Bay Geeks logoTampa Bay IT Support · Since 2004
Bay Geeks Guide · Identity Read This First

Passkeys, Explained: What Replaces Your Password

A passkey is the first sign-in method that is easier and safer than a password at the same time. Here's how it works, where it lives, what to do about a lost phone, and why the Microsoft deadlines make this a business question now.

Passwords have one design flaw that no amount of complexity fixes: they work anywhere you type them, including on a fake login page. Nearly every phishing email, fake Microsoft popup and account takeover we clean up comes down to that. A passkey closes the flaw instead of patching around it, and it is already built into the phone and computer you own.

The Short Version

A passkey is a pair of cryptographic keys created for one website or app. The public half is stored by the site. The private half stays on your device and never leaves it. When you sign in, the site sends a challenge, your device signs it after you unlock with your face, fingerprint or PIN, and the site checks the signature. There is nothing to type, nothing for the site to lose in a breach, and nothing you can be talked into handing over.

Why a Passkey Can't Be Phished

Every other sign-in method leaves something a scammer can ask you for.

MethodWhat a scammer can still doVerdict
Password onlyPhish it, buy it from a breach, or guess it if it's reused anywhereRetire it
Text-message codeTake over your phone number, or relay the code through a fake page while you type itBetter than nothing
Authenticator app codeRelay the six digits through a fake page, or flood you with prompts until you tap ApproveGood
PasskeyNothing to ask for. The key checks the website address itself and refuses a lookalike.Best

The reason is in the last row. A passkey is bound to the exact address it was created on. A page at micros0ft-login.com can copy every pixel of the real thing, but your device has no passkey for that address, so there is nothing to send. The scam fails before you have a chance to be fooled.

Where It Actually Lives

WhereHow it syncsGood for
iPhone, iPad, Mac (iCloud Keychain)Encrypted sync across your Apple devicesAnyone living in the Apple ecosystem
Android and Chrome (Google Password Manager)Encrypted sync across devices signed into your Google accountAndroid phones and Chrome users
Windows HelloStays on that one PCWork PCs; pair it with a synced option
Password manager (1Password, Bitwarden and others)Syncs across every platform you useMixed households and offices
Hardware key (YubiKey and similar)Never syncs; lives on the keyAdmin accounts and the highest-value logins

For a business on Microsoft 365, the Microsoft Authenticator app holds the passkey on the phone and Windows Hello for Business does the same on the PC.

“What If I Lose My Phone?”

This is the question everyone asks, and it has a good answer. A synced passkey comes back when you sign into a new device with the same Apple, Google or password manager account, the same way your photos do. A passkey that lived only on the lost phone is gone, which is why every important account should have two ways in: a second device, a hardware key, or the recovery codes the service handed you at setup. Do that on a calm day. Our lost phone guide covers the rest of that first hour.

Setting One Up

  1. Google: myaccount.google.com, then Security, then Passkeys. Create one on your phone and, separately, one on your computer.
  2. Microsoft account: account.microsoft.com, then Security, then Add a new way to sign in, then Face, fingerprint, PIN or security key.
  3. Apple: recent devices already secure your Apple account with a passkey through iCloud Keychain. Check Settings, your name, then Sign-In & Security.
  4. Everything else: look under Security for “Passkeys” or “Passwordless.” Most banks, Amazon, PayPal, eBay and every major password manager support them now.
  5. Then register a backup: a second device or a hardware key, and save the recovery codes somewhere that is not the phone.

The Microsoft Deadlines

If your business runs Microsoft 365, this stopped being optional this month. Microsoft is retiring text and phone-call codes for Entra sign-in on a fixed schedule.

Passkeys are switched on automatically for any user still on SMS or voice codes. They are prompted to register one at their next sign-in. A temporary opt-out runs until February.

SMS and voice codes are retired. Anyone whose only second factor is a text or call is blocked at sign-in until they register a passkey or the Authenticator app.

Dates from Microsoft's Entra announcement, tracked in our client advisories

The work is an audit of who still signs in with a text code, a staged enrollment so nobody is locked out on a Monday morning, and a short policy update. Passkey support is included on every Bay Geeks maintenance plan, and our email services team runs the enrollment.

Where Passwords Still Matter

Passkeys are spreading fast but they are not everywhere yet. Older line-of-business software, shared logins like a front-desk account, and smaller websites still take a password. For those, the rule stays what it has been: a unique password from a password manager, plus an authenticator app rather than a text code. Treat the password manager as the bridge. It holds your passkeys and your leftover passwords in one place and tells you which is which.

Quick Self-Check

QuestionIf “no” or “not sure”...
Does your email account have a passkey or authenticator app, not just a text code?Do this one today
Do you have a second way into that account if your phone disappears?Worth 15 minutes
On Microsoft 365: do you know how many staff still sign in with SMS codes?Worth a call
FIXED ✓

Want Passkeys Rolled Out Without the Lockouts?

We audit who is still on text codes, enroll your team in stages, and set up the recovery methods so nobody gets stuck. Included with our email services and every maintenance plan.

Frequently Asked Questions

Is a passkey the same thing as Face ID or Windows Hello?

No. Face ID and Windows Hello are how you unlock the passkey. The passkey is the key itself. Your face or fingerprint never leaves the device, and the website never sees it.

If someone has my phone, can they sign in as me?

Only if they can also unlock it. A passkey requires the device unlock every time. Use a real passcode, not 1234, and turn on Stolen Device Protection on an iPhone or Theft Detection Lock on Android. Our lost phone guide walks through both.

Do I still need a password manager?

Yes, for now. It holds passwords for the sites that don't support passkeys yet, and most managers store passkeys as well, so everything lives in one place and syncs everywhere.

What if a site I use doesn't support passkeys?

Use a unique password from your manager plus an authenticator app, and check back. Support is being added quickly, and the manager will usually offer to upgrade the login when it appears.

Can I use a passkey on a shared or public computer?

Yes. The site shows a QR code, you scan it with your phone, and the phone does the signing. Nothing is saved on the shared machine. Just don't create a new passkey on a computer you don't own.

Identity Threats 101

Why a stolen password is now the most common way in, and how it's stopped.

Your Password Was in a Breach

The first hour after a breach notice: what to change, in what order, and what to check.

How to Spot Phishing

The five tells, the scams hitting Tampa Bay right now, and what to do if you already clicked.

Lost or Stolen Phone

Lock it, protect the accounts on it, and suspend the line, in the right order.

Am I Being Hacked?

The three layers of cyber threats, and which one is actually your problem.

Client Advisories

Microsoft's passkey enforcement dates and other changes affecting clients.

📞 727-579-4335  ·  ✉️ support@baygeeks.com  ·  Privacy Policy  ·  Terms of Service

Call Now Schedule