Preserve Passkey Sign-In Before Retiring a Windows PC
A successful sign-in on the old PC does not show where its passkey is stored. Before replacing that computer, identify whether each important account uses a credential tied to the device or one available through a synced credential manager.
Make a private list of the accounts you need for work. Record the sign-in method and provider, without copying secrets into the list. Keep the old computer available while the replacement is being tested.
Establish where the passkey lives
On Windows 11, open Settings, Accounts, Passkeys to view credentials stored locally on the device. Passkeys kept by a synced manager are managed with that provider. An empty local list does not establish that you have no passkeys elsewhere.
For a personal Microsoft account, its Advanced Security Options dashboard also shows passkey information, including the storage location, last use and an editable name. Use recognisable names to distinguish the old PC from other legitimate methods.
Microsoft says a passkey stored on the old device needs a new passkey arrangement when that device is replaced. A passkey held in a synced credential manager instead becomes available through that manager's account; it does not require a separate new passkey simply because the PC changed. Organisation policy may restrict available providers.
Prove the replacement before removing the original
On the new PC, follow the account provider's supported sign-in and passkey setup process. Keep an approved alternative recovery method available. Do not remove the old credential as the first migration step.
Test a fresh sign-in to the intended account and observe which provider actually authenticates it. An already open session or a password fallback is not proof that the replacement passkey works. Confirm that the account and required service are the ones you intended to retain.
Only after the new route is established should you remove a retired passkey through its relevant account and storage controls. Microsoft's guidance explicitly puts adding new access before removing old access; work or school accounts can require removal both at the account and where the passkey was saved.
Finish the inventory with the accepted sign-in route and the device being retired. Keep account access verification separate from copying documents, since success in one does not establish the other.
Sources: Microsoft managing saved passkeys.