Passkeys are worth it. Losing the phone is the part nobody plans
Why this is worth changing
A passkey replaces the password with something a fake website cannot capture. Australia's cyber security agency describes it as needing two different keys to unlock a door: one held by the provider of your account, the other stored on your device or on a physical FIDO2 security key you buy and connect (ASD, passkeys).
The benefit that matters most is the one people skip past. A passkey helps stop criminals stealing your password through scams or by tricking you into logging in to a fake website. That is precisely the attack that beats a code from a text or an authenticator app, because a convincing fake login page will happily collect the code along with the password.
That is why the agency calls passkeys and their equivalents phishing resistant, and advises that if you cannot use a passkey you should use a different type of phishing resistant multi factor authentication.
So far so good. The problem is what happens next.
The trap in the good advice
The same guidance says that once your passkey is created, you should make sure the ability to log in with a password is disabled, so a criminal cannot use the password to get in.
That is correct, and it is also the moment you can build yourself a trap. If the only passkey lives on one phone, and the password route is now switched off, then a lost, stolen, drowned or factory reset phone is not an inconvenience. It is the account.
Which is why the recovery plan is not an optional extra to do later. It is part of turning the passkey on.
Your phone number is the weak recovery route
Most people's fallback is a text message to their mobile. That is the route worth being careful about, and there is Australian evidence for why.
In September 2026 the communications regulator penalised Telstra $277,200 after finding that between January and October 2025 it failed to use required identity authentication in 15 unauthorised SIM swaps, and that in 13 further instances its agents did not give extra fraud protection to customers already flagged as at risk. Customers reported combined losses of at least $39,500. It was the seventh action in a crackdown in which telcos have now paid more than $5 million (ACMA, 3 September 2026).
A SIM swap moves your mobile number to someone else's SIM. Once that happens, every account that recovers through a text goes with it. The regulator's own advice if you suspect it: contact your telco and your financial institution immediately.
The lesson for this page is narrow and practical. A phone number is a convenience, not a vault. If it is the only way back into your email, then your email is only as strong as a phone shop's identity check on a busy afternoon.
Set it up so you cannot be locked out
Work through this per account, starting with the one that resets all the others.
- Start with email. Whichever mailbox receives the password resets for everything else is the account that matters most. Secure that first and the rest gets easier.
- Create the passkey on a device you trust. The guidance is specific: use a device you trust not to have malware, use a reputable password manager, avoid a device you share with anyone, and avoid storing passkeys for personal accounts on an employer owned device.
- Create the second way in before you switch anything off. For important accounts the agency suggests a FIDO2 security key, and recommends creating and storing a backup passkey on a second FIDO2 security key in case the first is lost, stolen or damaged. Two keys, and they do not travel in the same bag.
- Then disable password login, as the guidance advises, now that you have proved you can get in another way.
- Write down the recovery arrangements and where the second key lives. Not the passkey itself, which cannot be written down. The arrangement: which accounts have passkeys, what the backup is, who can reach it.
- Rehearse it. Put the everyday device in a drawer and get into the account with the backup alone. That fifteen minute test is the whole point, and it is the step almost nobody does.
- Take the phone number off the critical path where an account allows it. Keep it for notifications if you like. Stop it being the master key.
Synced or stuck to one device
There are two ways passkeys live, and the difference matters for both convenience and risk.
A passkey can sync between your devices, and in most cases you can use the same passkey to log in from any of them. That is convenient and it is a real form of backup, because the passkey is not trapped on one handset.
The trade off is stated plainly in the guidance: avoid syncing passkeys to untrusted or shared devices, because every device you sync to gives criminals another opportunity to steal them.
A passkey on a physical security key does the opposite. It does not roam, which is exactly why it is recommended for the most important accounts, and exactly why the second key exists.
Neither is the right answer for everything. Sync for the accounts you use constantly across your own devices; keys for the small handful you cannot afford to lose.
For a business, this is a register not a habit
If more than one person is involved, the thing that fails is not the technology. It is that nobody knows who can get back into what.
Keep a short written record of the accounts that matter, which have passkeys, what the backup route is for each, and which person can perform a recovery. Keep it with the continuity plan rather than in the head of whoever set it up. The business continuity plan template is a reasonable place for it.
The related question, when someone with access leaves, is covered in the Microsoft 365 staff handover checklist.
Ask us to set this up properly
Frequently asked questions
Are passkeys actually safer than a code from an authenticator app?
For the attack that matters most, yes. Australia's cyber security agency says passkeys help stop criminals stealing your account password through scams or by tricking you into logging in to a fake website. A one time code, whether it arrives by text, email or an authenticator app, can be captured by a convincing fake login page in the moment you type it. That is the difference the word phishing resistant is pointing at.
What happens if I lose the phone with my passkey on it?
That depends entirely on what you set up beforehand. If the passkey syncs across your own devices, you sign in from another one. If it lived only on that handset and you had already turned off password login, you are relying on whatever recovery the provider offers. Set the second route up first, and this question stops being frightening.
Should I really turn off password login?
The guidance says to, once the passkey exists, so a criminal cannot use the password to get in. The order matters: prove you have a second way in first, then disable the password. Doing it the other way around is how people lock themselves out.
Is a physical security key worth buying?
For your most important accounts, the agency suggests it, and recommends a backup passkey on a second FIDO2 key in case the first is lost, stolen or damaged. Two keys stored in different places is the arrangement. For everyday accounts, passkeys on your own trusted devices are usually enough.
Is it safe to sync passkeys?
It is a normal and useful way to use them, with one stated caution: avoid syncing to untrusted or shared devices, because every device you sync to is another place a criminal could steal them from. Sync across your own devices, not the family computer at the front desk.
Why does a SIM swap matter if I use passkeys?
Because recovery is the back door. If your account still falls back to a text message when something goes wrong, then whoever controls your mobile number controls the account. The regulator penalised a carrier in September 2026 over unauthorised SIM swaps where identity checks were not followed, so this is a live risk rather than a theoretical one. Take the phone number off the critical path where you can.
I think my number has been taken over. What now?
Contact your telco and your financial institution immediately, which is the regulator's own advice. Then work through the accounts that recover through that number, starting with your email. IDCARE, the national identity support service, can be reached on 1800 595 160.