Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
FIDO2 keys versus passkeys is the multi-factor question Canadian buyers ask most in 2026. Microsoft’s own Entra documentation reports that 99 percent of users register synced passkeys successfully and sign in 14 times faster than a password plus traditional MFA. Adversary-in-the-Middle phishing defeats the codes those users are replacing, every week, in Canadian inboxes.
This guide sits under the multi-factor authentication for Canadian businesses pillar. It compares hardware FIDO2 keys against synced passkeys, maps both to the NIST AAL2 and AAL3 lines, prices them in CAD, and walks the Two-Track rollout we run in client tenants.
Key Takeaways
- 99 percent register successfully. Microsoft reports 99 percent registration success on synced passkeys, sign-in 14 times faster than password plus MFA, and a 95 versus 30 percent success rate, from consumer Microsoft accounts (Microsoft Entra documentation, 2026).
- NIST splits them at the assurance level. SP 800-63B-4, final July 31, 2025, says syncable authenticators SHALL NOT be used at AAL3, because the key is exportable (NIST SP 800-63B-4).
- The Cyber Centre wants it on every account. Its October 2025 adversary-in-the-middle guidance says to deploy phishing-resistant MFA to every user, without exception.
- The Canadian price trap is currency. Yubico lists the YubiKey 5 NFC and 5C NFC at USD 58 and the FIPS 140-3 versions at USD 88, in US dollars even on its Canadian store page.
- The Fusion Two-Track pattern. Roughly 8 percent of headcount on hardware keys at AAL3, the other 92 percent on synced passkeys at AAL2, split by Entra conditional access.
Get a FIDO2 + Passkey Readiness Review
What is the difference between FIDO2 keys and passkeys?
According to the FIDO Alliance (2026), synced passkeys are “passkeys that are synced between user’s devices via a cloud service” and device-bound passkeys are “those that never leave a single device”. The Alliance also confirms that FIDO security keys have housed device-bound passkeys since 2019, which is why the categories overlap.
FIDO2 is the open standard behind hardware security keys and the WebAuthn browser API. A passkey is a credential built on that standard, held either on a hardware key or synced through an Apple, Google, or Microsoft account. Hardware FIDO2 keys are passkeys. Not every passkey is a hardware key.
One 2026 spec-sheet note: WebAuthn Level 2 is still the current W3C Recommendation, and Web Authentication Level 3 sat at Candidate Recommendation on May 26, 2026. A vendor claim of “Level 3 support” describes a draft.
| Term | What it is | Where the private key lives | AAL ceiling |
|---|---|---|---|
| FIDO2 | Open standard from the FIDO Alliance and W3C | n/a (specification) | supports AAL2 and AAL3 |
| WebAuthn | Browser API that lets web apps invoke FIDO2 credentials | n/a (API) | delivery layer |
| Hardware FIDO2 key | USB or NFC token; key generated and held on the token | the token, non-exportable | AAL3 |
| Synced passkey | Credential synced via iCloud Keychain, Google Password Manager, or a Microsoft account | synced to a cloud provider | AAL2 |
| Device-bound passkey | Credential created on one device that never leaves it | that device only | AAL3 if hardware-protected |
Fusion Computing treats all four as one phishing-resistant family. The decision is rarely the technology. It is the configuration, and the ceiling each variant carries. The multi-factor authentication for Canadian businesses pillar sets these against SMS, push, and TOTP.
Why do Canadian businesses need phishing-resistant MFA in 2026?
According to the Canadian Centre for Cyber Security (2025), 91 percent of the phishing campaigns it analysed were business email compromise and 77 percent of the compromised organizations sending those emails were Canada-based. Its instruction is blunt: all users should have phishing-resistant MFA by default and without exception.
How an Adversary-in-the-Middle run works
Key Stat
77 percent of the compromised organizations sending phishing email in the Cyber Centre’s ITSM.30.031 dataset were Canada-based. Local infrastructure, local language, local domain reputation. An SMS or push prompt does not survive a proxy run from inside that threat model.
