How to set up passkeys and stop using passwords
Passkeys let you sign in with your fingerprint, face, or PIN instead of a password. Here is what they are and how to turn them on for Google, Microsoft, and Apple.

If you keep reusing the same password across accounts, a passkey is the fix that actually removes the problem instead of nagging you about it. By the end of this guide you will know what a passkey is, why it is harder to steal than a password, and where to turn one on for your Google, Microsoft, and Apple accounts. You do not need new software, and you do not have to give up your password on day one.
What a passkey actually is
A passkey is a sign-in credential stored on your phone or computer that you approve with the same fingerprint, face, or screen PIN you already use to get into the device. There is nothing to remember and nothing to type. The FIDO Alliance, the industry group behind the standard, describes a passkey as a credential you use “with the same process that they use to unlock their device (biometrics, PIN, or pattern).”
Under the hood it is a pair of cryptographic keys. Your device keeps the private half and never hands it out. The website or app only ever stores the public half, which is useless to a thief on its own. When you sign in, your device proves it holds the private key without sending it anywhere. That single design choice is what makes passkeys behave so differently from passwords.
Why a passkey beats a password
Two things make passkeys stronger. First, a passkey is tied to the exact website it was created for, so a lookalike page cannot trigger it. That is what people mean when they call passkeys phishing-resistant, and it is the same threat covered in our guide to spotting a phishing email. Second, because the site only holds the public key, a data breach leaks nothing that can sign in as you. As the FIDO Alliance puts it, “there are no passwords to steal and there is no sign-in data that can be used to perpetuate attacks.”
| Password | Passkey | |
|---|---|---|
| To sign in you | type a secret you memorized | confirm with a fingerprint, face, or PIN |
| The site stores | a version of your secret | only a public key that can’t sign in for you |
| If the site is breached | the secret can leak and be reused | there is nothing reusable to steal |
| Phishing | a fake page can capture it | tied to the real site, so a fake page can’t use it |
| Reused across sites | common, and dangerous | each passkey is unique to one site by design |
Where to turn passkeys on
The option lives in the security settings of each account. Menu names shift over time, so treat these as the neighborhood to look in rather than a fixed sequence of taps.
| Account | Where the setting lives | Confirmed with |
|---|---|---|
| Google Account, then Security, then “Passkeys and security keys” | fingerprint, face, or screen lock | |
| Microsoft | account.microsoft.com, then Advanced security options, then “Add a new way to sign in or verify” | face, fingerprint, or PIN |
| Apple ID | created on your Apple device and stored in iCloud Keychain; sign in with “Sign in with Passkey” | Touch ID, Face ID, or device passcode |
For a Google Account, open Security and look for “Passkeys and security keys,” then choose to create one (the direct page is myaccount.google.com/signinoptions/passkeys). Google lets you make a passkey on a computer running Windows 10, macOS Ventura, or ChromeOS 109 or later, on a phone running Android 9 or iOS 16 or later, or on a hardware security key.
For a Microsoft account, go to your account security page, choose Advanced security options, then “Add a new way to sign in or verify,” and pick “Face, Fingerprint, PIN, or Security Key.” Microsoft now makes brand-new personal accounts passwordless by default, though existing accounts keep their password until you decide otherwise.
For an Apple ID, you usually do not press a single “create passkey” button. On an iPhone, iPad, or Mac, a passkey is offered when a site or app supports it, and it is saved to iCloud Keychain automatically. To use a passkey for your Apple Account itself, enter your Apple ID on an Apple sign-in screen and choose “Sign in with Passkey.” Apple requires two-factor authentication for any account using iCloud Keychain, and it will prompt you to turn 2FA on if it is not already.
How passkeys sync across your devices
A passkey does not have to be trapped on one phone. Each platform has a manager that copies your passkeys, encrypted, to your other devices signed in to the same account.
- Google Password Manager saves your passkeys and makes them available on your Android devices and in Chrome wherever you are signed in to the same Google Account.
- iCloud Keychain keeps your passkeys available across your Apple devices. Apple states that in iCloud Keychain “passkeys are end-to-end encrypted, so even Apple can’t read them.”
- Windows and the Microsoft ecosystem can store a passkey in Windows Hello on the PC, or in a synced credential manager. Microsoft also lets you save a passkey to an iPhone, iPad, Android device, a security key, or another manager such as Google Password Manager or iCloud Keychain.
You can also use a passkey that lives on your phone to sign in on a computer you do not own. On the computer’s sign-in screen you scan a QR code with your phone’s camera and confirm with your fingerprint, face, or PIN. The two devices talk over Bluetooth to confirm they are near each other, and the passkey never leaves your phone.
What happens if you lose your phone
This is the question that keeps people on passwords, and the answer is reassuring once you understand the sync above. If your passkeys are synced, losing one device does not lose the passkey, because it is still on your other signed-in devices. Sign in on another phone or computer, then remove the lost device from your account.
If the lost phone was your only device, you fall back on account recovery. Apple, for example, can restore your passkeys through iCloud Keychain escrow even if every device is gone. You authenticate with your Apple Account, respond to a text sent to a trusted phone number, and enter your device passcode; a Recovery Contact you set up ahead of time can also help. The practical takeaway is the same one behind a good backup habit: keep a second way in before you need it. Add a recovery phone or email, keep two-factor authentication on, and, until passkeys are everywhere, keep a strong password as a fallback. It is the same mindset as backing up your files properly, applied to your accounts.
The honest limits today
Passkeys are growing fast, but they are not everywhere yet. Plenty of sites and apps still offer only passwords, so for now you will run a mix. Most big providers let you keep a password as a backup even after you add a passkey, and that is fine. Syncing is also tied to the manager you use, so a passkey saved in iCloud Keychain and one saved in Google Password Manager live in different places, even though you can now save across some of them and sign in between devices.
Turn passkeys on for the two or three accounts that matter most, your email and your Google, Microsoft, or Apple sign-in, and you have removed the exact thing attackers count on: a reused, guessable, phishable password. On a Windows PC, the same face or PIN behind a passkey is also your Windows Hello sign-in, so it is worth also making sure the machine itself locks when you step away, which you can automate with Windows Dynamic Lock. Add the rest of your accounts as the sites you use catch up.