Resource icon

Save a new passkey on the intended Windows device, not the wrong account

A passkey can let you sign in to a supported website using Windows Hello's face, fingerprint or PIN instead of typing a password. At creation time the site or browser may offer several storage locations: Windows device, a password manager, a phone or a physical security key. Those choices have different recovery implications. Microsoft says a passkey saved to Windows Hello is local to that Windows device. Choose knowingly before confirming the prompt.

Before you start​

Use a trusted, updated Windows PC with a strong device lock. Confirm the site's genuine address and the exact account you are signed into. Keep an existing sign-in or recovery method working until you have tested the passkey on the device you intend to use.

Do it step by step​

  1. Sign into the service through its verified site and open its account security page. Look for Add passkey or equivalent rather than responding to a surprise popup on an unrelated page.
  2. When the creation dialog opens, read the proposed save location. Select Windows device or Windows Hello only if you want the passkey tied to this PC. A synced password manager or phone is a different storage choice.
  3. Complete the Windows Hello prompt using face, fingerprint or PIN. This unlock gesture protects use of the passkey; it is not the passkey itself and is not sent to the website as your biometric data.
  4. Return to the service's security page and confirm the passkey is listed with a recognizable device label. Avoid deleting the password or old factor yet.
  5. Sign out and perform a real sign-in with the new passkey. If another computer must access the service, test its separate passkey or fallback method before travel.
  6. Record the site's recovery options and add another independent passkey if supported. If the PC is lost, use the service's official account security page from a trusted device to revoke the lost passkey.

Check the result​

A fresh sign-in works with the intended Windows Hello device, the service lists the correct passkey, and an independent fallback has been tested.

If something goes wrong​

If creation is not offered, the service or your work organization may not support that choice. If the dialog proposes a different credential manager, cancel and inspect browser settings rather than accepting a storage location you do not control.

Know the limit​

A passkey is phishing-resistant for the site it was created for, but device compromise and account recovery still matter. A local Windows Hello passkey is not automatically available on every future device. Never assume removing a password also removes all other account recovery paths. Microsoft passkey storage choices
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack