GOV.UK One Login is rolling out passkeys more widely, giving small business owners another way to protect the accounts they use for government services. For firms that already use One Login, this is a useful moment to check which device holds access and how the account would be recovered if that device disappeared.
What has been announced?
The government’s 14 September announcement says passkeys are being extended following a trial involving more than 300,000 users. One Login has more than 23 million users overall. Passkeys remain optional: people can continue signing in with a password if they prefer.
Instead of typing a password, a user can approve a sign-in with their device’s fingerprint reader, face recognition or PIN. The government says the biometric or PIN information used to unlock the passkey stays on the device and is not stored by One Login.
Why this matters to a small firm
A business owner may only visit some government services occasionally. That can make forgotten passwords and missing security codes particularly awkward when a task needs completing quickly. It is sensible to review access during a quiet working day, with time to resolve problems before a filing becomes urgent.
The National Cyber Security Centre recommends passkeys wherever they are available. They resist phishing because they cannot be intercepted or reused like passwords. A credential manager creates and stores them, and can synchronise them between trusted devices. Keeping devices and apps updated remains part of that protection.
For a small team, the practical question is whether each authorised person has dependable access from a suitable device. A convenient sign-in method still needs a clear owner and a recovery plan. Avoid treating the person with the office smartphone as the automatic owner of every important account.
Choose the device carefully
The official One Login instructions require a compatible phone, tablet or computer with a screen lock. They specifically warn against setting up a passkey on a shared device: another person who can unlock it may be able to use the passkey.
Setup is available through the account’s sign-in management settings. After it is created, the passkey becomes the main sign-in method, although a password and security code may still be needed as a backup. One Login emails the user to confirm where the passkey is saved.
Before making the change, consider the ordinary ways your business works. Is the device individually assigned, or passed between shifts? Does someone else know its unlock code? Is it due for replacement soon? If an IT provider manages it, ask them to explain the approved account and device arrangements before proceeding.
Plan for a lost phone
One Login guidance says users unable to use their passkey can sign in with a password and security code instead. If a device is stolen, users should remove its passkey from One Login and create a replacement.
Check the recovery route while the usual device is still available. A short internal note can record who is responsible for government-service access and where to find the official help page. Keep passwords, PINs and security codes out of that note. When equipment or responsibilities change, include account access in the handover conversation.
A manageable next step
Start with your own One Login account and read the setup guidance before making changes. Confirm that the device is appropriate, understand the backup sign-in method, then allow time to try the new process without an urgent submission waiting.
Businesses also reviewing Companies House access can read our guide to the Companies House sign-in change. That covers the separate transition to individual One Login accounts. Today’s passkey announcement adds a security option; it is a reason to improve everyday access arrangements at a sensible pace.