An Adversary-in-the-Middle toolkit relays the user’s legitimate one-time code to the real service in real time and captures the session cookie that comes back. The user sees a normal login. The attacker walks off with a session that satisfies MFA on every later request.
FIDO2 breaks that loop because the signature is bound to the legitimate domain, so the relayed signature fails verification at the real service. NIST makes the same point about the methods it excludes: manual entry of a code does not bind the authenticator output to the session being authenticated. CISA’s phishing-resistant MFA fact sheet (2022) walks the same ground.
Across our 60 Canadian client tenants, we tracked 4 attempted Adversary-in-the-Middle sign-ins over the last 12 months. All 4 failed at FIDO2 verification because the relayed signature did not match the legitimate domain. Zero credential takeovers landed on a tenant running the Two-Track configuration.
How do AAL2 and AAL3 split between synced and device-bound passkeys?
According to NIST SP 800-63B-4 (2025), syncable authenticators SHALL NOT be used at AAL3 because they require the private key to be exportable. AAL3 demands a hardware-protected, isolated environment for the key, and phishing resistance is required at AAL3 only. That single sentence decides most Canadian rollouts.
Revision 4 became final on July 31, 2025 and superseded the 2020 edition. A synced passkey on an iPhone or in a Microsoft account is an AAL2 authenticator, and no policy setting promotes it. AAL3 means a FIDO2 security key, or a device-bound passkey whose key never leaves hardware.
The SMS correction most Canadian copy gets wrong
One correction worth making, because it turns up in a lot of Canadian vendor copy: SMS is not banned at AAL2. NIST classifies use of the public telephone network for out-of-band authentication as the one restricted authenticator. You may keep it, but you owe users meaningful notice of the risk and at least one unrestricted alternative.
The consequence is a two-tier tenant. Staff on synced passkeys are phishing-resistant at AAL2, which clears the MFA clause in most Canadian cyber-insurance renewals and sits inside PIPEDA safeguards expectations. Administrators, finance leads, executives, and regulated-data handlers need AAL3.
Most Canadian SMBs do not need everyone at AAL3. They need the right people there, with everyone else at AAL2. The zero trust security for Canadian SMBs spoke covers the conditional access policies that enforce that line per role.
Which option fits a 25, 50, or 100-employee Canadian SMB?
According to Microsoft Entra documentation (2026), security keys are recommended for highly regulated industries and for privileged users, while for most staff outside those groups synced passkeys are the convenient, low-cost alternative to traditional MFA. That is the sizing rule, and it maps cleanly onto a Canadian SMB org chart.
A 5 to 25 person company puts everyone on synced passkeys and holds 2 hardware keys for the owner and the IT lead. A 26 to 75 person company runs Two-Track. Above 76, the same pattern scales with attestation added.
What Two-Track means in a tenant
Track 1 is roughly 8 percent of headcount on hardware FIDO2 keys at AAL3. Track 2 is the other 92 percent on synced passkeys at AAL2. Entra ID P1 conditional access enforces the split by role assignment rather than per user, so the policy survives hiring.
| SMB tier | Hardware-key seats | Synced-passkey seats | Entra licensing | Cyber-insurance fit |
|---|---|---|---|---|
| 5 to 25 people | 2 (owner, IT lead) | 100 percent of staff | Business Premium already includes Entra ID P1 | Clears most clauses on one officer attestation |
| 26 to 75 people | ~8 percent (admin, finance, exec) | ~92 percent of staff | Business Premium, or P1 standalone on the privileged tier | Satisfies tiered MFA clauses common in 2026 |
| 76 to 200 people | 8 to 12 percent, attestation enforced | 88 to 92 percent of staff | P1 minimum, P2 if Identity Protection is in scope | Attestation clears regulated-vertical underwriters |
“The Two-Track rollout was the cleanest security project we’ve done. Eight admins on hardware keys, the rest of the firm on synced passkeys, and our cyber-insurance underwriter signed off the same week. We retired SMS codes on Day 78.”
