Losing a phone creates two separate problems: securing the missing device and proving your identity to the account service. Whether a passkey survives depends on where it was stored. Some passkeys sync through a platform credential manager; others remain only on one device or security key.
First identify the storage model
If the passkey was synchronized, signing into the same protected Apple, Google or Microsoft account on a replacement device may restore it. A device-bound passkey does not automatically appear elsewhere. A hardware security key remains available only if you still possess that key.
Use an existing trusted session
Before starting a difficult recovery flow, check a laptop, tablet or browser profile that is already signed in. From that session, add a new passkey, update recovery information and remove the missing phone. Do not sign out until the replacement method has been tested.
If no trusted session remains
- Use a second passkey or hardware key registered earlier.
- Try the service's official recovery codes.
- Use the documented account-recovery process from a familiar device and network.
- Avoid paid “recovery agents” and unsolicited support messages.
Secure the missing phone
Use the platform's official lost-device service to mark, lock or erase the phone. Contact the mobile carrier if the SIM or eSIM could be abused. Review recent account sessions and remove the missing device only after another recovery path works.
Prepare before the loss happens
Important accounts should have more than one recovery route. Register a second personal device or security key, store recovery codes separately and keep recovery contact details current. Document which credential manager syncs each passkey; “it is somewhere in the cloud” is not a recovery plan.
A passkey can be safer than a password without being magically indestructible. Resilience comes from two independent credentials, a protected platform account and recovery information that an attacker cannot easily change.
Run a recovery rehearsal before the phone disappears
Use a spare browser profile and confirm which recovery route appears without finishing the process. Check that the recovery email and phone still belong to you, that another trusted device can approve access, and that offline codes are readable. This small rehearsal exposes a circular design in which the lost phone is required to recover the account that restores the passkeys.
Separate device loss from account compromise
A locked phone with current encryption is not automatically an account breach. Use the platform's lost-device controls, contact the carrier, and review recent sessions. If the device was unlocked, the PIN was observed, or an unfamiliar recovery event appears, rotate critical credentials from a clean device and contact financial providers where necessary.
When a replacement arrives, do not erase the old device from the account until the new one can sign in and recovery has been verified. Then revoke the missing device and record what actually restored access.
Build a recovery dependency map
Draw the recovery chain before replacing the phone. Start with the service being recovered, then list the platform account that synchronizes passkeys, the email address used for recovery, the mobile number, trusted devices and offline codes. A circular dependency is common: the email needs the missing phone, while the phone backup needs the same email. Break that loop with a second trusted authenticator or an offline recovery method.
For a company-managed device, the identity team should also know whether credentials are stored in a personal cloud account, an enterprise credential manager or hardware assigned to the employee. Device replacement and staff departure should follow a written process rather than improvisation at the help desk.
Evidence to collect during an incident
Record the time the phone disappeared, the last successful sign-in, carrier changes, unfamiliar recovery notifications and the devices still shown as trusted. This helps separate simple device loss from account takeover. Do not erase the missing device until another trusted route is confirmed, unless immediate remote wiping is necessary to protect exposed data.
After recovery, revoke the old device, review sessions, replace recovery codes and test the new arrangement. The goal is not merely to regain access once. It is to remove the lost device from every path that could restore access later.