
By Raymond Todd Blackwood, President of QuickLaunch
I was on a call last month with an identity architect at a system office. Sharp woman, ten years in the seat, one of the people you actually want running an authentication program. She told me her passkey pilot had gone great. Ninety-two percent enrollment. Zero helpdesk tickets. She said it the way you say things when you have finally earned a quiet Tuesday.
I asked her what happened with the incarcerated student cohort. She got quiet.
She said, "We didn't include them in the pilot."
That is the column right there. But it took me another six weeks of reading Microsoft release notes, a Federal Student Aid security alert, and a community college two-factor exemption policy to understand why that quiet moment is going to define the next twelve months for every CIO reading this.
Here is what happened while most of us were closing out the fiscal year. Microsoft announced that on March 27, tenants that already had FIDO2 passkeys enabled would get automatically migrated to the new passkey profile model. If your tenant does not have attestation enforcement configured, synced passkeys turn on by default. On April 12, the education-specific passwordless deployment rolled out to A3, A4, and A5 tenants. A1 and A2 stay on traditional multi-factor. On June 5, a conditional access template arrived that blocks text-message one-time codes and requires either a passkey, Windows Hello, or the Authenticator app. Text-message authentication is slated for full retirement by December 31.
I called this on record eighteen months ago. Prediction one on my public list: within twelve months, text-message and email one-time codes will start to be seen as a risk, not a control. Microsoft did not need my prediction. They just made it a licensing artifact.
The receipt everyone is missing is the licensing floor. A3 and higher get the education passkey deployment. A1 and A2 do not. If your community college is running A1 seats for adjuncts and dual-enrollment students, you are about to have a two-tier security posture inside the same tenant. That is not a Microsoft problem you can escalate. That is a governance problem you own. Configure your passkey profiles before the auto-migration or accept Redmond's defaults on your behalf.
The Department of Education has already started writing the language that turns this from a vendor announcement into an audit finding. On May 12, Federal Student Aid issued a technology security alert about an ongoing incident involving the Canvas learning management system between April 25 and May 8. The alert names accounts lacking multi-factor authentication as particularly susceptible. That sentence is doing quiet work. It is the enforcement framework arriving through advisory letters instead of rulemaking. The November 2025 Dear Colleague Letter for the 2026-2027 award year already formally accepted identity-proofing at assurance level two for aid verification. Both ends of the chain are now on the record. How the person proves who they are on day one, and how they authenticate on day four hundred.
If your institution is still on password-plus-text-code for the learning management system and you get breached, the after-action review will not be sympathetic.
Passkeys are structurally better. I want to say that clearly, because the rest of this column is going to sound like I disagree, and I do not. What I disagree with is the narrative.
The narrative says passkeys are the answer. The narrative is silent on the populations for whom passkeys are structurally inaccessible, and those populations already carry higher fraud exposure than the students your pilot enrolled cleanly.
Incarcerated students in Pell-eligible prison programs. These students cannot legally possess devices with a secure enclave. That is the entire cryptographic ground under passkeys. There is no workaround that respects both the security model and the correctional policy. At institutions like Blue Mountain Community College, this is not a rounding error. It is a meaningful percentage of the student body.
Dual-enrollment minors. West Hills Community College District wrote the exemption honestly. Their public support documentation explicitly exempts dual-enrollment students on college and career access pathway campuses from two-factor authentication, because minors moving between K-12 and higher-ed governance regimes cannot navigate two overlapping second-factor stacks. Google Workspace for Education does not currently permit passkeys on K-12 accounts, which cascades directly into every dual-enrollment federation your registrar has quietly built. The seventeen-year-old taking two courses at your community college has an authentication path that runs backward through her high school's identity provider.
The AI agents your provost keeps announcing. This one is the sleeper. Passkeys are a WebAuthn ceremony. Agents cannot perform ceremonies. When you enforce passkeys at every human entry point, the agents your faculty and admissions team have already deployed authenticate through a side channel: workload identities, client secrets, or the new agent-identity object Microsoft introduced in Entra. Microsoft's own language on agent conditional access is the tell. Their documentation describes it as a lightweight mechanism intended primarily to block unauthorized or risky agents rather than a comprehensive policy suite. Lightweight. Primarily. That is not a governance surface. That is a placeholder with a product manager's honesty attached.