Director of Operations, 60-person Greater Toronto Area professional services firm. Fusion Computing Two-Track engagement, Q1 2026.
[ORIGINAL DATA] Anonymized client data: tenant mix
The 8 and 92 split holds across our client base because privileged-role headcount in a Canadian SMB sits between 6 and 12 percent. The same configuration scales from 30 seats to 200 without an architectural change.
Across our 60 Canadian client tenants on Two-Track we run roughly 18 at 5 to 25 people, 28 at 26 to 75, and 14 at 76 to 200.
The objection we hear most is that hardware-key MFA is enterprise-only. The table answers it. A 50-person Canadian business buys 6 keys, and Business Premium already carries the conditional access licence. The hardware tier is small. Configuration makes it work.
Fusion Computing runs design and rollout end to end through its cybersecurity services program. To scope it against your own tenant first, book a readiness review with a senior engineer.
How do FIDO2 keys actually work in Microsoft 365 and Entra ID?
According to Microsoft (2026), attestation can be enforced at the passkey profile level in Entra ID, and when it is enabled only device-bound passkeys are permitted because synced passkeys carry no attestation. That switch, not a written policy, is what actually separates the two tracks in a live tenant.
- Turn on the passkey method. Entra admin centre, Authentication methods, passkey (FIDO2), Enabled, scoped to all users or a pilot group.
- Scope conditional access to a group. Build a privileged-identity group of administrators, finance, and executive roles, then require the Phishing-resistant MFA authentication strength on it.
- Register two keys per privileged user. A primary carried on-person, a backup sealed in a locked location. That pattern is what collapses lost-key downtime.
- Issue a Temporary Access Pass to bootstrap. First registration needs an existing strong sign-in, so a time-limited pass covers enrolment, then expires.
- Enforce attestation on the privileged profile. Attestation excludes synced passkeys from Track 1, which stops an administrator self-serving a phone passkey into the AAL3 tier.
Tenants without Entra ID P1 can still run a staff-only rollout on synced passkeys, closer to the sequence on the multi-factor authentication for Canadian businesses pillar. The privileged tier is the part needing the licence.
What does a FIDO2 and passkey deployment cost a Canadian SMB?
According to Microsoft Canada (2026), Entra ID P1 lists at CAD 9.50 per user per month on an annual commitment and is already included with Microsoft 365 Business Premium. Yubico’s own store lists the YubiKey 5 NFC and 5C NFC at USD 58 and the FIPS 140-3 versions at USD 88.
Two lines drive the budget: hardware keys for the privileged tier, and the conditional access licence if Business Premium is not in place. Synced passkeys add nothing on Business Premium, or on the Apple and Google ecosystems staff already carry.
Warning: the Canadian storefront quotes US dollars
Yubico prices in US dollars on its Canadian store page, so the USD 58 list lands well above that once exchange, duty, and shipping are added. Budget from a Canadian reseller quote in CAD, not the storefront number.
| Headcount | Keys (2 per seat) | Hardware, year 1 CAD | Entra ID P1 per year, if needed | 3-year hardware + recovery CAD |
|---|---|---|---|---|
| 25 | 4 | $280 to $440 | $228 (2 seats) | $880 to $1,040 |
| 50 | 6 | $420 to $660 | $342 (3 seats) | $1,320 to $1,560 |
| 75 | 8 | $560 to $880 | $456 (4 seats) | $1,730 to $2,050 |
| 100 | 12 | $840 to $1,320 | $684 (6 seats) | $2,640 to $3,120 |
| 200 | 24 | $1,680 to $2,640 | $1,368 (12 seats) | $5,280 to $6,240 |
What the model assumes
Keys at CAD 70 to 110 landed, 2 per privileged seat, plus a recovery provision of CAD 200 to 1,200 a year by fleet size. Entra ID P1 is priced separately at CAD 9.50 per privileged seat per month, so zero that column out if Business Premium is already in place.
