Scope: This is guidance for personal consumer accounts. For work, school, or managed accounts, follow the administrator’s enrollment and recovery policy before changing sign-in factors.
Moving to passkeys does not need to be a sudden change. A safer rollout is additive: create the passkey first, keep an existing sign-in or recovery method active, and test access from a second device before removing older credentials. This reduces the chance that one device, provider setting, or untested recovery path becomes your only way back into the account.
Start with an access and recovery plan
Before creating a passkey, list the methods that can still let you sign in or recover the account. Depending on the service, these might include your current password, a recovery method, a security key, or another configured option. The goal is not to keep every possible method forever. It is to confirm that at least one practical route remains available if your main device cannot be used.
- Keep an existing sign-in or recovery method active.
- Create the passkey on a device that you personally own and can unlock.
- Keep your screen lock and iCloud Keychain or chosen password manager enabled when they are part of your setup.
- Test sign-in from a second device before deleting an older method.
- Save backup codes securely when the account provides them.
Create passkeys only on personally owned devices, not shared or borrowed devices. Anyone who can unlock the device may be able to use the passkey on it. This matters especially for a device used by several people or one that will later be returned to someone else.
Choose a synced passkey or a separate authenticator
For personal devices, a synced passkey provider may be convenient. A synced passkey may be restored to a replacement device if you can still regain access to its passkey provider. It is not a substitute for securing the provider account and documenting its recovery process. Before relying on synchronization, understand how you would recover the provider account after losing a device.
Device-bound passkeys and hardware security keys need a different plan. Register a spare authenticator and store it separately. A spare authenticator means another authentication method, such as a second security key. If the original device or key is lost, the backup authenticator or the account’s recovery process may be needed.
| Option | Practical step | Important limitation |
|---|---|---|
| Synced passkey | Review the provider’s setup and recovery process | Recovery may first require access to the provider |
| Device-bound passkey | Register a spare authenticator | Device loss may require another recovery route |
| Hardware security key | Register and store a spare key separately | Do not depend on one physical key |
Test before removing anything
After creating the passkey, sign out or use a test session on a second device and try to sign in with it. Also confirm that the recovery method you kept is still available. Seeing a passkey listed in account settings is not the same as completing a sign-in test. The test checks whether the second device, passkey provider, and recovery route work together.
For a Google Account, creating a passkey enables passkey-first sign-in by default. Before relying on a password fallback, confirm the current Skip password when possible setting and test Try another way while you still have account access. Google may also apply a waiting period to a newly created passkey, so do not postpone testing alternatives until you have lost the main device.
After losing a security key, Google may offer backup codes, prompts, another security key, registered devices, or account recovery. These options are available only when they were previously configured and are offered for that account; do not assume that every option will appear automatically. Store backup codes somewhere you can reach without the same device that might be lost.
Apple-specific recovery details
iCloud Keychain can sync passkeys across approved devices. However, recovery is subject to Apple’s current requirements, including Apple Account authentication, a trusted or registered phone-number verification path, and the device passcode. An account recovery contact is an optional additional safeguard. Review these requirements before treating synchronization as a complete recovery plan.
What to do when a device is lost or stolen
Removing the account registration for a passkey may be only one response. Follow the service’s lost-device steps, review active sessions and registered devices, and remotely lock or erase the device when that option is available. Do not imply that deleting a passkey registration alone resolves every compromise scenario: an open session or registered device may also need attention.
After confirming another access and recovery route, remove passkeys that are lost, stolen, no longer authorized, mistakenly created on a shared device, or otherwise no longer needed. Before removing one, check whether it is a synced passkey, because removal may affect access on other devices using that passkey provider.
A final checklist
- Did you test sign-in from a second device?
- Is your recovery method still available?
- Did you save backup codes when the account offers them?
- Do you know whether the passkey is synced or device-bound?
- If a device is missing, did you review active sessions and registered devices?
- If you use a hardware key or device-bound passkey, did you register a spare authenticator?
Sources
- Google Account Help: Sign in with a passkey instead of a password
- FIDO Alliance: Displace Password + OTP Authentication with Passkeys
- Apple Support: About the security of passkeys
- Microsoft Support: Troubleshoot signing in with a passkey
- Android Help: Sign in if you lost your security key
AI disclosure: This article was prepared with AI assistance from the listed sources. It does not represent firsthand testing or an endorsement of any service.