Passkey Setup Guide for Microsoft and Google
A step-by-step guide to setting up passkeys safely on Microsoft and Google accounts while retaining reliable account recovery. A passkey allows a trusted device to approve sign-in without requiring you to type a reusable password — but create one only on a device you control, and keep a safe recovery route.
Before creating a passkey
- Use a device you control.
- Update the device’s operating system and browser.
- Protect it with a screen lock (PIN, fingerprint or face).
- Check the account’s recovery email and telephone details.
- Retain another secure recovery option.
Menu names and screens can change. These instructions were last checked on 28 July 2026.
Choose your account type
The correct steps depend on which type of account you are securing. Follow only the route below that matches your account — personal and organisational accounts use different management pages.
- Personal Microsoft account — Guide A
- Microsoft work or school account — Guide B
- Personal Google Account — Guide C
- Google Workspace account — Guide D
Guide A: Personal Microsoft account
Before setup, confirm: a trusted device, a supported browser, a device screen lock, checked recovery email and telephone details, and another existing sign-in method available.
- 1Open the official Microsoft account Advanced Security Options page (account.live.com/proofs/manage) on the device where you want the passkey.
- 2Sign in.
- 3Choose “Add a new way to sign in or verify”.
- 4Select “Face, Fingerprint, PIN, or Security Key”.
- 5Choose where the passkey will be stored — a password manager, a phone or tablet, a security key, or your Windows device via Windows Hello.
- 6Approve creation with your PIN, fingerprint or face.
- 7Name the passkey where supported.
- 8Sign out.
- 9Test passkey sign-in.
After setup (Microsoft personal)
- Confirm the credential appears in the account.
- Record where it is stored.
- Retain a recovery route.
- Remove any accidental duplicate.
Guide B: Microsoft work or school account
Your organisation must permit the relevant passkey method. Work and school accounts are managed through Microsoft Entra ID, and administrators control which sign-in methods are available.
- 1Open your organisation’s Security info page (normally mysignins.microsoft.com/security-info).
- 2Choose “Add sign-in method”.
- 3Select “Passkey” or “Security key” using the current displayed wording.
- 4Choose the storage method your organisation has approved.
- 5Complete the device or application setup.
- 6Name the passkey where offered.
- 7Test sign-in.
If the option is unavailable, do not use personal-account instructions and do not create an unofficial workaround — contact the organisation’s IT administrator.
After setup (Microsoft work or school)
- Test access to Microsoft 365.
- Confirm mobile and desktop behaviour.
- Confirm where the passkey is stored.
- Know the lost-device process.
- Retain approved fallback access.
Guide C: Personal Google Account
Before setup: review your existing passkeys, check whether an Android device has already created one automatically, and confirm your account-recovery information.
- 1Open the official Google Account page and select Security (or go directly to myaccount.google.com/signinoptions/passkeys).
- 2Open the current “Passkeys and security keys” section.
- 3Review existing entries.
- 4Choose “Create a passkey”.
- 5Approve with the device screen lock (PIN, fingerprint or face).
- 6Confirm the device appears in the account.
- 7Sign out.
- 8Test passkey sign-in.
After setup (Google personal)
- Remove accidental or unknown passkeys.
- Confirm another recovery method.
- Review signed-in devices.
Guide D: Google Workspace account
The organisation’s Google Workspace policy may determine whether passkeys are available and whether passwordless sign-in is permitted. On a managed account, a passkey may only work as a second verification step unless the administrator allows users to skip passwords.
- A managed account is normally one provided by an employer or school, often using the organisation’s own domain name rather than gmail.com.
- If the passkey option is missing or restricted, contact the administrator rather than working around the policy.
- Do not add business credentials to an unapproved personal password manager.
- Report a lost device to the organisation immediately.
- When you leave, the organisation controls the account — expect credentials to be removed.
- Account recovery on managed accounts is typically handled by the administrator, not by consumer recovery routes.
If the device is lost
If the Device Is Lost
- 1Use another trusted method to sign in.
- 2Lock or erase the lost device where possible.
- 3Remove the device from the account.
- 4Remove or revoke the relevant passkey.
- 5Review recent account activity.
- 6End unrecognised sessions.
- 7Report business-device loss immediately.
- 8Register a replacement passkey.
Passkey review checklist
Passkey Review Checklist
- I recognise every registered passkey.
- I know which device or manager stores each one.
- Old devices have been removed.
- Shared-device passkeys have been removed.
- Recovery information is current.
- Important accounts have a fallback recovery route.
- Business passkeys follow company policy.
- The new sign-in has been tested.
Want the full explanation?
Read our Technology Intelligence article covering how passkeys work, why they resist phishing and what to check before relying on one:
Passkeys: How to Protect Your Microsoft and Google Accounts →
Preparing an organisational rollout? See the companion analysis of Microsoft’s move to make passkeys the default:
Microsoft Is Making Passkeys the Default: Is Your Business Ready? →
Plain-English Takeaway
Create passkeys only on trusted devices, record where they are stored and keep a safe recovery route. Test the passkey before changing older sign-in methods, and remove credentials belonging to devices you no longer own or use.
Downloadable guide
Download the Passkey Setup and Safety Checklist
A printable checklist covering trusted devices, account setup, testing, recovery and removal of old passkeys.
Download PDFFree download. No email address required.
Want the full business explanation?
The Technology Intelligence article covers why this matters, where it helps and what to watch out for.
Read the full Technology Intelligence articleRelated Knowledge Centre resources
Microsoft Passkey Readiness Guide
Check which users, devices, authentication policies and recovery procedures your business should review before Microsoft retires its own SMS and voice authentication.
View guideCyber Essentials Readiness Checklist
Work through the key controls to review before applying for Cyber Essentials.
View guideRemote Working Security Checklist
The security basics to check for staff working from home or on the move.
View guideWhatsApp Impersonation and Payment Fraud Checklist
Checks to help staff spot fake WhatsApp accounts and verify payment requests safely.
Coming Soon