top of page

MFA ... uhm... Two way ... Password .. Passkey


Your passkey only works once the old locks come off

Plenty of organisations switch passkeys on and think they are done.

They are not done. They have added one more lock.


What makes a passkey different

A passkey is not a code you retype. It is a key pair. The private half never leaves your device.

That is why it is phishing-resistant. There is nothing to intercept. Nothing to talk someone out of over the phone. Nothing to copy out of a text message.

That is the whole point.


What the older methods still let through

The methods most organisations still have switched on do not offer that protection:

  • SMS and email codes. Interceptable through SIM swap. Discouraged for years now.

  • TOTP apps. Better, but the code can still be retyped on a fake site.

  • Push notifications. Vulnerable to MFA fatigue. Push long enough and someone taps approve.

  • Shortcuts such as Lightning Login. Convenience that skips a verification step.

  • Security questions. Enough has been said about those on LinkedIn.


The real mistake

The mistake is not that these methods exist. The mistake is leaving them standing next to your passkey.

An attacker does not pick your strongest route. He picks the weakest one you leave open. Your security is only as good as your softest option.

And this goes beyond security. Old and new methods clash technically. Your user gets the wrong prompt, or no prompt at all, and cannot get in. That costs your service desk more time than the entire migration.


What to actually do

  1. Take inventory. Which verification methods are active right now? Per user, not per profile.

  2. Roll out passkeys. Start with admins and the users holding the most permissions.

  3. Put passkeys at the highest assurance level. Otherwise they count for no more than a text message.

  4. Switch the weak methods off. SMS first. Shortcuts next.

  5. Sort out your recovery route. What happens when someone loses their phone? Write it down before it happens.

  6. Make sure you have two admins. Always. An organisation with one admin does not have security, it has a single point of failure.

The order decides whether it works

Most migrations fail at step 4. People switch passkeys on, do not dare switch the old methods off, and keep both worlds running for months.

That is the worst of both. All the complexity, none of the added security.

Pick a date. Communicate it. Switch them off.


Why we are writing this

At CRMSolver B.V. this is not a loose technical job. This is governance.

Our certified talent is directly deployable at clients in the Netherlands, the US, Suriname and the Caribbean.

Your partner that helps you grow while making a difference.

 
 
 

Comments


Virtual Salesforce Assistance  

With the Virtual Salesforce Assistant from CRMSolver, you get the right support exactly when you need it.

© 2026 by CRMSolver b.v

Address:

CRM Solver BV

The Extra Mile Community

Hessenbergweg 8, 
1101BT, Amsterdam

E-mail:

Phone:

+31 203086850

Kvk:


74329405 – BTW: NL859857840B01

dit is de Salesforce Partner logo
This is a logo
  • Instagram
  • Twitter
  • LinkedIn
bottom of page