top of page
Danovation Logo V1_edited.jpg

Danovation IT

Passkeys Explained: What is a Passkey & How It Works

Daniel Bell
14 minutes ago
8 min read

Passkeys are the latest modern way to sign in to Websites and apps without typing in your password. Instead of asking you to prove who you are by entering a secret, a passkey lets your device prove it securely in the background, usually after you unlock it with your face, fingerprint, or PIN. This guide keeps passkeys explained in plain English while also covering the technical basics, everyday setup choices, and what to do if you lose a device.

So what is a passkey and how does it work?


A passkey is a password replacement that uses cryptographic keys (a fancy way of saying a Digital Key) instead of a written password. If you searched for “what is a passkey” or even “what is a pass key,” the simplest passkey meaning is this: it is a secure sign-in credential stored on your device or in a supported password manager, and it lets you log in without giving the website a password that could be stolen. In a business sense this works well when you have an employee leave, it means that if you have a shared password vault, you don't need to go change the password as the password vault contains this digital pass key instead of the written password, because let's face it, nobody is changing the password to a shared platform each time a staff member leaves your business.


That may sound technical, but the daily experience is simple. You visit a sign-in page, choose the passkey option, unlock your device with biometrics or a PIN, and you are in. You never type the private key, the website never receives it, and there is no password for an attacker to trick you into revealing.

Option showing sign-in option using a Passkey
Option showing sign-in option using a Passkey

Passkeys should replace the Common Authenticator Apps We All Love to Hate


Most of us are pretty used to authenticator apps by now. You try to log in, your phone buzzes, you open the app and approve the request before you can get on with what you were doing. They have definitely made accounts more secure than relying on passwords alone, but they can still be frustrating for staff and they are not completely immune to phishing attacks.


Passkeys make the whole process feel much simpler. Instead of opening an authenticator app every time, you can sign in using the security already built into your device, such as Windows Hello or your phone’s biometric sign-in. The passkey is also tied to the legitimate website, which makes it much harder for someone to trick you with a fake Microsoft 365 login page. It is a better experience for users without giving up security.


Your Standard Windows Authenticator Prompt
Your Standard Windows Authenticator Prompt

How do passkeys work in real life?


In day-to-day use, a passkey feels a lot like unlocking your phone or computer. Instead of typing in a password and then reaching for an authenticator app, you choose to sign in with a passkey and your device asks you to verify that it is really you.


A typical sign-in might look like this:

  1. You open the website or app and enter or select your account.

  2. You choose to sign in with a passkey.

  3. Your device asks you to verify yourself using something like Windows Hello, Face ID or your device PIN.

  4. Your device securely confirms the login in the background.

  5. You're signed in.


The clever part is what happens behind the scenes. Your actual passkey is not being typed into the website or sent across the internet like a password. Your device instead proves that it has the correct credential without exposing the private part of it.


Passkeys also know which website they belong to. If someone creates a fake Microsoft 365 login page that looks almost identical to the real one, your Microsoft passkey will not simply work on that fake website. That makes passkeys much harder to steal through traditional phishing attacks and removes one of the biggest weaknesses of passwords - relying on the person signing in to spot the fake.

Passkey vs password: the practical difference


The biggest difference between a password and a passkey is where the security actually sits. A password is something you know and type in. A passkey is stored securely on your device and is used only with the website or service it belongs to.


In practical terms:

  • Passwords can be typed into almost any login page, which is exactly why phishing works so well.

  • Passkeys are tied to the real website or app, so they are much harder to use on a fake login page.

  • People often reuse passwords, which means one stolen password can sometimes unlock several accounts.

  • Passkeys are different for each service, so a compromised account does not expose the same credential somewhere else.

  • Passwords need to be remembered, stored or reset.

  • Passkeys let your device handle the hard part, while you simply verify that it is really you.


Traditional MFA has made passwords much safer, but it can still have weak points. A user can be tricked into entering a verification code into a fake website, or accidentally approve a sign-in request they did not start.

Passkeys remove a lot of that risk because there is no password or verification code for the user to hand over. They also make the safer way of signing in feel easier, which matters in the real world. If security is too annoying, people will eventually look for ways around it.

Passkey Prompts Look Like This
Passkey Prompts Look Like This

Using passkeys across devices


A common worry with passkeys is that they might lock you into one phone or computer. In most cases, that is not how they work. If your passkeys are synced through something like your Apple, Google or Microsoft account, or through a supported password manager, they can often be available across the devices you already use.


