RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Defense

Defense / From the archive · 5 May 2022 event · prepared 16 September 2026

Apple, Google and Microsoft committed to passkeys on the same day

A joint 2022 announcement describes what a passkey is meant to replace and what it does not address on its own.

Visual for this record: Apple, Google and Microsoft committed to passkeys on the same day
Visual published by storage.googleapis.com, shown for identification of the record. Credit: storage.googleapis.com · source page ↗ Rights: owner-review-pending.

What happened

On 5 May 2022, Apple, Google and Microsoft jointly announced plans to expand support for FIDO Alliance and W3C passwordless sign-in standards across their platforms over the following year. The core feature the companies committed to is what the industry now calls a passkey: a FIDO credential that, unlike earlier hardware-bound security keys, can sync across a person's own devices through the platform's existing account system, so a phone, laptop and tablet can each present the same sign-in capability without a separate enrollment step for every device. Apple's own announcement described the sign-in action as identical to unlocking the device: a fingerprint, a face scan or a PIN. The companies also committed to letting a phone serve as an authenticator for a sign-in attempted on a nearby computer, regardless of operating system or browser.

Confidence and limits

The announcement is a statement of intent by three platform vendors, not a technical specification or an independent evaluation. It documents what each company said it would build, not a verified account of adoption, and the companies' own promotional framing, that passkeys are phishing-resistant, reflects the credential's cryptographic design rather than a claim that every implementation is equally careful. The FIDO Alliance's passkeys reference page, a living document as retrieved on 16 September 2026, explains the underlying public-key mechanism but says little about what happens when the account used to sync passkeys across devices is itself compromised.

Why it mattered

Passkeys address a specific, common failure: a password or a one-time code typed into a look-alike site. Because the cryptographic challenge is tied to the real site's identity, a phished user cannot hand over anything a fake site could reuse. That is a narrower claim than universally unphishable accounts, since it says nothing about a compromised device, a coerced approval, or an attacker who gains control of the cloud account that syncs a person's passkeys in the first place.

Defensive takeaway

Where you enable passkeys, also review the security of the account that syncs them, since that account, not any individual device, becomes the resource an attacker would need to compromise to reach every synced credential at once.

  • Which of your accounts currently offer passkeys, and does your organization actually require or default to them?
  • What happens to access if the platform account syncing a user's passkeys is itself taken over?
  • Do your recovery procedures for a lost device create a new phishable fallback, such as a one-time code sent by text?

The May 2022 commitment was a starting point for platform-level rollout, not a completed migration away from passwords. Reading it years later means checking what each platform actually shipped against what it promised, rather than treating the announcement itself as evidence of present-day coverage.

Defensive takeaway

Enable passkeys where available, but also harden the platform account that syncs them, since that account becomes the single point that reaches every device's credentials at once.

The announcement documents what three platform vendors committed to build, not an independent measurement of adoption or security outcomes; it establishes the passkey's phishing-resistant design but says little about risk to the account that syncs passkeys across devices.

Sources & reading trail

Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard to Accelerate Availability of Passwordless Sign-Ins ↗

Records the joint 5 May 2022 commitment and each company's stated plans for synced FIDO credentials.

standards-body · Source published: 5 May 2022 · Retrieved: 16 September 2026

Apple, Google, and Microsoft commit to expanded support for FIDO standard ↗

Apple's own statement of the commitment, describing the sign-in mechanism and its phishing-protection claim.

vendor-primary · Source published: 5 May 2022 · Retrieved: 16 September 2026

Passkeys ↗

Living reference describing passkeys as phishing-resistant public-key credentials, as it stood on 16 September 2026.

standards-body · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.