Account security
Set up passkeys on the personal accounts you rely on
Your personal email account often connects several parts of student life, from shopping receipts to travel bookings and account recovery. Improving its sign-in protection is useful, but the setup should also account for a lost or replaced device. Start with one important account and understand the provider's process before changing several at once.
The NCSC now recommends passkeys where services support them. Google separately documents backup codes for accounts using its two-step verification process. These are related account-access tools, not interchangeable instructions. Use the options offered by each actual provider, and follow university policy for institutional accounts rather than applying personal-account settings to them.
We may earn a commission from retailer links. This guide does not claim first-hand product testing. Our editorial approach
Identify the account and trusted devices
Write down which personal account you are updating and the devices you control. Check that you can unlock those devices reliably and that their software is supported. Do not create a passkey on a shared computer or on someone else's phone merely because it is nearby during setup.
Open the account's security settings through the provider's known website or application. Avoid following an unexpected message that claims you must immediately upgrade your login. The security change should begin from a route you independently recognise. Keep any account-recovery information current before altering a method you presently depend on.
Understand where the passkey will live
Read the provider's explanation of the available passkey storage option. It may involve a device or a credential manager you already use. Decide whether that arrangement matches your normal access needs. If you use more than one operating system, check the supported sign-in and recovery process across those devices instead of assuming it will be identical.
Keep the distinction between creating a passkey and removing other methods clear. A successful setup screen does not mean you must immediately delete every existing recovery option. Follow the provider's guidance for managing the remaining methods, and avoid leaving an obsolete phone number as the only route you understand.
Test a routine sign-in
After setup, try a fresh login from a trusted device using the documented method. Read the prompt so you know what you are approving. Test the situation you actually expect to encounter, such as accessing personal email from your laptop while your phone is available. Record success without writing down private credentials.
If the process fails, keep the working method available while you consult official support. Do not experiment by removing account access routes until only the uncertain one remains. A security improvement should leave you able to use the service and explain to yourself how you will sign in next week.
Prepare for a missing device
Read the service's recovery guidance before you need it. Where backup codes are provided for a separate two-step verification arrangement, store them securely according to the provider's instructions and outside the single device whose loss they are meant to address. Treat them as sensitive credentials, not as ordinary notes to share with a flatmate.
Make a simple plan for who to contact and which trusted device or recovery route remains available if your phone breaks. Keep the plan free of secrets where practical. The aim is to avoid a circular problem in which the instructions and the only recovery information can only be opened after signing into the locked account.
Review after a device change
When replacing a phone or laptop, confirm account access on the new device before retiring the old one. Review obsolete devices and methods through the provider's settings. If your circumstances change, such as losing access to a recovery email address, update the account while you still have a working sign-in route.
Hardware purchases should follow a specific requirement. You may already own everything needed for the provider's supported setup. Browse related products only when replacing an unsuitable or failed device, and verify its current software support separately. No accessory can promise that an account will never be compromised or that recovery will always be immediate.
Your next steps
- Start from the provider’s known security settings.
- Use a device you control.
- Test the new method before retiring an old one.
- Keep a documented recovery route available.
Sources and further help
Sources were consulted on 5 September 2026. Provider terms and services can change; check your exact booking, product or university service.
Keep planning
- Change phones without losing access to university accounts
- Check an urgent university email before acting on it
- Prepare an account recovery plan before deadline week
- Prepare university cloud files before your account closes