You can also use a passkey from your phone to sign in on another computer. For example, a website might show a QR code on the screen. You scan it with the phone that has your passkey, unlock your phone and approve the sign-in. The devices may also use Bluetooth to help confirm that your phone is actually nearby.


This is especially handy if you are signing in on a new computer or a device where your passkey is not stored. Instead of falling back to a password, your phone can confirm the login for you. As with any sign-in request, it is still worth checking that you actually started the login before approving it.

What happens if you lose your device?


Losing your phone or laptop does not necessarily mean losing access to all of your passkeys. What happens next depends on where those passkeys are stored and what recovery options you have set up.


This is one of the reasons we recommend using a password manager such as 1Password (no affiliation) to store and manage passkeys, rather than relying only on passkeys stored directly within your iPhone, Android phone or another device ecosystem. Using a password manager can make it easier to access your passkeys across different devices and reduces how dependent you are on one particular phone or platform.


It is still important to have a backup plan. For important business accounts, make sure you have another trusted way to regain access if a device is lost, damaged or replaced. That could mean having another registered device, a backup security key or making sure the account's recovery options are properly configured.


If a device is lost or sold, remove it from your accounts as soon as possible. It is also worth checking your recovery options before something goes wrong, rather than trying to figure them out when you are already locked out.


Your passkeys should make signing in easier without creating a single point of failure. A little bit of planning upfront can save a lot of frustration later.

It's not uncommon for somebody to lose or break their phone
It's not uncommon for somebody to lose or break their phone

A sensible way to start using passkeys

You do not need to move every account over to passkeys in one go. A better approach is to start with one or two important accounts, get comfortable with how passkeys work, and then gradually use them elsewhere as more services support them.


Start with an account you use regularly and make sure you understand how you would recover access if something went wrong. Once the passkey is set up, try signing in from another device as well. This gives you a good idea of what the experience will actually be like before you start relying on passkeys more heavily.


It is also worth keeping your devices and browsers up to date, as passkey support has improved significantly over the last few years. If a website still requires a password, keep using a strong and unique one rather than falling back into password reuse.


You may also find that some services still ask for passwords, verification codes or another form of MFA from time to time. That is completely normal. Passkeys are still being rolled out across different platforms, so for now most people will probably be using a mixture of passkeys and more traditional sign-in methods.


The important part is not trying to change everything overnight. Start small, make sure your recovery options are sorted, and move more accounts across once you are comfortable with how it all works.

Common misconceptions about passkeys


One of the biggest misconceptions about passkeys is that they are basically just Face ID or a fingerprint. That is not quite how it works. Your fingerprint, face or device PIN is simply used to unlock the passkey stored on your device. The website itself does not receive or store your biometric information.


Another common concern is that passkeys will lock you into one brand of device. While the experience can differ depending on whether you use Apple, Google, Microsoft or a password manager such as 1Password, passkeys are based on widely supported authentication standards. What matters more is where you choose to store them and how easily you can access or recover them across your devices.


Passkeys also do not make every security problem disappear. If someone gains access to your device or your account recovery process is weak, there can still be risk. What passkeys do very well is remove many of the problems that come with passwords, especially phishing and password reuse.

Everybody complains about MFA - but it's saving your accounts!!!
Everybody complains about MFA - but it's saving your accounts!!!

So Passkeys are the Future?


Passkeys make signing in simpler while also giving businesses a much stronger level of protection against phishing and stolen passwords. Instead of relying on something a user has to remember or type into a website, the device securely handles the authentication in the background.


For businesses using Microsoft 365, passkeys are also part of a broader move towards stronger identity security. If you're reviewing how your business handles authentication, our IT Support team can help with day-to-day technical issues, user access and security-related problems as they come up.


For businesses that want a more proactive approach, our Managed IT Services cover ongoing support, device management, cybersecurity and the general management of your IT environment - we can also help setup and configure shared passkeys in managers such as 1Password


If you're looking specifically at Microsoft 365, Entra ID or improving how your staff sign in, our Microsoft 365 Consultants can help you plan and roll out passkeys and other modern authentication methods without making things unnecessarily complicated for your team.


Passkeys will not replace every login method overnight, but they are a big improvement over the passwords and constant authentication prompts most of us have become used to. Start with a few important accounts, make sure your recovery options are sorted, and expand from there.


 
 

HI THERE!

I'm Dan

I'm an IT guy who has worked in the professional IT support space for the last 10 years. I decided to take a leap of faith and started an IT firm that helps those who really need it in a friendly and accessible manner.

2.png
bottom of page