How to use Passkeys in Windows 11 with Bitwarden and 1Password

Last update: November 18th 2025
  • Windows 11 integrates passkeys at the system level and allows the use of 1Password and Bitwarden as authenticators.
  • 1Password generally works with its MSIX version; Bitwarden offers beta integration from GitHub.
  • Activation is done in Settings → Accounts → Passwords → Advanced options with Windows Hello.

Passkeys in Windows 11 with password managers

The arrival of passkeys in the Microsoft system is now a reality, and with direct integration of third-party managers. Windows 11 incorporates native support for access keys managed by 1Password and Bitwarden , an important step towards leaving traditional passwords behind and gaining security against phishing and credential theft.

This feature didn't appear out of nowhere: after months of testing with Windows Insider, Microsoft included it in the November security update (Patch Tuesday). The feature is activated system-wide as a "system authenticator" and works in conjunction with Windows Hello , allowing you to authenticate actions using facial recognition, fingerprint, or PIN, and use these passkeys in a unified way across apps and browsers, often without extensions.

What are passkeys and what changes in Windows 11?

Explanation of passkeys and Windows 11

Passkeys are based on FIDO2/WebAuthn standards and replace the password with a pair of cryptographic keys . The private key never leaves your computer, and the public key is stored on the service , so there's nothing to "remember" or that can be leaked in a conventional breach. This reduces the risk of phishing attacks to virtually zero, as the process is linked to the legitimate domain.

In the context of Windows 11, the novelty lies at the system layer: Microsoft is allowing managers like 1Password and Bitwarden to act as "system authenticators ," just as they do on iOS and Android. Until now, the experience was more fragmented (for example, limited to the browser or proprietary tools), but this update centralizes the use of passkeys for the entire computer.

This "system authenticator" relies on Windows Hello. Biometric or PIN authentication (Hello) unlocks your passkey store conveniently and securely. If you already use Windows Hello to log in, switching to passkeys is a natural step: it's the same layer of trust, now applied to compatible websites and apps.

Microsoft is also strengthening its own file manager as a native Windows component, with synchronization via a Microsoft account. Operations are protected by the administrator's PIN, the device's TPM , and Azure Confidential Compute , raising the bar for security. Even so, the biggest change for many users is being able to continue using their usual file manager.

And here's where the key players come in: 1Password and Bitwarden are the first to be integrated. 1Password is generally available with the latest MSIX version , while Bitwarden is initially offered in beta through its GitHub repository. Both allow you to save and use passkeys from their vaults and, importantly, in apps and browsers without needing an extension in numerous scenarios.

  Sysinternals for controlling processes in Windows like a pro

Incidentally, although the competition already had a head start (Apple and Google have been promoting passkeys since 2023), Microsoft has opted for a broad integration and third-party compatibility . The move may seem late, but the important thing is that the Windows ecosystem is joining the passwordless trend with a system solution well-suited to real-world use.

How to activate and use passkeys with 1Password and Bitwarden

Configuring passkeys with 1Password and Bitwarden

First, make sure your system is up to date. Native support for passkey managers arrives with the November 2025 security update (KB5068861) , which activates this unified experience and the advanced options page for choosing your system authenticator.

Once Windows is updated, the process is simple. Install the official app of the password manager you're going to use (1Password or Bitwarden) , and if the system prompts you to activate it as a system authenticator, follow the wizard. If it doesn't appear, you can do it manually in Settings.

The exact path in Windows 11 is easy to remember: Settings → Accounts → Passwords → Advanced options . From there, you select your preferred manager to act as the system authenticator, and once you choose, Windows will ask you to confirm with Windows Hello to link it.

From that moment on, you can create and use passkeys seamlessly. When a website or app offers "Create passkey" or "Use passkey," Windows will display suggestions from your authenticator (1Password, Bitwarden, or Microsoft's own). It's the centralized experience you've been asking for: a single access point for everything.

With 1Password, integration is seamless and stable. You'll need the latest MSIX version (it's rolled out gradually), and you can enable password autofill directly within the app. Open the 1Password app and go to Settings → Autofill, where you'll find the "Show password suggestions" option for easy access.

In addition, Windows lets you activate 1Password directly from the system settings. In Settings → Accounts → Passwords → Advanced options, you can choose 1Password as your system authenticator , thus unifying the experience for all your logins. In many cases, you won't even need the browser extension to use your passwords.

