain access through another sign-in method registered in advance or through the account recovery process.
So it is not accurate to reduce the distinction to “passkeys on phones sync, while passkeys on hardware stay local.” What really matters is where you choose to store the passkey when it is created, and whether that storage method supports synchronization. This also determines how you will regain access when you change or lose a device.
For ordinary users, two questions are especially useful:
|
Question to Ask |
Why It Matters |
|
Does my passkey sync? If so, which service synchronizes it? |
This determines how you continue using it after changing devices, and which credential-management account you need to protect. |
|
If my phone is unavailable, damaged, or lost, how else can I sign in? |
This determines whether a single device failure could turn into a loss of account access. |
Synchronization provides convenience. Separate hardware provides another way to store credentials. The right choice depends on your own usage habits and recovery requirements.
The Value of a Physical Security Key Is Having an Independent Sign-In Path
Consider another scenario involving Mark.
He uses Gmail every day for email, Google Drive for files, and Google Photos for photo backups. All of these services are tied to the same Google account. Because his phone and computer normally remain signed in, he rarely has to think about what would happen if neither device were available.
Now suppose his bag containing both his phone and laptop is lost during a business trip. He can buy a new computer and phone, but he cannot use the passkeys stored on the original devices or approve sign-ins on them. At that point, whether he can regain access depends on which backup sign-in methods he prepared in advance.
Google allows users to create account passkeys on FIDO2 physical security keys. If Mark had already registered one and stored it separately from his phone and computer, he could use a compatible backup computer, choose to authenticate with the security key, connect it as prompted, verify his identity using the key’s PIN or fingerprint, and sign in to his Google account. He would not need to recover his old phone first or wait for a cloud-stored passkey to synchronize to the backup computer.
Multi-device synchronization makes everyday sign-in more convenient. A physical security key gives you an additional independent and fast sign-in path when your usual devices are unavailable.
One important detail is easy to overlook: a security key must be registered with the relevant account in advance. Simply buying one and putting it in a drawer does not automatically make it a backup key for all of your accounts.
This setup is particularly worth considering for several types of accounts:
-
Primary email accounts: They are often also the recovery channel for other accounts.
-
Accounts connected to funds or sensitive information: Losing access can be much more costly.
-
Enterprise administrator accounts: In addition to individual convenience, organizations need to consider issuance, revocation, and recovery requirements.
“Adding another key” usually means adding another available sign-in method. It does not necessarily mean that you must use both your phone and the security key every time you sign in. Whether a specific authentication method is required depends on the service configuration and enterprise policy.
Microsoft Entra, for example, allows administrators to configure passkey types, authenticator restrictions, and related policies by user group. Before purchasing hardware at scale, organizations should first confirm these policies and then test the registration and sign-in process.
Independent Storage Also Means You Need a Serious Backup Plan
A physical security key can work independently of your phone, but it can also be lost or damaged. Whether it truly provides value depends on whether you have planned the recovery process properly.
For important accounts, we recommend registering both a primary and a backup security key when the service allows it, storing them separately, and actually testing that the backup key can sign in successfully. The two keys are separately registered credentials; one is not an automatically duplicated copy of the other.
If you use only one security key, you should still confirm which recovery options the service provides and whether you have already configured them. Do not wait until the device is lost before reading the recovery instructions for the first time.
At the same time, passkeys primarily protect the authentication step. They cannot evaluate every transaction for you, stop every malicious action performed by malware after a user is already signed in, or guarantee that the account recovery process itself will never become a weak point. Important accounts still require trusted devices, appropriate permissions, and securely stored recovery information.
Why Consider imKey Pass S6?

https://shop.imkey.im/shop?id=46cfbbe1-60fd-46cc-a557-4c9d44399b20&locale=en-us
If you want an additional sign-in path for important accounts outside of your phone, imKey Pass S6 is one option to consider. It is a physical security key with a USB-C interface that supports FIDO2/U2F and local fingerprint verification.
Keep Using Your Phone Every Day, With Another Option Available When You Need It
You do not need to change the sign-in method you already use. On services that support multiple authentication methods, you can continue using a passkey on your phone while also registering imKey Pass S6 in advance. If you later need to sign in on another compatible device, or if your usual phone is temporarily unavailable, the security key can provide another option.
