Microsoft is retiring text-message logins, banks are pushing them, and your phone keeps offering to “save a passkey”. But almost nobody explains what a passkey actually is — just that you should use one.
Here’s the plain-English version, plus honest answers to the questions people actually ask us.
What a passkey is
A passkey replaces your password. Instead of remembering something, you prove it’s you the same way you unlock your phone — face, fingerprint, or PIN.
Think of it as a key cut for exactly one lock. Your passkey for Microsoft 365 only works on the real Microsoft sign-in page. It physically cannot be used anywhere else, so a convincing fake login page gets nothing, because there’s nothing to type in and nothing to hand over.
How it works (the two-halves bit)
When you create a passkey, your device makes two matching halves of a digital key.
The private half stays locked on your device — your phone, laptop or security key. It never leaves. Nobody, including the website and including us, can see it.
The public half goes to the website. On its own it’s useless — like a padlock with no key.
When you sign in, the website sends a puzzle only the private half can solve. Your device asks for your face, fingerprint or PIN to unlock it, solves the puzzle, and sends the answer back. Your fingerprint never leaves your device either — it just unlocks the key.
That’s the whole trick. There’s no shared secret to steal, so there’s nothing for a hacker to phish, guess, or find in a data breach. Even if a website is breached, all the criminals get is the useless public half.
Why you should use Passkeys vs passwords and text codes
A password can be guessed, reused, leaked in a breach, or typed into a fake site. A text code can be intercepted, SIM-swapped, or phished — a convincing fake page just asks you for it and you hand it over.
A passkey can’t be any of those things. There’s nothing to type, nothing to remember, and nothing to accidentally give away. It’s also faster: a glance at your phone instead of hunting through a password manager and waiting for a text.
It’s also very convenient to use, it’s quick and easy.
Your questions, answered
Can I have the same passkey on my computer and my phone?
Yes — this is the most common question and the answer is easy. If you save your passkey to Apple’s iCloud Keychain or a password manager like Keeper, it syncs automatically to every device signed into that account. Create it once on your phone, and it’s on your laptop too.
You can also register several separate passkeys for the same account — one on your work laptop, one on your phone, one on a security key. Most people should do exactly that, because it means losing one device never locks you out.
What if I don’t want it synced to the cloud?
You can create a device-bound passkey that never leaves the machine it was made on. More secure in the strictest sense, but if that device dies, that passkey is gone — so always register a second one somewhere else.
When I use a YubiKey, how does that help?
A YubiKey (or any hardware security key) is a small USB or NFC device that holds your passkey physically rather than on your phone or PC. You plug it in or tap it, touch the gold disc, and you’re in.
It helps in three situations: staff who don’t have — or don’t want to use — a work smartphone; shared or awkward environments like workshops, warehouses and reception desks; and anyone who wants the strongest option available, since the key is a separate object a remote attacker simply cannot reach. It also works on any computer you plug it into, which is useful for people who move between machines.
What if I lose my YubiKey?
This is why the golden rule is always register at least two ways in. Most businesses that deploy security keys buy them in pairs: one on the keyring, one in a drawer at home or in the safe.
If you lose one and you have a second method registered, you sign in with that and remove the lost key from your account — it immediately becomes a useless lump of plastic to whoever finds it. If it was your only method, your IT team resets your account and you register a new one. Slightly annoying; not a disaster.
Worth knowing: a lost YubiKey on its own is not a security emergency. Whoever finds it still needs to know which accounts it belongs to, and on most setups they’d need your PIN or fingerprint as well.
What if I lose my phone?
Same principle. If your passkeys sync through iCloud or a password manager like Keeper, they reappear on your new phone as soon as you sign back into that account — nothing is lost. If you have a second method registered, you’re never locked out in the meantime.
Do I still need a password?
For now, usually yes — most accounts keep a password as a fallback while everyone transitions. The long-term direction is passwords disappearing entirely, and some Microsoft accounts already let you delete yours.
Are passkeys safe if someone steals my unlocked phone?
They’d need your face, fingerprint or PIN to use a passkey, the same as they’d need it to open your banking app. That’s why a device PIN matters. If a phone is stolen, remote-wipe it and remove its passkeys from your accounts — exactly what you’d do today anyway.
What about shared accounts, like a team mailbox?
Passkeys are tied to a person and a device, which makes them awkward for logins several people use. For those, store a rotating six-digit code (TOTP) in a shared vault in a password manager like Keeper, so everyone who needs access has it without passing a phone around.
Is this just a Microsoft thing?
No. Passkeys are an industry standard built by Apple, Google, Microsoft and others, and they already work with Amazon, PayPal, eBay, LinkedIn, most banks and thousands more. Learning it once covers all of them.
Getting started
Next time a site offers to create a passkey, say yes — you’ll have it working in under a minute. Start with something low-stakes if you’d rather build confidence first.
For businesses, the sensible pattern is: passkeys in Microsoft Authenticator for everyone with a smartphone, hardware keys for anyone without, TOTP in a shared vault for shared accounts, and at least two methods registered per person.
Rolling passkeys out across your team and not sure where to start? We can plan it, set it up, and handle the questions your staff will inevitably have. Call us on 01442 933356 or get a quick quote — you’ll speak to an engineer straight away.