You keep getting asked whether you want to create a passkey, and nobody has explained what one is or what you give up by agreeing. Nothing, as it turns out.
A passkey replaces the password for one site and lives on the device rather than in your head. It is not another password and there is nothing new to remember.
I will take what it actually is, what it needs, and the one thing worth settling before you start.
What Microsoft says it is
Their words first, then a plainer version.
Documented by Microsoft on its passkeys page: a passkey is "the evolution of passwords: instead of remembering (or writing down!) your complex passwords, a passkey is linked to your device."
And how you use one: "On your computer, using Windows Hello with PIN, fingerprint, or face."
⭐ So the site stops asking for a secret you typed and starts asking your device to prove it is yours.
⚡ You still unlock the device the way you always did. The PIN or the fingerprint is not the passkey, it is the thing that lets the passkey be used.
Why that is safer, in plain terms
Ours, and marked as ours. The vendor pages tend to skip the mechanism.
⭐ A password is a secret you and the site both hold. If their copy leaks, yours is out too, and every site you reused it on is at risk.
⭐ A passkey is a pair. Your device keeps one half and never sends it. The site keeps the other half. Useless on its own.
⛔ So a breach at the site gives an attacker nothing to reuse. There is no password in their database to steal, because you never gave them one.
⚠️ And it will not be phished. The passkey is tied to the real address of the site, so a lookalike page cannot ask for it. That is the part that matters most day to day.
Ours: it does not need a fingerprint reader
The assumption that stops people, and it is simply wrong.
Ours, and read on this desktop. There are no biometric devices on it at all. No fingerprint reader, no infrared camera.
⭐ Passkeys work on it anyway. Microsoft lists PIN alongside fingerprint and face, and a PIN counts as Windows Hello.
⚡ One line answers it, and changes nothing:
Get-PnpDevice -Class Biometric | Select-Object FriendlyName, Status
⚠️ An empty result is not a blocker. It only means the PIN is how you will approve things.
⭐ If you have never set Hello up at all, that takes about two minutes and it is the prerequisite.
What actually happens when you make one
Four seconds of work. Worth knowing what each click did.
⭐ The site asks. You approve with your PIN or finger. That is the whole ceremony. No email confirmation, no code, no new secret.
⚡ Your device creates the pair at that moment, keeps its half, and hands the site the other half.
⚠️ You can usually keep the password as well. Most sites treat a passkey as an additional way in rather than a replacement, at least at first.
⭐ Ours, and marked as ours: say yes on the sites you sign into constantly and leave the rest. The benefit is real and it compounds with use rather than with count.
Where they are kept, and the part people worry about
A straight answer, and it depends on what you agreed to.
⭐ On the device, in the secure store behind Windows Hello. That is the default on a Windows PC.
⚡ Microsoft also mentions saving to "a synced credential manager", which is how a passkey follows you to another machine rather than living on one.
⛔ A synced passkey is only as protected as the account syncing it. Ours: that account is now the thing worth protecting properly.
⚠️ On a shared PC, think before you save one. Anyone who can unlock that machine can use the passkeys on it, exactly as they could use a saved password.
What happens if you lose the device
The question worth answering before you commit. Not after.
⛔ A passkey stored only on one machine dies with it. No copy exists anywhere else, by design.
⭐ Which is why every site keeps a recovery route open, usually the old password or an email link. Do not delete the password until you have a second way in.
⚡ Ours: put a passkey on your phone as well as your PC for anything important. Two devices is the practical answer to this and it costs nothing.
⚠️ A passkey on a Microsoft account is a special case. If you moved to a local account, there is no cloud account for it to attach to.
Where it still does not work
Being fair about the state of it in 2026.
⚠️ Plenty of sites have not implemented it. Banks in particular have been slow, and there is nothing you can do to bring them along.
⛔ Some apps ask for the password anyway, even where the website accepts a passkey. That is the app, not your setup.
⚡ And a work or school account may have this decided centrally. A missing option there is policy rather than a fault.
Whether to say yes
The decision, plainly.
⭐ Yes on email, on your Microsoft or Google account, and on anything holding money. Those are the accounts worth the two seconds.
⚡ It costs nothing to try one and change your mind. Removing a passkey is a setting on the site, and the password still works.
⛔ It is not antivirus and it is not a firewall. It protects one specific thing, which is somebody signing in as you, and nothing else.
⚠️ Ours: if you are already using a password manager well, the gain is smaller than the marketing suggests. If you reuse passwords, this is the single biggest improvement available to you.
Status: read against Microsoft's current passkeys page 25 August 2026. Its own words cover the description of a passkey as the evolution of passwords linked to your device, and for signing in on a computer using Windows Hello with PIN, fingerprint or face. The absence of biometric hardware was read on the machine here. The explanation of key pairs and phishing resistance is ours and is labeled as such.
What is a passkey in simple terms?
A replacement for a password on one site. Your device keeps half of a pair and never sends it, the site keeps the other half which is useless alone. You approve with your PIN or fingerprint instead of typing a secret.
Do I need a fingerprint reader for a passkey?
No. Microsoft lists PIN alongside fingerprint and face as ways to use one. The machine tested here has no biometric hardware at all and passkeys work on it. A PIN counts as Windows Hello.
What happens to my passkey if I lose my laptop?
A passkey stored only on that machine is gone with it. That is why sites keep a recovery route open, usually the old password or an email link. Adding a passkey on your phone as well is the practical answer.
Is a passkey safer than a password?
For the two things that actually go wrong, yes. A site breach leaks nothing reusable because you never gave them a secret, and a lookalike page cannot ask for it because the passkey is tied to the real address.
The Short Version
- Microsoft describes a passkey as the evolution of passwords, linked to your device.
- Your device keeps one half of a pair and never sends it. The site's half is useless alone.
- A breach at the site leaks nothing you reused elsewhere.
- It cannot be phished, because it is tied to the real address of the site.
- No fingerprint reader needed. Microsoft lists PIN alongside fingerprint and face.
- A passkey stored on one device only is lost with that device.
- Keep the password until you have a second way in, and add a passkey on your phone too.
- Say yes on email, your main account and anything holding money. The rest can wait.
Where to Next
Say yes the next time your email provider offers you one. That is the account everything else can be reset through, so it is the one worth protecting first.
Then add one on your phone for the same account. Two devices is what turns this from a nice idea into something you can rely on.
Leave the password in place for now. Nothing is gained by deleting it before you have used the passkey a few times.
And if you hit a site that offers a passkey and then keeps asking for the password anyway, tell me which in the comments. That gap is real and worth a list.

Isaac Smith is the founder and editor of PC Glance, a website that covers computers, laptops, and technology. He is a tech enthusiast and a computer geek who loves to share his insights and help his readers make smart choices when buying tech gadgets or laptops. He is always curious and updated about the latest tech trends.