Bitwarden is also making a strong push, although it's currently in beta. The feature is being tested with the desktop app available in its GitHub repository , while it's being rolled out to the standard installation. It's fully functional for creating and using passkeys, and can also operate without an extension in most scenarios.

  Brute-force algorithms in programming: what they are, examples, and differences with backtracking.

As with any beta version, it's wise to take precautions. Bitwarden recommends testing with a separate, dedicated account to avoid risks to your everyday data, since beta builds are not yet production-ready. If you encounter bugs, the community suggests reporting them on GitHub so the team can fix them.

If you're interested in trying the Bitwarden beta, the process suggested by its community is very straightforward. 1) Create a GitHub account and 2) download a beta build of the desktop app , with the expected warnings for software in testing. Then, on Windows, the rest is identical: select it as your system authenticator in Advanced Options and confirm with Windows Hello.

From a usability standpoint, it's pretty straightforward. You'll be able to "Save as passkey" when a service allows it, and from there, log in with Windows Hello without typing passwords. This works in both browsers and applications, which is one of the biggest differences compared to the previous version on Windows.

A clear advantage of using 1Password or Bitwarden is cross-device synchronization. The passkeys you save in your preferred manager can travel with you across your entire system , simplifying your daily tasks if you use a PC, laptop, and other devices. The same applies if you choose Microsoft's manager, which synchronizes through your Microsoft account.

If you're concerned about security, it's worth remembering how all of this is protected. Windows Hello unlocks your passkey vault, the TPM securely stores secrets, and Azure Confidential Computing adds layers of cloud protection for critical operations. The passkey itself doesn't travel and is useless outside its domain.

What about browser support? Thanks to the "system authenticator" role, apps and browsers on Windows can invoke the native passkey selector . Therefore, the manager extension is no longer essential, although it can still be useful for other functions, such as secure notes or legacy passwords.

In your day-to-day use, you'll notice very concrete improvements. Sign-up and login processes become faster and more convenient , and the problems of remembering or copying passwords disappear. In businesses and shared environments, this leap also translates into fewer incidents of compromised credentials.

One interesting fact is that this feature didn't appear out of thin air: Microsoft began testing 1Password as a passkey provider months ago within the Windows Insider program . The result is an integration that's now available worldwide, with 1Password stable and Bitwarden in beta.

Bitwarden reminds users of the beta quality assurance notice. Test builds are not yet production-ready and may contain errors , hence the recommendation to use a separate account and report any bugs on GitHub so the team can review them as soon as possible.

  What is Zero Trust Architecture: pillars, design and best practices

With 1Password, in addition to adjusting the settings in Windows, it's worth accessing its configuration. Enable "Show password suggestions" in the Autofill section so the password manager suggests passwords in compatible forms, saving you from having to search manually.

Finally, there's a feature that will please those who value interoperability. You can now create new passkeys for all kinds of sites from Windows and save them directly to 1Password or Bitwarden , and use them instantly to log in from your browser or from applications that call the system's authenticator.

For those who are coming in with traditional passwords, the transition can be gradual. There's no need to migrate everything in one day; you can keep your passwords where passkeys aren't yet available and adopt passwords for services that already support them. Over time, the proportion of passkeys will increase without you having to do anything else.

It's also understandable that, in this initial stage, some websites might use different terminology: "Log in without a password," "Access key," "Passkey," etc. The important thing is that when you choose "passkey," Windows will open the native selector and suggest available password managers , including 1Password, Bitwarden, or the Microsoft password manager if you have them configured.

The overall result is positive: the experience is more consistent and secure than with passwords and SMS codes. Authentication is resistant to phishing and reuse , and you also avoid the hassle of entering complex passwords or relying on unreliable second factors.

If you're coming from the Apple or Google ecosystem, you'll find it familiar that Windows has adopted this system authenticator role. It's the same idea: a native layer that orchestrates passkeys and integrates with your password manager , device biometrics, and hardware security. And now, it has official support for the two most popular password managers.

Looking to the near future, we expect more password managers to join and passkey compatibility to expand to more services. Microsoft has already made it clear that its strategy involves fostering a passwordless ecosystem , and opening the doors to 1Password and Bitwarden is an important step in accelerating adoption.

Anyone using Windows 11 now has top-notch tools to simplify their digital life. Update to version KB5068861, choose your authenticator (1Password or Bitwarden), and activate Windows Hello ; from then on, creating and using passkeys becomes almost automatic and, above all, much more secure than memorizing passwords.

security and privacy
Related articles:
7 Security and Privacy Strategies in the Digital Age