The phone upgrade excitement is real… until your passkeys make it weird
#I love changing phones. Like, genuinely love it. The unboxing, the weird plastic peel, the first boot where everything feels too clean and too fast and you’re convinced your life is about to become organized because the new phone has 17% better battery life. But I’ll be honest, the first time I changed phones after going heavy on passkeys, I got humbled pretty quick. I had this smug little feeling, you know, like “passwords are old news, I’m a modern authentication person now.” Then one banking app asked me to confirm from my old device, one developer account wanted my passkey, and my old phone was already in a trade-in box on my kitchen table. Not my finest tech moment.¶
Passkeys are fantastic. I’m all in on them. They’re phishing-resistant, they remove a ton of password drama, and when they work they feel almost magical. Face ID, fingerprint, PIN, boom, you’re in. But that magic depends on some boring behind-the-scenes stuff: cloud sync, device trust, account recovery details, backup methods, and whether the service you’re logging into actually supports passkey recovery in a sane way. And boring stuff is exactly what we forget when we’re excited about a shiny new phone.¶
Quick refresher: what you’re actually moving when you “move passkeys”
#A passkey is not just a password saved in a prettier password manager. Under the hood it’s based on public-key cryptography. The website or app gets a public key, your device keeps the private key, and when you sign in your device proves it has the private key without sending it to the website. That’s why passkeys are such a big deal for phishing. If some fake login page tries to trick you, the passkey generally won’t authenticate to the wrong domain. Very nice. Very “future is finally useful” energy.¶
But here’s the part that matters before changing phones: your passkeys may be synced, local-only, stored in a password manager, stored in iCloud Keychain, Google Password Manager, Windows Hello, a hardware security key, or some combination of these. Apple, Google, Microsoft, and the FIDO Alliance have all pushed passkeys as the direction account login is going, but the user experience still varies by platform and app. That’s the annoying bit. One account might follow you to the new phone with zero effort. Another account might stare at you like it has never met you in it’s life.¶
My rule now is simple: don’t wipe, trade in, sell, factory reset, or “just quickly erase” your old phone until you have signed into your important accounts on the new one. Not checked the apps are installed. Actually signed in.
My pre-phone-change passkey checklist, the one I wish I had years ago
#This is the checklist I use now before switching phones, especially if I’m moving between iPhone and Android or changing the main account that controls my cloud sync. It’s a little paranoid, sure. But authentication paranoia is the good kind of paranoia. The bad kind is when you’re sitting on the floor at 11:47pm trying to remember if you saved backup codes in a Notes app that is, tragically, locked behind the account you can’t access.¶
- Make a list of the accounts that would ruin your week if you got locked out: primary email, Apple ID or Google Account, Microsoft account, banking, brokerage, work SSO, GitHub, domain registrar, cloud storage, password manager, crypto wallets if you use them, and anything tied to your phone number.
- Open each account’s security settings while you still have the old phone. Look for passkeys, security keys, two-step verification, recovery email, recovery phone, backup codes, trusted devices, and account recovery options.
- Confirm where the passkey lives. Is it in iCloud Keychain? Google Password Manager? 1Password, Dashlane, Bitwarden, NordPass, or another manager? Windows Hello? A physical security key? If you don’t know, that’s not a failure, but it is a warning light.
- Add at least one backup sign-in method before the move. For me that usually means a second passkey on another device, a hardware security key, or fresh backup codes saved somewhere safe. Not in the same phone you’re about to wipe. Please don’t do that.
