A passkey can let you sign in to a supported website using Windows Hello's face, fingerprint or PIN instead of typing a password. At creation time the site or browser may offer several storage locations: Windows device, a password manager, a phone or a physical security key. Those choices have different recovery implications. Microsoft says a passkey saved to Windows Hello is local to that Windows device. Choose knowingly before confirming the prompt.
Before you start
Use a trusted, updated Windows PC with a strong device lock. Confirm the site's genuine address and the exact account you are signed into. Keep an existing sign-in or recovery method working until you have tested the passkey on the device you intend to use.Do it step by step
- Sign into the service through its verified site and open its account security page. Look for Add passkey or equivalent rather than responding to a surprise popup on an unrelated page.
- When the creation dialog opens, read the proposed save location. Select Windows device or Windows Hello only if you want the passkey tied to this PC. A synced password manager or phone is a different storage choice.
- Complete the Windows Hello prompt using face, fingerprint or PIN. This unlock gesture protects use of the passkey; it is not the passkey itself and is not sent to the website as your biometric data.
- Return to the service's security page and confirm the passkey is listed with a recognizable device label. Avoid deleting the password or old factor yet.
- Sign out and perform a real sign-in with the new passkey. If another computer must access the service, test its separate passkey or fallback method before travel.
- Record the site's recovery options and add another independent passkey if supported. If the PC is lost, use the service's official account security page from a trusted device to revoke the lost passkey.