
I don’t know about all of you, but I have received numerous emails lately telling me that all of my Microsoft products will soon be switching to PASSKEYS. The email subject states: “Passkeys by default and retirement of Microsoft-provided SMS and voice authentication.”
To help with the many phishing scams Microsoft is retiring SMS and voice authentication. They claim these are more vulnerable due to AI. Everyone will need to move away from these by February 1, 2027. After February 1, 2027 — Users whose only available MFA method is SMS or voice will receive a blocking prompt to register a passkey before they can continue signing in. There is no opt out from this enforcement; it applies to all tenants. Not just Microsoft, but most other accounts you use on a daily basis on your devices will be going to these.
Since this is relatively new technology for most of us, I did some research so that we can all better understand what this is, how it works, and how we keep from getting locked out of our accounts in the future. From what I found out this new technology will be helpful to most as long as it is set up correctly.
First of all, there are two kinds of passkeys:
- Synced passkey: Stored by a credential manager such as Microsoft Password Manager, Google Password Manager, Apple iCloud Keychain, 1Password, etc. The encrypted passkey is synchronized through that provider. When you replace your device, you sign into the same credential manager, and your passkeys can become available on the new device.
- Device-bound passkey: Stored only on that particular computer, phone, or hardware security key. Lose the device and you’ve lost that copy of the passkey. You need another passkey or another account-recovery method.
This just reinforces the need for a password manager. If you save your passkeys in a password manager, you will always have access to those by just signing into a new device with the password manager. If you use local passkeys like Windows Hello, you are in danger if that device dies or gets stolen. You could lose access to the accounts. For instance, if you use the Google password manager on your android phone when you sign into your new android phone all of your passkeys will be available.
This is a much better solution than the Microsoft authenticator that might not sync those accounts to your new phone. The big difference is using a SYNCED CREDENTIAL MANAGER. So, all of us that use Windows Hello on our computers are not saving our credentials to a synced credential manager but instead a local one. Those will not sync to your new device.
Another issue is if you switch platforms on devices. If you go from an Android phone to an iPhone your Google passwords might not come over and if you go from an iPhone to an android your apple keychain might not come over. This is the same with going from mac to pc or pc to mac.
The bottom line of all of this is that you really need to know where your passkeys are saved so you can ensure you have access even if you can’t access one of your devices. It is still best to set up all available options for account recovery to protect yourself from losing access to an important account.
As always, I can help with this as long as you reach out before there is a problem and an account is not accessible. When that happens, my methods might not be able to help. Make sure you are protected before something happens.
Want to get my computer services updates and reminders directly into your email inbox? Sign up for my FREE Newsletter!