Change Your Phone Without Losing the Credentials Stored on the Security Key
Authentication private keys stored on imKey Pass S6 remain inside the hardware. They do not migrate when you change phones, nor do they need to be synchronized to a new device through the cloud. As long as the credential registered with your account remains valid and the device and service are compatible, you can continue using the security key for authentication.
For important accounts that you expect to use over the long term, this means one less thing to reconfigure when you replace your phone.
Local Fingerprint Verification Makes Independent Credential Storage Convenient to Use
In supported sign-in flows, after connecting imKey Pass S6, you can verify your identity with your fingerprint as prompted. The fingerprint template is stored on the device and is not uploaded to the website or cloud. The private key used for authentication also remains inside the hardware. The website verifies the authentication result generated by the security key—it does not receive your fingerprint.
These characteristics make imKey Pass S6 suitable as either a primary security key for important accounts or a backup key. But a backup path has to be prepared in advance: register the key with the account, test the sign-in process at least once, and store the backup key separately from your everyday devices.
Individual users should confirm that their commonly used services support the relevant authentication method and that their device interfaces are compatible before purchasing. Organizations using Microsoft Entra should also run a pilot based on their authentication policies and security-key restrictions.
Ultimately, choosing a security key is about ensuring that important accounts are both well protected and still accessible when you need them.
Important Accounts Should Keep Others Out—and Make Sure You Can Still Get Back In
Microsoft’s migration plan is a useful reminder to re-examine the sign-in methods we use every day.
If you still rely on passwords and SMS verification codes, start by checking whether the services you use support passkeys. If you already use passkeys on your phone, the next question is worth asking: if your phone becomes unavailable, can you still sign in?
For everyday sign-ins, you can prioritize the convenience of a phone-based passkey. For important accounts, it is worth preparing an additional independent and tested access path. The value of a physical security key is that this path can be something you personally hold, manage, and prepare in advance.
Frequently Asked Questions
Q1: What is the difference between a passkey on a phone and a physical security key (FIDO2)?
Answer: The main difference is where the credential is stored and how—or whether—it is synchronized:
-
Phone-based passkeys (for example, those stored in Apple iCloud Keychain or Google Password Manager) are often synced credentials. They can be encrypted and synchronized across multiple devices signed in to the same account, making them convenient to use.
-
Physical security keys (such as imKey Pass S6) use device-bound credentials. The private key remains inside the independent hardware device and is not synchronized or migrated through the cloud. This provides an authentication path independent of your phone and cloud credential service.
Q2: If my phone is lost or damaged, can I recover the passkeys stored on it?
Answer: If the passkey is a synced passkey, you can generally regain access after signing in to the same cloud-service account—such as your Apple ID or Google account—on a new phone. If it is a device-bound passkey, such as a credential created by Microsoft Authenticator for a work account, it cannot be restored across devices. You will need to rely on a backup physical security key registered in advance or use an administrator or account recovery process to regain access.
Q3: After I buy a physical security key, do I have to plug it into my computer or phone every time I sign in?
Answer: No. Whether the physical security key is required depends on the specific application, service, or enterprise policy, such as Microsoft Entra rules. In everyday use, you can continue using a phone-based passkey as your primary sign-in method and use the physical security key only when your phone is unavailable, when you are using a new device, or when you are signing in to a high-risk or critical account.
Q4: What happens if I lose my physical security key?
Answer: Losing the security key does not automatically expose the credential stored on it, because the private key is protected by the hardware and by local fingerprint/PIN verification. To avoid being locked out of your account if the key is lost, we recommend registering both a primary and a backup security key for important accounts and storing them separately. Alternatively, confirm in advance that the service provides another reliable account recovery method.
“Mark” is a fictional character used in this article to illustrate common scenarios.
Notes: Supporting Sources and Further Reading
-
Microsoft: Passkey Default Experience and Retirement of Microsoft-Provided SMS/Voice Authentication
Used to verify which users are affected, the migration timeline, and alternative telecommunications options. Policies may change, so organizations should review the latest documentation before deployment. -
Microsoft: Enable Passkeys (FIDO2) in Entra ID
Covers organizational policies, passkey types, and authenticator restrictions. -
FIDO Alliance: Passkeys
Explains passkeys, synced credentials, and device-bound credentials. -
imKey Pass S6 Product Information
Used to verify product interfaces, authentication methods, and claims about hardware-based credential storage. -
imKey Pass S6 Frequently Asked Questions
Covers usage, backup devices, loss scenarios, and reset precautions.















