Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Passwordless Is a Productivity Win, Not Just Security

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.

The short version: In 2018, Microsoft started pushing businesses toward signing in without passwords, using phones, fingerprints and security keys instead. It is now one of the few security changes that both improves protection and makes life easier for employees.

Why passwordless is a business case, not just a security one

Passwords cost money: help desk resets, lost productivity from lockouts, and the fallout when they are stolen. Passwordless methods are faster to use and much harder to phish.

The business impact

  • Fewer help desk calls for password resets.
  • Faster sign-ins, especially on mobile and shared devices.
  • Stronger protection against phishing kits that defeat traditional MFA.
  • Insurance and compliance: phishing-resistant authentication is increasingly expected for administrators.

Questions to ask your team

  • What percentage of our users could sign in without a password today?
  • What do password resets cost us each year in help desk time?
  • Which applications still require passwords, and what is the plan for them?
  • What is the cost of security keys for our highest-risk users?

What good looks like

A phased plan: administrators first, then high-risk roles, then everyone else, with progress measured monthly and legacy applications retired or wrapped over time.

The decision

Approve a passwordless pilot for IT and one business unit this quarter. Measure user satisfaction and help desk calls; the results usually make the case for broader rollout on their own.

microsoft passwordless impactIgnite 2018 passwordless2018

More on this story