Step 1: check your sync before you trust it
#This sounds obvious, and yet this is where I personally messed up. If your passkeys are supposed to sync through iCloud Keychain, make sure iCloud Keychain is turned on and actually syncing. On Apple gear, passkeys saved to iCloud Keychain can be available across your signed-in Apple devices, assuming everything is configured properly. But if you’ve disabled Keychain sync because you were “cleaning up iCloud settings” six months ago, well… welcome to the consequences department.¶
On Android and Chrome, Google Password Manager can sync passkeys with your Google Account, again depending on setup and the app or browser involved. Password managers can also store passkeys, and honestly I like that because it makes cross-platform life less dramatic. I bounce between devices more than a normal person probably should, so having passkeys in a dedicated password manager has saved me more than once. Still, don’t assume. Open the password manager on another device and check that the passkey is visible or usable. Actually test it with a non-critical account if you can.¶
One tiny thing that catches people: a hardware security key passkey does not magically sync into your new phone. That’s kind of the point. If your login depends on a YubiKey or similar device, keep that key with you, and ideally have a second one registered. I know, hardware keys cost money and feel nerdy. But for your email or password manager? Worth it. Absolutely worth it.¶
Step 2: add a second passkey before the old phone leaves your hand
#If a service lets you register multiple passkeys, do it. Add the new phone as a passkey holder while you still have the old phone available to approve logins. Add your laptop too, if that makes sense. I like having one passkey on my phone, one through my password manager, and one hardware key for the really serious stuff. That might be overkill for some people. Also, no it’s not overkill, because I have seen too many account recovery horror stories and I’m tired.¶
The flow is usually something like this: sign in on the old phone or laptop, go to security settings, choose “add passkey,” then scan a QR code or use Bluetooth proximity to create the passkey on the new device. The exact labels differ. Some sites call them “passkeys,” some bury them under “security keys,” and a few still make the whole page feel like it was designed during the era of tiny gray buttons. Be patient. Authentication settings are somehow always in the least fun corner of every app.¶
- Email account first. If your email is gone, everything else becomes harder.
- Password manager second. That’s your keys-to-the-kingdom app.
- Banking and payment apps next, because they often have extra device trust checks.
- Developer, cloud, and domain accounts after that. Losing a domain registrar login is a very special kind of stress.
Step 3: don’t forget recovery codes, because passkeys don’t remove recovery pain
#There’s this myth that passkeys mean account recovery is solved. Nope. Passkeys make sign-in safer and smoother, but recovery is still the messy human part. People lose phones. Phones get stolen. Cloud accounts get locked. Biometrics fail after a reboot and suddenly you need the device PIN you changed during a half-asleep moment. Life happens, basically.¶
Before switching phones, regenerate backup codes for important accounts if they exist, then save them in a sane place. I personally keep recovery codes in my password manager and also keep a printed copy for a couple of critical accounts in a boring folder that nobody would ever want to read. Not glamorous. Works though. If you already lost access to a security key or you’re in the “uh oh, I wiped the old phone” zone, this is where a companion recovery process matters. I’d honestly read something like Lost Security Key Checklist: How to Get Back Into Your Accounts Safely before you start panic-clicking recovery forms, because those forms can get weird fast.¶
Also check recovery emails and phone numbers. I know nobody wants to maintain recovery details, but old phone numbers are account lockout magnets. If your bank or email provider sends recovery codes to a number you haven’t used since 2019, congratulations, you’ve built a tiny authentication trap for your future self.¶
Step 4: your phone number is still annoyingly important
#I wish phone numbers mattered less in account security. SMS codes are weaker than passkeys, weaker than authenticator apps, and definitely weaker than hardware keys. SIM swap attacks are real enough that I avoid SMS for anything sensitive when I can. But in practice, phone numbers still matter. Banks use them. Delivery apps use them. Some government portals use them. Random old accounts from 2014 absolutely use them, because apparently we all made security decisions in a cave back then.¶
So before you change phones, make sure your number will transfer properly, especially if you’re moving eSIMs. If you use an eSIM, check your carrier’s transfer process before wiping the old device. Some transfers are smooth, some want app confirmation, and some make you feel like you’re negotiating with a vending machine. Keep your old phone powered on and connected until calls, texts, and data work on the new phone.¶
