IT explained
Passwords, two-step verification, MFA and passkeys explained
Your online accounts need more than a memorable password. Here is what the common security terms mean, where each protection helps, and what to do if something goes wrong.
The short version
Four useful habits
- Use a different, strong password for every important account. A password manager can generate and remember them.
- Turn on an additional sign-in check. Prefer a passkey or phishing-resistant security key where supported; otherwise use an authenticator app when offered.
- Protect email and recovery routes. Whoever controls your mailbox may be able to reset many other accounts.
- Keep the devices you sign in from secure. Updates, malware protection and a standard daily user account matter alongside sign-in settings.
No single method makes an account invulnerable. The strongest choice also needs a practical way to recover if a phone or key is lost.
Passwords
Make each password long, unique and hard to guess
A password is a secret used to prove you are allowed into an account. Its length and uniqueness matter more than clever substitutions. Use a password manager to generate a random password for each service, or a suitably long passphrase where you need to type and remember it. Never reuse your email or password-manager password elsewhere.
Avoid names, birthdays, addresses, favourite teams, keyboard walks such as qwerty, predictable sequences such as 123456, and a base word with a site name or year added. Changing Password1! to Password2! is not a meaningful fresh secret. Do not share passwords in email, chat, a support form or over the telephone.
Changing a password on a fixed timetable, without evidence of a problem, can encourage small, guessable variations or notes kept in unsafe places. Change it when it may have been exposed, reused, phished or entered on a compromised device, or when your organisation’s policy requires it. A unique generated replacement is better than a new number on the end. See the National Cyber Security Centre’s password guidance.
What is a password manager?
A password manager stores your login details in an encrypted vault and can create different passwords for different sites. Protect the vault with a strong, unique primary password or passphrase, enable its strongest available additional sign-in method, keep its app and devices updated, and check its recovery options. Your vault is valuable because it holds access to many accounts. Do not leave it unlocked on a shared computer; do not assume that a synced vault removes the need for backup or account recovery planning. Compare the manager’s security and recovery model before choosing one.
JM Restart can help choose and set up a password manager. We work with a range of products and can supply Keeper where it suits the customer. The right choice depends on your devices, sharing needs, account recovery, ongoing cost and security settings; you do not have to change a suitable manager just to get help from us.
A second check
Two-step verification and MFA: what is the difference?
Two-step verification (2SV) adds another step after your password. Multi-factor authentication (MFA) is the wider term for using different types of proof, such as something you know, something you have or something you are. Services do not always use these labels consistently. The practical question is what happens if someone steals your password.
A one-time passcode is a short-lived code used for one sign-in or transaction. It might come from an authenticator app, text message or email. An authenticator app usually generates a changing code on your device, or sends an approval prompt. A code or prompt helps, but a convincing fake sign-in page can still trick you into entering a code or approving a request. Never approve an unexpected sign-in. Where available, number matching helps you check that a prompt relates to the sign-in you started.
Text and email codes are useful but have limitations. A mobile number can be taken over through a SIM-swap or number-reassignment process, and a phone can be lost. An emailed code depends on the security of the mailbox, and may add little protection if the mailbox uses the same password or is already compromised. Text delivery can also fail where there is no signal. If these are the only options, they are usually better than using a password alone. If a service offers a well-supported authenticator app, passkey or FIDO security key, consider the stronger option and document a recovery route.
Modern sign-in
Passkeys and hardware security keys
A passkey lets a supported device or password manager prove your identity to a particular website without sending that website a reusable password. You normally unlock the passkey with your device PIN, fingerprint or face. A passkey is tied to the real service, so it is much harder to use on a lookalike phishing site. Some passkeys are synced between your devices through a protected account; others remain on one device or a hardware security key. The recovery and sharing choices differ, so check how you will sign in if a device is lost.
A hardware security key, such as a YubiKey or another FIDO-compatible key, is a physical USB or near-field communication (NFC) device. Depending on the service, it may hold a device-bound passkey or act as an additional sign-in factor. A physical key is not a universal replacement for every password: the service must support it, and account recovery can still be a weak point. Register a spare key or another approved recovery method before you need it. Never hand a key and its unlock PIN to someone asking for an unsolicited verification.
JM Restart can help set up a hardware key. YubiKeys are one type we currently use; we can assess another compatible key if it better suits the accounts and devices involved.
For a useful overview, see the NCSC’s passkey guidance. We can help choose a sensible method for the accounts and devices you actually use, rather than insisting on one method everywhere.
Windows and older apps
Is a Windows PIN just a shorter password?
No. A Windows Hello PIN unlocks sign-in on that particular Windows device; it is not the same reusable secret as your online Microsoft-account password. Windows Hello can also use supported face or fingerprint recognition, with a PIN as a fallback. It is still important to protect the physical device, choose a non-obvious PIN, keep Windows updated and understand the account’s recovery method. Your organisation may use Windows Hello for Business, which has additional managed security features. See Microsoft’s Windows Hello guide.
What is an app password?
An app password is a special generated credential that some services allow for an older application that cannot complete a modern MFA sign-in. It is not your usual password and it does not make that old application use modern authentication. Treat it as sensitive, record which app uses it, remove it when no longer needed, and favour updating or replacing the app. If a password changes after a breach, review app passwords separately because they may not all be revoked automatically. Microsoft’s app-password documentation explains this legacy exception.
