Knowledge Centre
Cyber Security GuidesStep-by-Step Guide

Passkey Setup Guide for Microsoft and Google

5 minutes to completeEvergreen guide — kept up to date

A step-by-step guide to setting up passkeys safely on Microsoft and Google accounts while retaining reliable account recovery. A passkey allows a trusted device to approve sign-in without requiring you to type a reusable password — but create one only on a device you control, and keep a safe recovery route.

Before creating a passkey

  • Use a device you control.
  • Update the device’s operating system and browser.
  • Protect it with a screen lock (PIN, fingerprint or face).
  • Check the account’s recovery email and telephone details.
  • Retain another secure recovery option.

Menu names and screens can change. These instructions were last checked on 28 July 2026.

Choose your account type

The correct steps depend on which type of account you are securing. Follow only the route below that matches your account — personal and organisational accounts use different management pages.

  • Personal Microsoft account — Guide A
  • Microsoft work or school account — Guide B
  • Personal Google Account — Guide C
  • Google Workspace account — Guide D

Guide A: Personal Microsoft account

Before setup, confirm: a trusted device, a supported browser, a device screen lock, checked recovery email and telephone details, and another existing sign-in method available.

  1. 1Open the official Microsoft account Advanced Security Options page (account.live.com/proofs/manage) on the device where you want the passkey.
  2. 2Sign in.
  3. 3Choose “Add a new way to sign in or verify”.
  4. 4Select “Face, Fingerprint, PIN, or Security Key”.
  5. 5Choose where the passkey will be stored — a password manager, a phone or tablet, a security key, or your Windows device via Windows Hello.
  6. 6Approve creation with your PIN, fingerprint or face.
  7. 7Name the passkey where supported.
  8. 8Sign out.
  9. 9Test passkey sign-in.

After setup (Microsoft personal)

  • Confirm the credential appears in the account.
  • Record where it is stored.
  • Retain a recovery route.
  • Remove any accidental duplicate.

Guide B: Microsoft work or school account

Your organisation must permit the relevant passkey method. Work and school accounts are managed through Microsoft Entra ID, and administrators control which sign-in methods are available.

  1. 1Open your organisation’s Security info page (normally mysignins.microsoft.com/security-info).
  2. 2Choose “Add sign-in method”.
  3. 3Select “Passkey” or “Security key” using the current displayed wording.
  4. 4Choose the storage method your organisation has approved.
  5. 5Complete the device or application setup.
  6. 6Name the passkey where offered.
  7. 7Test sign-in.

If the option is unavailable, do not use personal-account instructions and do not create an unofficial workaround — contact the organisation’s IT administrator.

After setup (Microsoft work or school)

  • Test access to Microsoft 365.
  • Confirm mobile and desktop behaviour.
  • Confirm where the passkey is stored.
  • Know the lost-device process.
  • Retain approved fallback access.

Guide C: Personal Google Account

Before setup: review your existing passkeys, check whether an Android device has already created one automatically, and confirm your account-recovery information.

  1. 1Open the official Google Account page and select Security (or go directly to myaccount.google.com/signinoptions/passkeys).
  2. 2Open the current “Passkeys and security keys” section.
  3. 3Review existing entries.
  4. 4Choose “Create a passkey”.
  5. 5Approve with the device screen lock (PIN, fingerprint or face).
  6. 6Confirm the device appears in the account.
  7. 7Sign out.
  8. 8Test passkey sign-in.

After setup (Google personal)

  • Remove accidental or unknown passkeys.
  • Confirm another recovery method.
  • Review signed-in devices.

Guide D: Google Workspace account

The organisation’s Google Workspace policy may determine whether passkeys are available and whether passwordless sign-in is permitted. On a managed account, a passkey may only work as a second verification step unless the administrator allows users to skip passwords.

  • A managed account is normally one provided by an employer or school, often using the organisation’s own domain name rather than gmail.com.
  • If the passkey option is missing or restricted, contact the administrator rather than working around the policy.
  • Do not add business credentials to an unapproved personal password manager.
  • Report a lost device to the organisation immediately.
  • When you leave, the organisation controls the account — expect credentials to be removed.
  • Account recovery on managed accounts is typically handled by the administrator, not by consumer recovery routes.

If the device is lost

If the Device Is Lost

  1. 1Use another trusted method to sign in.
  2. 2Lock or erase the lost device where possible.
  3. 3Remove the device from the account.
  4. 4Remove or revoke the relevant passkey.
  5. 5Review recent account activity.
  6. 6End unrecognised sessions.
  7. 7Report business-device loss immediately.
  8. 8Register a replacement passkey.

Passkey review checklist

Passkey Review Checklist

  • I recognise every registered passkey.
  • I know which device or manager stores each one.
  • Old devices have been removed.
  • Shared-device passkeys have been removed.
  • Recovery information is current.
  • Important accounts have a fallback recovery route.
  • Business passkeys follow company policy.
  • The new sign-in has been tested.

Want the full explanation?

Read our Technology Intelligence article covering how passkeys work, why they resist phishing and what to check before relying on one:

Passkeys: How to Protect Your Microsoft and Google Accounts

Preparing an organisational rollout? See the companion analysis of Microsoft’s move to make passkeys the default:

Microsoft Is Making Passkeys the Default: Is Your Business Ready?

Plain-English Takeaway

Create passkeys only on trusted devices, record where they are stored and keep a safe recovery route. Test the passkey before changing older sign-in methods, and remove credentials belonging to devices you no longer own or use.

Downloadable guide

Download the Passkey Setup and Safety Checklist

A printable checklist covering trusted devices, account setup, testing, recovery and removal of old passkeys.

Download PDF

Free download. No email address required.

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.