Password security guide
Apple Account Password and Passkey Security
Apple Accounts require a strong password and normally use two-factor authentication. Protect trusted devices and recovery as carefully as the password.
Official Apple Account password requirements
Apple states that an Apple Account password must have at least eight characters, contain letters and numbers, avoid three or more consecutive identical characters, and not be a commonly used password. Apple encourages additional characters and punctuation.
Treat eight as a minimum, not a target. Use a longer unique random value stored in the Passwords app or another reputable manager.
Two-factor authentication
Two-factor authentication is the default security method for most Apple Accounts. A new device or web sign-in can require the account password plus a six-digit verification code shown on trusted devices or sent to a trusted phone number. Keep more than one trusted route current.
Passkeys in the Apple ecosystem
Apple devices can create and store passkeys for supported websites and apps in iCloud Keychain. The passkey is unlocked with Face ID, Touch ID or the device passcode. Passkeys are unique per service and resistant to conventional phishing.
This is distinct from the Apple Account password used to protect access to Apple services.
Security keys for Apple Account
Apple supports physical FIDO Certified security keys as an advanced option. Apple requires at least two keys so one can serve as backup. Users are responsible for maintaining access; losing all trusted devices and keys can create permanent lockout risk.
Protect trusted devices and recovery
Use a strong device passcode, biometric unlock where suitable, current software and Activation Lock. Review trusted phone numbers and devices. Recovery contacts or a recovery key change the recovery model, so follow current Apple documentation before enabling them.
Respond to suspicious Apple Account activity
Change the password through official device settings or account.apple.com, review devices and trusted numbers, investigate purchase or sign-in alerts and secure the recovery email. Do not provide verification codes to a caller or message sender.