Recovery is part of security
Protect your email, phone and recovery information
Your primary email account often receives password-reset links, purchase receipts and security alerts. Give it a unique password and a strong additional sign-in method. Check its recovery address and phone number, forwarding rules, connected apps and recent sign-ins. A password reset is not enough if an attacker still receives a copy of your mail or remains signed in on another device.
Keep recovery details current and store backup codes in a secure place separate from the account they unlock. Remove old phone numbers and email addresses that you no longer control. Security questions can also be a recovery route, but answers based on public facts such as a school, pet or parent’s name may be guessed or researched. If a service requires them, use unique, hard-to-guess answers and store them securely in your password manager; do not rely on a question as your only protection. Check whether the service offers stronger recovery choices. For a business account, use approved administrator and recovery procedures rather than a personal mailbox or shared code.
If something leaks
What is a data breach, and what does Have I Been Pwned show?
A data or security breach means information or systems were exposed, accessed, lost or disclosed without authorisation. It can happen at a company even when you have kept your own device secure. The exposed data may be an email address, password, phone number, payment information or something else. A breach notification does not by itself prove that someone has signed into your account, but it is a reason to check what was affected.
Have I Been Pwned (HIBP) lets you check whether an email address appears in breaches in its database. Its separate Pwned Passwords service can tell you whether a password has appeared in known breach data without linking it to your email address. A result is a prompt to investigate and secure affected accounts, not proof that every account using that address was accessed. No result does not prove that an account is safe or that no breach occurred. Use the official site or the affected organisation’s official website rather than a link in an alarming message. Do not enter your current password into a random “breach checker”. Read HIBP’s explanation of what it stores before deciding to search.
Respond safely
What should I do if I think an account or device is compromised?
- Verify the warning. Go directly to the provider’s official website or app. Do not follow a link or call a number in a suspicious message. For a work account, report it promptly through your organisation’s incident route.
- Use a trusted device. If you suspect the computer or phone itself is infected, do not type a new password into it. From another device you trust, protect the email account and then change affected or reused passwords promptly. Do not wait for a lengthy scan before taking urgent steps from a safe device.
- Remove unwanted access. Review recent sign-ins, recovery details, email forwarding rules, connected apps and app passwords. Sign out other sessions where the provider offers this. Turn on a stronger sign-in method and store recovery codes safely.
- Investigate the suspect device. Update its security software and run an appropriate malware scan, then investigate anything it finds. A keylogger is software or hardware that captures what you type, including passwords; some malware can also capture browser sessions or screens. A clean scan does not prove the device is safe. If the risk is significant, get help assessing whether to rebuild the device before using it for new secrets.
- Check for wider harm. Look for unusual messages, purchases, bank activity or account changes, and contact the relevant provider or bank through a known route. If a business system is involved, preserve evidence and follow its incident and data-protection procedures.
There is no universal “scan first, then change every password” rule. The aim is not to re-enter new secrets on a potentially compromised device while still containing the account quickly. See the NCSC’s hacked-account recovery guide and data-breach advice.
Your daily Windows account
Why not work as an administrator all day?
An administrator account can install software and change system-wide settings. A standard user account has fewer privileges for routine work. Using a standard account day to day and a separate administrator account only when needed can limit the reach of mistakes or malicious software. It is not a substitute for updates, backups, malware protection or careful approval of prompts.
User Account Control (UAC) is the Windows prompt that appears when an action needs administrator-level permission. A standard user is normally asked for administrator credentials; an administrator is asked to approve elevation. It gives you a chance to stop and ask why an app wants more control. Do not approve an unexpected prompt just to make it disappear. Someone who persuades you to approve a malicious action may still gain those privileges. Microsoft explains how UAC works.
Common questions
Choosing and keeping your sign-in methods
Is a passkey the same as an authenticator-app code?
No. A passkey proves sign-in to a particular service through a protected cryptographic credential. An app code is a short number you type into a sign-in page, including a convincing fake one. Both can improve on a password alone, but their phishing resistance differs.
What if I lose my phone or security key?
Use a recovery method you set up in advance, such as a spare key, another authorised device or securely stored backup codes. Keep your recovery details current and follow the provider’s official process. Do not weaken an account by sharing recovery codes “just in case”.
Can I still use text-message verification?
Yes, if that is what the service supports. It is usually better than password-only access, but a SIM swap, lost number or phishing attempt can undermine it. Review stronger supported methods for important accounts.
Does a Windows PIN replace my Microsoft password everywhere?
No. The Windows Hello PIN is linked to the device. Your Microsoft-account password and recovery settings still need protection, especially for sign-in on another device or account recovery.
How JM Restart can help
We can help choose and set up password managers, passkeys and hardware security keys; assist with account recovery through the provider’s supported process; and assess a device suspected of containing malware. Recovery depends on the provider’s checks and cannot be guaranteed.
For a compromised business account, where authorised access permits, we can review active sessions, sign-in history and mailbox forwarding rules and help secure the account. We do not provide formal digital forensics or regulated breach-notification advice. If an incident may affect other people or regulated data, we will agree the technical support scope with the customer and work alongside their specialist advisers where appropriate.
Explore home IT security, business cyber security or managed IT services. If you need remote help, read our remote support safety advice. Never send us a password, recovery code or one-time code in an enquiry.