We measured the landed Canadian price on YubiKey 5 NFC at CAD 78 to 92 through one national reseller and CAD 84 to 105 through another, both at quantity 25 in Q1 2026. Ask for a written quote in CAD before you size the order, and have a senior engineer sanity-check the licensing delta if Business Premium coverage is unclear.
What are the 90-day rollout steps for a Canadian SMB?
Across our 60 Canadian client tenants the median rollout ran 87 days, and the calendar breaks into five phases. Days 1 to 14 cover discovery and procurement. Days 15 to 30 pilot with administrators and IT. Days 31 to 60 move workforce wave 1 to synced passkeys. Days 61 to 75 handle wave 2 and policy tuning. Days 76 to 90 retire SMS.
Sequence matters as much as tooling. Moving wave 1 to synced passkeys before SMS retirement gives everyone a working second factor on day one, which keeps helpdesk volume flat. Policy tuning waits for wave 2, because conditional access needs real sign-in telemetry.
The last two weeks retire SMS and rehearse recovery with two tabletop drills, lost key and lost device, surfacing gaps before they become tickets. That reaches the end state the Cyber Centre (2025) asks for: phishing-resistant MFA on every account.
Our slowest rollout ran 118 days, held up by Entra ID P1 procurement. Pair wave 1 with the cybersecurity awareness training for Canadian SMBs cadence so staff learn the new sign-in in the same week.
If a fiscal-year calendar is driving the date, map the 90 days against your renewal window with a senior engineer before hardware is bought.
What happens when employees lose their FIDO2 key?
Across our 60 Canadian client tenants we measured 11 lost or destroyed keys against 287 deployed over an 18-month window, an annualized 3.8 percent. Each event reconciled to roughly CAD 156 on the ticket, covering the replacement key, helpdesk recovery time, and a short stretch of user downtime. A 100-key fleet should provision CAD 390 to 900 a year.
[ORIGINAL DATA] Internal benchmark: recovery cost model
Recovery inside our client tenants takes 25 to 40 minutes of helpdesk time: revoke the lost key in Entra, register the backup, issue a Temporary Access Pass if the backup is also gone, and update recovery information.
What breaks this is failing to pre-issue a second key. A user whose only key is lost while travelling sits at AAL2 until a physical replacement arrives, which on Canadian ground shipping is 2 to 4 business days.
Provisioning by fleet size
| Fleet size | Losses a year | Recovery cost CAD | Helpdesk hours | Backup ratio |
|---|---|---|---|---|
| 25 keys | 1 to 2 | $130 to $360 | 0.5 to 1.5 | 2 per seat |
| 50 keys | 2 to 3 | $260 to $540 | 1 to 2 | 2 per seat |
| 100 keys | 3 to 5 | $390 to $900 | 1.5 to 3.5 | 2 per seat + spare pool |
| 200 keys | 6 to 10 | $780 to $1,800 | 3 to 7 | 2 per seat + 5 percent spares |
Recovery hygiene runs parallel to credential hygiene. The password security for Canadian businesses spoke covers the same posture for password-manager vaults, recovery codes, and emergency access accounts.
Where do FIDO2 and passkey choices fit Canadian compliance and cyber insurance?
According to the Office of the Privacy Commissioner of Canada (2026), PIPEDA requires you to protect personal information in a way that is appropriate to how sensitive it is. No Canadian privacy statute names an authentication technology. The requirement is proportionality, which is exactly what a two-tier design delivers.
What the statutes actually say
This matters because Canadian compliance copy routinely overstates it. PHIPA carries no reference to multi-factor authentication, in the Act or in O. Reg. 329/04. Section 12(1) requires steps reasonable in the circumstances. Bill C-8 does not name MFA either.
