Just The Tip

Passkeys: The Tip That Kills Password Reset Emails

Passkeys: The Tip That Kills Password Reset Emails

Your bookkeeper has forty logins and a sticky note. Your office manager has one password with a different number on the end for every site. Everyone knows this is a bad system, and nobody has the time to fix it.

Passkeys fix it by removing the thing that gets stolen. This tip covers what a passkey is, where to turn one on today, and what to do about the accounts that do not offer one yet.

What a passkey is

A passkey replaces your password with a pair of cryptographic keys. The private key stays on your phone, computer, or hardware security key. The website only ever gets the public key. When you sign in, you approve it the same way you unlock your device, with a fingerprint, your face, a PIN, or a pattern. That description comes from the FIDO Alliance, the group that maintains the standard.

There is no password to type, so there is nothing to reuse, guess, or hand over.

Why phishing does not work on them

Phishing works because people type secrets into pages that look real. A passkey does not get typed. It is tied to the real site, so a lookalike page at a slightly different address cannot ask your device for it, and the fake login comes up empty.

The FIDO Alliance calls this phishing-resistant authentication built on public key cryptography, with no passwords to steal and no sign-in data attackers can reuse. On its passkeys page it also cites a Google figure of about four times better sign-in success than passwords, which is a nice side effect for anyone tired of reset emails.

Where to turn one on today

Start with your email account, because every other account resets through it. Google, Microsoft, and Apple accounts all support passkeys. Sign in, open the security settings, and look for the words passkey or passwordless sign-in. The screen walks you through it in about a minute.

Make sure your phone or computer has a strong PIN first. That PIN is what unlocks your passkey, so a 1234 lock screen undoes the whole thing.

Keep a way back in If your only passkey lives on one phone and that phone ends up in a lake, you are locked out. Add a second device or a hardware key, and store your recovery codes somewhere offline.

What to do with sites that do not offer passkeys

Plenty of sites still only take passwords. For those, use a password manager, give every account its own long random password, and turn on multi-factor authentication. Many password managers now store passkeys too, so you can keep one tool for both.

The bigger lesson

Passwords fail because we ask people to act like random string generators. Rolling out passkeys across a company is mostly a policy question: which accounts go first, who gets a hardware key, and how recovery works. That is the kind of decision we make with clients every week through our managed IT services.

Passwords are the weakest link in most small offices. We can roll out passkeys, a password manager, and a recovery plan for your whole team. No pressure, no obligation, just a straight look at your setup.

Book a 10-Minute Discovery Call →

Frequently asked questions

Are passkeys safer than a password plus a text code?

In one important way, yes. A password and a code can both be typed into a fake page, and a passkey cannot. A password with multi-factor authentication is still far better than a password alone, so do not skip it on sites that lack passkeys.

What happens if I lose the phone that holds my passkey?

It depends on where the passkey is stored. Many are synced through your Apple, Google, or password manager account, so a new device can pick them up. Set up a second device or hardware key and keep recovery codes offline before you need them.

Do I have to give up my password manager?

No. You will still need it for every site that does not support passkeys, and many managers can store passkeys alongside your passwords.

Can we use passkeys for Microsoft 365 or Google Workspace at work?

Both platforms support passkeys, and admins can control who uses them. The setup needs a plan for recovery and lost devices, so do it on purpose rather than one employee at a time.

Can safemode IT roll out passkeys for our team?

Yes. We set the policy, enroll your staff, and handle the lost-phone calls. See our managed IT services or ask for a free assessment.

Source: FIDO Alliance, Passkeys

Last updated: October 1, 2026

passkeyspasswordsMFAauthenticationphishing