Week 2 · Friday
Password managers, multifactor authentication, and passkeys
Understand three ways to protect business sign-ins, choose a practical first improvement, and plan how to recover access if a device is lost.
You now know which accounts your business depends on and who should have access. The next step is protecting those sign-ins.
Three terms come up often: password manager, multifactor authentication, and passkey. They solve related problems, but they are not interchangeable.
You do not have to rebuild every account today. Understand the choices, improve one important account carefully, and make sure you can recover access.
A password manager helps you use different passwords
A password manager stores passwords in a protected collection often called a vault. It can also generate long, random passwords, so you do not have to invent or remember a different one for every service.
Using a unique password for each account limits the damage if one password is exposed. A password taken from one service should not also open your business email.
Protect the manager itself. Use a strong, unique master password if it requires one, enable its supported additional protection, and understand its recovery process. The FTC describes password managers as a way to create and remember strong passwords. FTC: Creating strong passwords.
For a team, check whether the manager supports business administration and controlled sharing. Employees should not need the owner's entire vault to access one business tool.
A password manager cannot guarantee that every service is safe. Its practical benefit is making good password habits easier to maintain.
Multifactor authentication adds another kind of proof
Authentication means checking that someone signing in is who they claim to be.
Multifactor authentication, or MFA, uses more than one kind of proof. You might know a password and also have a device or security key. Two passwords are still the same kind of proof.
You may see settings called "two-factor authentication" or "two-step verification." Available methods differ by service.
An authenticator app can generate a short-lived code or ask you to approve a sign-in. A security key is a physical device used to prove access. Text message codes are another option.
The FTC recommends using an authenticator app or security key when available, while noting that text or email codes are better than having no second factor. FTC: Two-factor authentication.
Treat unexpected approval requests as a warning
Suppose your phone asks you to approve a business email sign-in while you are serving a customer. You have not tried to sign in.
Deny the request. Open the service through your usual trusted app or saved address to check your account, and contact the person who manages it if you need help. Do not approve repeated prompts just to make them stop.
Also keep verification codes private. Someone who calls claiming to be support should not get the code that would let them into your account.
An MFA prompt needs your judgment. Approving an attempt you did not start can defeat the protection it was meant to provide.
A passkey works differently from a password
A passkey is a digital credential that uses cryptography, a mathematical way to prove access. It is commonly unlocked with your device PIN, fingerprint, or face recognition.
Passkeys are tied to the intended website or service. That helps resist a fake sign-in page trying to steal a reusable secret. Some passkeys sync through a credential provider; others stay on a particular device or security key. FIDO Alliance: Passkeys.
The familiar unlock gesture is not the credential being sent to the website. For example, Google explains that the biometric information used to unlock a passkey stays on the device. A passkey can also satisfy its second authentication step, so you may not see a separate code prompt. Google: Signing in with a passkey.
Availability and recovery vary. For business accounts, confirm where passkeys are stored and how the business manages access when a device or employee changes.
Match the tool to the job
| Tool | What it helps with | What to check |
|---|---|---|
| Password manager | Creating and storing unique passwords | Vault protection, business access, and recovery |
| MFA | Requiring another kind of proof | Supported methods and unexpected prompts |
| Passkey | Signing in without typing a reusable password | Device protection, storage, and recovery |
These are not three mandatory steps for every sign-in. A supported passkey may replace both a password and a separate verification step. Other services may still require a password plus MFA.
Plan for a lost phone before it happens
Picture the phone you use for sign-ins becoming unavailable during a busy workday. What is your authorized way back in?
Depending on the provider, the answer might involve a registered spare security key, recovery codes, another authorized administrator, or a documented support process.
Recovery codes are sensitive credentials that some services provide for regaining access. Store them securely, with access limited to authorized people. Avoid keeping the only recovery method inside the account or device it is meant to recover. Follow the service's instructions, including whether codes can be used only once.
The right method depends on your setup. Write down the process and where authorized people can find what they need, without putting the secrets themselves in your shared technology inventory.
A fifteen-minute exercise: improve one account
Start by reviewing an important account, such as business email, with its administrator.
- Open its official security settings through a trusted route.
- Check whether its password is unique and how it is stored.
- Review available MFA or passkey options.
- Confirm a supported recovery method before changing the sign-in setup.
- Test the new method successfully before removing a working alternative.
If setup will take longer, use the time to document the next step and who will help. Protecting access includes making sure the business can still use it.
Your takeaway: Use unique passwords where needed, strengthen sign-ins with supported protection, and plan how authorized people will recover access.
Test your knowledge
Ready to put this week's learning into practice? The EdwardsCG learning portal has an eight-question knowledge check covering account control, personal and business separation, and safer sign-ins.
Choose this week's check, or try the cumulative option covering Weeks 1 and 2. The cumulative check selects one question from each article, for six questions in total. Each answer includes an explanation to reinforce the lesson.
Follow the Small Business Learning Series for new articles on Monday, Wednesday, and Friday at 1 p.m. Eastern.