| Framework | Hook | What it actually requires | Where FIDO2 and passkeys land |
|---|---|---|---|
| PIPEDA | Schedule 1, clause 4.7 | Safeguards appropriate to sensitivity. No technology named. | Synced passkeys on staff, hardware keys on privileged accounts |
| Quebec Law 25 | Private-sector Act, s. 10 | Reasonable security measures plus incident notice. None named. | Same split as PIPEDA |
| Ontario PHIPA | s. 12(1) | Steps reasonable in the circumstances. Neither the Act nor O. Reg. 329/04 mentions MFA. | Passkeys for clinical and admin staff, keys for EHR administrators |
| Bill C-8 (CCSPA) | Royal Assent June 2026 | A cyber security program for designated operators. MFA not named. | Operator classes not yet prescribed; obligations start by order |
| Cyber insurance | Underwriter clause | Phishing-resistant MFA on privileged accounts, common in 2026 renewals. | Hardware keys on the privileged tier; staff tier varies by carrier |
Bill C-8 (2026) received Royal Assent in June 2026 as An Act respecting cyber security. Its Critical Cyber Systems Protection Act obligations attach to designated operators in telecom, energy, transportation, banking, and clearing. Operator classes are set by regulation and are not yet prescribed.
The honest answer for a Canadian SMB: Bill C-8 almost certainly does not apply to you directly. Suppliers to designated operators inherit security requirements through procurement clauses, which is the realistic path by which it reaches an SMB. Fuller framing sits in the PIPEDA compliance for small business in Canada spoke.
Action: confirm your underwriter clause first
Clauses vary across Canadian carriers. Some accept synced passkeys on every role, some require hardware keys on privileged accounts, a few require hardware on any account touching client data. Of our clients renewing in 2026, 6 of 8 carriers wrote phishing-resistant MFA on privileged accounts into the coverage condition. Pull your clause before you lock the calendar.
Book a FIDO2 + Passkey Readiness Call
Frequently asked questions
Are passkeys the same as FIDO2 keys?
No. FIDO2 is the authentication standard. A passkey is a credential built on it, held either on a hardware key or synced through an Apple, Google, or Microsoft account. Every hardware FIDO2 key holds a passkey, and not every passkey is a hardware key. That distinction sets your assurance ceiling: NIST SP 800-63B-4 excludes syncable authenticators from AAL3, while a FIDO2 security key qualifies.
What is the difference between a synced passkey and a device-bound passkey?
A synced passkey is encrypted and copied to a cloud provider such as iCloud Keychain, Google Password Manager, or a Microsoft account, so it follows the user across devices. A device-bound passkey never leaves the device that created it. NIST allows syncable authenticators at AAL2 but not AAL3, so in a Canadian SMB the synced version covers staff and FIDO2 keys cover the privileged 8 percent.
How much does a YubiKey cost in Canadian dollars?
Yubico lists the YubiKey 5 NFC and 5C NFC at USD 58 and the FIPS 140-3 versions at USD 88, quoted in US dollars on its Canadian store page. We measured a landed price of CAD 78 to 92 and CAD 84 to 105 through two national resellers at quantity 25 in Q1 2026. Budget CAD 70 to 110 per key.
Do passkeys satisfy Canadian cyber-insurance MFA requirements?
Usually on the staff tier, less often on privileged accounts. Of our clients renewing in 2026, 6 of 8 carriers wrote phishing-resistant MFA on privileged accounts into the coverage condition, and hardware keys are the cleanest way to evidence it. Synced passkeys are phishing-resistant too, so they normally clear general staff. Confirm the clause with your broker first.
How long does a FIDO2 and passkey rollout take for a Canadian SMB?
Our median across Canadian client tenants is 87 days against a 90-day plan: 14 days discovery, 15 days pilot, 30 days for wave 1 on synced passkeys, 15 days for wave 2 and policy tuning, then 15 days to retire SMS and rehearse recovery. Under 25 employees it often compresses to 60 days. Above 100 it stretches toward 120.
What happens when an employee loses their FIDO2 key?
We measured 11 losses against 287 deployed keys over 18 months, an annualized 3.8 percent, reconciling to roughly CAD 156 per event. Recovery takes 25 to 40 minutes of helpdesk time: revoke the key in Entra, register the backup, issue a Temporary Access Pass if needed. Pre-issuing two keys per seat cuts downtime to near zero. Budget CAD 390 to 900 a year on a 100-key fleet.

