How to Use Passkeys in Windows 11: A Simple Guide

Passkeys let you sign in to supported websites and apps without typing a traditional password. Depending on where you save a passkey, Windows 11 can protect it with Windows Hello, use one from a synced credential manager, or authenticate with a phone or security key.

The website or app must support passkeys before you can create one. The exact prompts vary by service and browser, but Windows handles the authentication once a supported passkey option is selected.

Set up Windows Hello for passkeys stored on your PC

If you save a passkey directly on your Windows 11 PC, Windows Hello protects it with your PIN, fingerprint, or face.

  1. Open Settings.
  2. Select Accounts.
  3. Select Sign-in options.
  4. Set up at least one Windows Hello method, such as a PIN, fingerprint, or facial recognition.

A Windows Hello PIN is enough for locally stored passkeys, so you do not need a fingerprint reader or compatible camera.

Windows Hello is not the only way Windows can use a passkey. You can also use passkeys stored in a supported synced credential manager, on a FIDO2 security key, or on another device such as your phone.

Create a passkey for a website or account

You normally create a passkey from the security or sign-in settings for the website or service you are using.

  1. Open the website or app and sign in to your account.
  2. Open its security, password, or sign-in settings.
  3. Look for an option to create, add, or set up a passkey.
  4. Choose where you want to save the passkey when Windows or your browser asks.
  5. Confirm the request using the authentication method for that location, such as Windows Hello, your phone’s unlock method, or a security key.

The choices you see can include a Windows device, a password manager, a phone or tablet, and a physical security key. The website and the credential providers installed on your PC determine which options are available.

Use a passkey to sign in

  1. Open the website or app.
  2. Choose Sign in with a passkey or the equivalent option.
  3. Select the passkey or device you want to use if Windows gives you a choice.
  4. Approve the sign-in using Windows Hello, your password manager, phone, or security key.

If the passkey is stored locally on the Windows PC, you can usually approve the request with your Windows Hello PIN, fingerprint, or face.

The website never needs your Windows Hello PIN. Windows uses that local verification to unlock the passkey and complete the cryptographic sign-in.

Use a passkey from your phone

  1. At the website’s passkey prompt, choose the option to use another device, phone, tablet, or similar wording.
  2. Select the phone or tablet option if Windows asks.
  3. Scan the QR code with your mobile device when one appears.
  4. Approve the request on the phone using its normal unlock method.
  5. Wait for the website on the PC to finish signing in.

For cross-device passkey authentication, Windows and the mobile device need Bluetooth enabled and an Internet connection. Bluetooth is used as part of the proximity check.

Use a physical security key

A FIDO2-compatible security key can also store or provide a passkey.

Connect the key when prompted, select the security-key option, and follow the instructions on the screen. Depending on the key, you may need to touch it or enter its PIN.

A security key can be useful if you do not want a particular passkey stored on the PC or synced through a cloud credential manager.

Manage passkeys in Windows 11

Windows 11 has a dedicated page for passkeys saved locally on the PC.

  1. Open Settings.
  2. Select Accounts.
  3. Select Passkeys.
  4. Find the locally stored passkey you want to manage.
  5. Open its menu to see the available action, such as deleting the passkey from the device.

This page manages passkeys stored on the Windows device. It does not replace the security settings for the website or service itself. Removing a local passkey and removing a sign-in method from an online account are separate actions.

On supported current Windows 11 releases, Settings > Accounts > Passkeys > Advanced options contains controls for passkey services and supported third-party passkey providers.

Passkeys saved in a synced credential manager are managed by that provider. Examples include Microsoft Password Manager, Google Password Manager, Apple iCloud Keychain, and other supported providers.

Local passkeys and synced passkeys are different

Where you save a passkey determines whether it is available elsewhere.

A device-bound passkey is stored only on the device where it was created. If you save a passkey directly to the Windows PC with Windows Hello, it does not automatically become available on your other devices.

A synced passkey is stored through a credential manager or cloud service. A supported provider can make that passkey available on other devices signed in to the same service.

If you choose device-bound passkeys, it is a good idea to maintain another supported sign-in or recovery method for important accounts. Losing the only device that holds a passkey can otherwise leave you dependent on the website’s account-recovery process.

What to do if passkeys do not work

  1. Make sure you are using a supported browser or app. Current mainstream browsers support passkeys, but the prompts can differ.
  2. Check the authenticator you are trying to use. For a passkey stored directly on the PC, confirm Windows Hello is set up under Settings > Accounts > Sign-in options.
  3. Check Passkey access. On Windows 11 24H2 and later, open Settings > Privacy & security > Passkey access and make sure the app is allowed to use passkeys. If access was denied, passkey registration or authentication can fail in that app.
  4. Update Windows 11 and the browser or app.
  5. Check the website’s account settings. Some services require you to create or enable a passkey before the option appears at sign-in.
  6. If you are using a phone for cross-device authentication, make sure Bluetooth is enabled on both devices and both devices are connected to the Internet.

If the website itself does not support passkeys, there is no Windows setting that can force it to use them.

Passkeys are not saved passwords

A passkey uses public-key cryptography rather than a reusable password. The website stores a public key, while the credential needed to authenticate remains protected by your device or credential manager.

This also makes passkeys resistant to ordinary phishing. A passkey is associated with the website or service for which it was created, so a look-alike phishing site cannot simply ask you to type the credential into a fake form.

Windows supplies the local or cross-device authentication experience, but the website still decides whether your account supports passkeys.

Frequently asked questions

Can I use the same passkey on my PC and phone?

It depends on where the passkey is stored. A passkey in a supported synced credential manager can be available across devices that use that provider. A passkey stored only on the Windows PC is device-bound and does not automatically sync to your phone.

You can also keep a passkey on your phone and use it to authenticate on a nearby Windows PC through cross-device authentication. Some services let you register several separate passkeys for the same account.

Can I still use my password after creating a passkey?

That depends on the website. Some services keep passwords or other sign-in methods available, while others may encourage or allow a more passwordless setup.

Before removing an old sign-in method, make sure you understand the account’s recovery options and have another way to regain access if your passkey device is lost.

Do passkeys work in every browser?

No. Passkey support depends on the operating system, browser, website, and credential provider. Current mainstream browsers support passkeys, but an older browser or a managed work PC may offer different options.

Can I delete a passkey?

Yes. For passkeys stored locally by Windows, go to Settings > Accounts > Passkeys and use the menu for the passkey you want to remove.

You may also need to remove that sign-in method from the website or account’s own security settings. Passkeys stored in a synced credential manager should be managed through that provider.

Join Our Free Newsletter

Featured guides and deals

You may opt out at any time. Read our Privacy Policy