Three populations. Three different exemption stories. All three end at the same place: a fallback path that is weaker than the primary control, sitting inside the same tenant, protecting people and processes that carry more risk than the population you designed for.
That is the inverse of what a threat model should produce.
The National Cyber Security Centre in the UK has a line I have taped to my monitor. True phishing resistance is only achieved when all methods of authentication are phishing-resistant. A single weak factor invalidates the posture.
Attackers already know this. Push Security has documented that adversaries targeting passkey-enabled accounts are bypassing the cryptography entirely by forcing downgrades. They route users to legacy authentication flows, consent-phishing screens, or the "help I lost my phone" recovery path. Cisco Talos has confirmed that reverse-proxy phishing kits like Evilginx and Tycoon remain effective against any account that retains a phishable fallback method. Your recovery flow is your posture. If your helpdesk can reset a passkey with a text-message code to a personal number on file, the attacker will find that helpdesk agent before your auditor finds the runbook.
This is why the passkey conversation cannot end at enrollment percentage. Ninety-two percent enrollment with an unnamed exemption path is worse than sixty percent enrollment with a scoped, monitored, compensating control. Because the sixty-percent institution knows where the risk lives. The ninety-two-percent institution has convinced itself the risk is gone.
If you are the CIO reading this at a budget meeting, here is what your identity lead needs to walk in with by the end of the month. Not a strategy deck. A one-page list.
Name the exemptions on page one. Incarcerated cohort. Dual-enrollment minors. Adjuncts on A1 licensing. Agent identities. For each, write the compensating control in a sentence. If you cannot write the sentence, you do not have a control.
Scope the fallback. What is the exact recovery path for a lost passkey? Who approves it? What is logged? What is the maximum session lifetime granted through the fallback? If the answer is "temporary access pass and a legacy method," you have built the phishing target of the next eighteen months.
Inventory the agents. Which agent identities exist in your tenant right now. Who owns each one. What did each touch in the last twenty-four hours. What happens to the credential when the human who created it separates from the institution. If your identity team cannot answer in ten minutes, your passkey story is a false ceiling and I would rather you know that in July than in an incident report in October.
Configure the passkey profile before the next Microsoft cycle. Do not accept the defaults. The defaults are configured for the median tenant, and the median tenant is not a community college with dual-enrollment federation and a Pell-eligible prison program.
None of this is a Microsoft failure. Microsoft shipped a serious control and a licensing floor beneath it. The failure mode is institutional. It is the CIO who declared victory over the ninety-two percent and never wrote down the plan for the other eight.
I keep coming back to that call with the identity architect. She was not lazy. She was not cynical. She had a pilot to run and a budget cycle to survive and a vendor telling her the numbers looked great. So she ran the pilot on the population the vendor designed for, and the population the vendor did not design for stayed on the old control, quietly, off the slide.
We keep declaring identity victories over the population we designed for. The population we did not design for keeps carrying the risk we removed from everyone else. That is the pattern that has been true for the twenty-five years I have been doing this work. It was true when I built Login Manager at a small tech university in Arizona in 1996 and we sanded off the edges for the students who did not have a Windows machine at home. It is true today when passkeys sand off the edges for the students who do not have a phone that can hold a secure enclave.
Passkeys are not the problem. The passkey narrative is the problem. If your rollout plan does not name the exemptions on page one, page two is going to be the incident report. Write the exemptions down. Scope the fallback. Inventory the agents. Then you can celebrate the ninety-two percent, because the other eight will be on the same page with a name next to each of them.
That is the whole job.
Primary: Download the QuickLaunch ILM assessment for higher-ed CIOs. It gives you the one-page exemption and fallback inventory this column argues you need before the fall semester starts.
Secondary: Subscribe to the QuickLaunch column. Weekly, Wednesday, no academic-calendar skips.
Raymond Todd Blackwood is the President of QuickLaunch and writes about identity, agentic AI, and the messy reality of higher-ed IT. #ItsExistential