If you’re trading in the device, I’d also turn on the protective stuff before the transition, not after. Find My on iPhone, Google’s Find Hub features on Android, device lock settings, stolen device protections, all that. The phone is an account-access device now, not just a rectangle for memes and maps. I wrote down my own setup after a friend lost a phone in an airport lounge, and the checklist in Stolen Phone Protection Checklist: iPhone and Android Settings to Turn On fits weirdly well with passkey prep too.¶
Step 5: authenticator apps, because they love causing last-minute chaos
#Passkeys might be replacing passwords for some logins, but a lot of accounts still use authenticator apps. Google Authenticator, Microsoft Authenticator, Authy, 2FAS, Duo, Okta Verify, and whatever your workplace forced you to install after a security training video. These apps are not all the same when it comes to backup and transfer. Some sync tokens to the cloud. Some require export. Some work accounts need admin re-enrollment. Some apps are tied to device trust in a way that is not obvious until the old phone is gone and you are suddenly emailing IT with the subject line “sorry, urgent.”¶
Before wiping your old phone, open your authenticator app and check its backup or transfer options. If you use Microsoft Authenticator for personal accounts, check cloud backup settings. If you use Google Authenticator, check the transfer or sync behavior in your version. If you use Duo or Okta for work, ask IT before switching devices, not after. This is one of those “five minutes now or two days of pain later” jobs.¶
Tiny test I do now, because I’m tired of surprises
#After setting up the new phone, I pick three accounts and test the full sign-in flow from scratch: email, password manager, and one financial account. Not just opening an already logged-in app. I log out on a browser, sign back in, approve with the new phone, and make sure recovery prompts aren’t pointing at the old device. It feels silly until it saves you. Then it feels genius, and you get to be smug for about six minutes.¶
Step 6: account-by-account notes, because the “ecosystem” matters
#Changing from iPhone to iPhone is usually the least dramatic if iCloud Keychain is healthy and your Apple ID recovery settings are good. Still, check your trusted phone numbers, recovery contact if you use one, and whether Advanced Data Protection changes your recovery responsibilities. Apple gives you strong privacy options, which I like, but strong privacy often means you are more responsible for recovery. That’s the deal.¶
Android to Android can be smooth too, especially if your Google Account and Google Password Manager are syncing properly. But if your old Android device has a work profile, custom ROM weirdness, beta software, or a manufacturer-specific transfer tool involved, don’t assume all security state follows perfectly. And Android to iPhone, or iPhone to Android, is where I become extra careful. Cross-platform passkey support is much better than it used to be, but individual apps can still be fussy. I know that sounds vague. It is vague. The ecosystem is better, but it’s not boring yet.¶
For Windows users, Windows Hello can be part of your passkey life too. Same with Chrome, Edge, Safari, and password managers that support passkeys. My practical advice is to avoid having only one platform hold your entire login future. If everything depends on one phone and one cloud account, your “passwordless” life can become “accessless” real quick.¶
My actual checklist, the fridge-door version
#Here’s the trimmed version I keep in my notes app. Yes, I keep the checklist in the phone that I’m replacing, which is dumb, so I also keep it in my password manager now. Growth.¶
- Update the old phone fully enough that account transfer tools and security apps aren’t broken by ancient software.
- Confirm iCloud Keychain, Google Password Manager, or your passkey-supporting password manager is syncing.
- Sign into your primary email on a second device before touching anything else.
- Register the new phone as a passkey for major accounts before wiping the old phone.
- Add or verify backup methods: hardware key, second device, recovery codes, backup email, trusted phone number.
- Export or sync authenticator app codes, and confirm work MFA requirements with IT.
- Move eSIM or physical SIM carefully, then test calls, texts, and mobile data.
- Log into banking, cloud, developer, and password manager accounts on the new device.
- Keep the old phone nearby for at least a few days if you can. A week is nicer. Two weeks if you’re anxious like me.
- Only after testing, remove the old phone from trusted device lists and factory reset it.
What to do if you already wiped the old phone
#First: breathe. I know that’s annoying advice. I hate when people tell me to breathe when the problem is clearly that I deleted my digital identity rectangle. But seriously, don’t start randomly removing security settings or retrying logins until accounts lock you out. Go in order.¶
- Try signing in from a device that was already trusted, like your laptop or tablet. Existing sessions can be lifesavers.
- Check your password manager for saved recovery codes, old backup codes, or notes you forgot you made.
- Use a hardware security key if you registered one. This is the moment hardware keys earn their little spot on your keychain.
