A person uses a laptop amid glowing cybersecurity icons, biometric authentication, and a futuristic digital landscape.
GOV.UK One Login’s move toward passkeys should not be read as a switch that removes passwords from citizens’ accounts. The available user guidance describes passkeys as an additional, optional way to sign in, while retaining password-and-security-code routes when a passkey is unavailable. For Windows users, that distinction matters: the change can make routine access more convenient on a suitably protected PC, but it does not remove the need to protect the device, retain recovery access, or judge the wider service on more than its sign-in screen.

Passwords are still part of the One Login journey​

The most important practical point is that a passkey is not mandatory under the published One Login guidance. A person can continue to use a password, and there may still be occasions when a password and security code are needed.

That makes headlines suggesting that government is simply “ending” passwords misleading. A passkey may become the preferred method for someone who has set one up, but it sits alongside other sign-in and recovery paths rather than replacing them outright.

This is more than a matter of wording. An account system needs a workable route for people who cannot use their normal device, do not have a passkey available at a particular moment, or have lost access to it. The retained password-and-code path is therefore a resilience feature as well as a transition mechanism. It also means users should not assume that creating a passkey allows them to forget every other aspect of account recovery.

For people who prefer not to use a passkey, the continued password option is significant. Public digital services must accommodate a broad range of devices, confidence levels and access circumstances. Optional adoption gives users time to decide whether their own computer or phone is an appropriate place to use a passkey.

What Windows users need to set up a passkey​

GOV.UK lists a Windows computer running Windows 10 or later as a supported device for setting up a passkey. The computer must have a screen lock configured.

That requirement should be treated as fundamental, not as a minor setup hurdle. The screen lock is the protection that stands between someone with physical access to a Windows PC and the local method used to unlock the passkey. Before setting one up, users should confirm that their normal Windows lock method works reliably and that other people cannot casually use the device while it is unlocked.

The One Login guidance says a passkey can be unlocked with a face or fingerprint scan, or with a device passcode, PIN or pattern. GOV.UK says biometric data is not shared with One Login or the services accessed through it. The published guidance lists PINs among the device-unlock methods, but it does not expressly make the same no-storage or no-visibility claim about PINs.

The choice of unlock method will depend on the Windows device and its configuration. A machine with compatible biometric hardware may offer a face or fingerprint route; another may use a PIN or other configured device credential. The key consideration is not whether one option sounds more sophisticated than another, but whether the chosen device is genuinely under the user’s control and has an effective screen lock.

Users should be cautious about setting up a passkey on a shared family PC, a workplace computer that others can access, or a device whose lock arrangements they do not control. The published eligibility of Windows 10 and later does not by itself make every such machine suitable for every account holder.

Convenience does not eliminate recovery planning​

A passkey can reduce the number of occasions on which a person manually enters an account password. That does not mean access becomes independent of every other factor around the device.

The official guidance explicitly preserves cases in which a password and security code may be required. Users should therefore keep their account details and their access to any relevant security-code route in a form they can use when their usual passkey device is unavailable. This is especially important before replacing, resetting, losing or sending a PC for repair.

The sensible approach is to view a passkey as an added sign-in option, not as an instruction to dismantle all existing recovery arrangements. If the everyday Windows computer is unavailable, the existence of an alternative route may determine whether an urgent government-service task can still be completed.

This is also why government communications need to be precise. Telling people that passwords have been abolished could encourage them to overlook the very fallback mechanisms the service says remain necessary. A clearer message is that the normal sign-in experience may change for users who choose a passkey, while password-and-code access remains relevant.

A passkey does not settle wider platform-security questions​

It is reasonable to distinguish the security of a sign-in method from the security of the entire digital service behind it. Even a well-designed account-authentication step cannot, on its own, answer questions about privileged administration, monitoring, service infrastructure or the handling of identity data elsewhere in the platform.

That distinction is particularly important for One Login because independent reporting in May 2025 described a red-team exercise that found privileged access to the platform could be compromised without detection by security monitoring tools. The reported finding concerned privileged access and monitoring, rather than an assertion that passkey sign-in was unsafe. Still, it is material context: it illustrates why improved authentication for end users should not be treated as proof that every service-level risk has disappeared.

Separate reporting in September 2026 said that the Government Digital Service had engaged a security consultancy for the government’s formal cyber-resilience audit of the One Login platform. The public material reviewed here does not establish the outcome of that assessment, nor does it establish whether the previously reported red-team issue was fully remediated.

For citizens, the practical conclusion is measured rather than alarmist. Use the available sign-in protections and a secure Windows device, but do not infer from the arrival of passkeys that broader oversight, testing and remediation no longer matter. For policymakers, the same distinction argues for transparent assurance around the full service, not only adoption of a new sign-in experience.

Accessibility must cover the whole account journey​

In a parliamentary submission, the Royal National Institute of Blind People said it was aware of cases in which people with sight loss had been unable to complete identity verification in the One Login app.

That evidence should not be misrepresented as proof that passkey sign-in itself is inaccessible. RNIB’s submission concerns the wider app-based identity-verification stage, which is distinct from passkey sign-in. Nevertheless, it is an important warning against evaluating accessibility only at the final sign-in prompt.

A user may have a compatible Windows 10 or later PC, a screen lock and a usable passkey method, yet still encounter barriers earlier in the process. Public services should therefore assess the complete path: identity verification, account recovery, device changes, alternative sign-in methods and support when something fails. Optional passwords and security codes have practical inclusion value only if those alternatives remain understandable and workable in real circumstances.

For Windows users with accessibility needs, retaining a familiar route can be as important as offering a newer one. Choice is beneficial when each route is designed, tested and supported to a comparable standard.

Be careful when interpreting user-count claims​

One publicly recorded government figure stated that, as of June 2026, more than 22 million users had proven their identity, enabling access to more than 240 government services. That is an indication of One Login’s substantial reach, but it is not the same measure as passkey use, passkey eligibility or successful passkey setup.

Those distinctions are worth preserving when assessing claims about the scale of any passkey availability or migration effort. A count of people who have completed identity proofing does not automatically reveal how many actively sign in, how many own compatible devices, how many choose passkeys, or how many may need password-and-code fallback. Different user metrics can all be valid while describing different populations.

For the public, the relevant test is less about a headline total than whether the service works reliably for their own circumstances: their Windows version, screen lock, access needs and ability to recover an account after a device problem. For government, publishing clearly defined measures would make it easier to distinguish the reach of One Login as a whole from adoption of a particular authentication option.

The practical takeaway​

Windows users can treat One Login passkeys as a supported option on Windows 10 and later, provided the PC has a screen lock. The passkey may be unlocked using a biometric method or a device credential such as a PIN. GOV.UK says biometric data is not shared with One Login or the services accessed through it; although the guidance lists PINs as a device-unlock method, it does not expressly make a corresponding claim about whether One Login sees or stores PIN information.

But this is not a password shutdown. Passwords and security codes remain part of the guidance, including when a passkey cannot be used. Users should set up a passkey only on a device they control, maintain a dependable lock method, and preserve their ability to use the service if that device is lost or unavailable.

The broader public-policy lesson is equally straightforward: safer and easier sign-in can be valuable, but it must be accompanied by accessible identity verification, credible recovery paths and ongoing scrutiny of the entire One Login platform. A new sign-in option is an important component of a public digital service, not a substitute for proving that the whole service is secure, resilient and usable for everyone.