- Use official account recovery only from the real website or app. Don’t click “support” links from random emails, forums, or search ads.
- If it’s a work account, stop guessing and contact IT. Failed attempts can make their job harder.
For accounts that use passkeys synced through a cloud account, getting back into the cloud account may restore access on the new device. For local-only passkeys or device-bound credentials, wiping the old device can mean that credential is gone. That doesn’t always mean the account is gone, but it does mean you’ll need another recovery route. This is why I keep harping on backup methods. Sorry, but also not sorry.¶
The trade-in trap nobody talks about enough
#Phone trade-ins create this weird pressure. The carrier says send it back quickly. The store rep says it’ll be fine. The box is sitting there. You want the credit. I get it. But authentication doesn’t care about your trade-in deadline. If your old phone is still a trusted device for Apple, Google, Microsoft, your bank, your work account, or your password manager, then it is part of your security system until you replace that trust somewhere else.¶
My move now is boring but effective: I set up the new phone, test major logins, keep the old phone on Wi-Fi for a few days, then remove it from trusted devices, sign it out of accounts, erase it, and only then send it away. The “few days” part has saved me twice. Once for a banking app that wanted old-device confirmation, and once for a travel app that had some bizarre device binding thing going on. Travel apps, by the way, are chaotic little gremlins. No one talks about this enough.¶
A slightly opinionated setup I recommend
#If you want my current favorite setup, it’s this: use passkeys wherever they’re supported, store them in a sync system you understand, keep your primary email extremely protected, and register at least one hardware security key for the accounts that truly matter. Not every pizza app needs Fort Knox. But your email does. Your password manager does. Your financial accounts probably do. Your domain registrar definitely does if you own domains.¶
I also like having a password manager that supports passkeys because it gives me a more consistent layer across devices. That said, platform passkeys are very convenient, and for lots of people iCloud Keychain or Google Password Manager is the simplest and best answer. The perfect setup is the one you will actually maintain. I’ve built elaborate security systems before and then abandoned them because they were annoying. Annoying security quietly becomes no security. That’s a lesson I learned the dumb way.¶
Security should be strong enough to protect you, but not so complicated that future-you refuses to use it. Future-you is tired and has groceries in the car.
The boring final cleanup after everything works
#Once the new phone is fully working, go back and clean up. Remove the old phone from trusted device lists in Apple ID, Google Account, Microsoft account, your password manager, and financial apps where possible. Revoke old sessions you don’t recognize. Rename the new device if your account dashboard shows three identical “iPhone” entries and you have no idea which is which. I name mine with the model and year now because apparently I am becoming the kind of person who labels cables too.¶
Then factory reset the old phone from settings, not by just deleting apps one at a time like it’s 2008. Confirm Find My or Factory Reset Protection steps are handled properly so the next owner or trade-in center doesn’t get activation locked. If you use a physical SIM, remove it. If you use eSIM, make sure the line is active on the new device and erased from the old one. And if you had work profiles or device management, follow your company’s offboarding instructions. Work MDM can be fussy, and not in a cute way.¶
Final thought: passkeys are worth the prep
#I don’t want this to sound like passkeys are scary. They’re not. I genuinely think they’re one of the best changes to everyday security we’ve had in years. Passwords trained all of us into bad habits: reuse, weak resets, phishing panic, sticky notes, and that one password with the exclamation mark at the end like it’s somehow armor. Passkeys fix a lot of that. But changing phones is where the real world pokes the elegant security model and says, “cool, but what if the user already mailed the old device to a warehouse in Ohio?”¶
So yeah, be excited about the new phone. Peel the plastic. Take photos of your coffee to test the camera even though it’s the same coffee. Install all your apps and pretend this time your home screen will stay clean. But before you wipe the old phone, do the passkey recovery checklist. Test the logins. Save the codes. Add the backup methods. Future-you will be so ridiculously grateful, and honestly, future-you deserves one easy win. If you like practical tech checklists and slightly nerdy security rabbit holes, I’d casually point you toward AllBlogs.in too, because that’s exactly the kind of stuff I end up reading when I’m supposed to be doing something else.¶














