Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-06-22T17:11:53+00:00

    I agree with Shawn Frey, I don't get why we are obliged to use a passkey, in the end, all is the same; we are asked to identify ourselves with a code. I don't see what advantages have to add another code, it makes users and software confused. We already have sooo many passwords, passkeys, codes, etc for the bank accounts, work, clubs, etc to add another one to the layer.

    Sadly all these security measures are more of a bother to the user than a real protection against hackers. These last ones are quite more advanced in technology than the normal user, and if the big companies add another layer of protection, the hackers will eventually crack it.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-06-13T07:28:54+00:00

    Hi Rob,

    About account recovery, you're focused too much on the tech; I'm focused on the legal. If I send a notarized signed document claiming my identity and backing it up with, say, a copy of my passport, then for legal purposes I am me, and Microsoft can trust that to recover my account. To a certain degree this could be challenging if my name would be "John Smith" living at "123 Main St"; one option - and it should be optional - would be (under the strictest of "we will use this only for account protection" contractual privacy commitments) to allow users to provide a greater degree of proof of their identity at the time of account creation, to better allow matching at a later time of need for account recovery.

    The United States has a structural distrust of central government (and, although now diminishing for very good reasons, excessive trust of corporations); I've lived in Europe for the past seventeen years, where it tends to go the other way; it is *trivial* for me to prove my identity - I have a national police issued ID card with an embedded digital certificate bound to my national ID number, and most truly-personal accounts (even down to many e-commerce sites) gather that ID (for tax purposes), so I could prove who I am for the purposes of account recover with nothing more than a web request form digitally signed by my ID card.

    Even in the US, online automatic global identity document verification services have long existed (see how ID.me performs its online sign up).

    This stuff is not rocket science. It's much more law, politics, and (problematically, unbridled) capitalism/ commercialism.

    We, in security and in usability, must know and remember - and instruct our bosses - about the legal and societal stuff surrounding our tech toys.

    Microsoft has most certainly not gotten (or, at high commercial levels, chosen to ignore) this fact.

    Going back to usability, you continue to fall into the falsehood of "The only application I'll ever run on my computer is Lotus 1-2-3" (this was the impetus of Microsoft creating the in-account application virtualization and eventually-enforced proper shared libraries), which of course today takes the form of "I'll only ever use Apple products". But, we don't; we do use multiple applications, multiple platforms. This "Windows Hello is GREAT IFF you ONLY use Windows" is not an acceptable argument for pushing the use of Passkeys. Not until true, uniform user experience, cross-platform synchronized passkeys, withOUT the trivial confusion of "is that really a passkey prompt or is that a clever hacker's browser iFrame?!", are deployed.

    And physical external keys like my handful of Yubikey FIDO2 keys are NOT simple. They're very secure, but they're a nuisance. They would either require (even assuming that most accounts allowed multiple passkeys to be associated, which most accounts do not) owning multiple of these things, to keep one each in each of the various places where I usually computer, or would require me to dig me one portable FIDO2 key out of my handbag over and over and over and over and over again throughout the day... just not practical.

    You are correct in your underlying theory, but your insistence that it's practical or usable *today* is simply wrong with current implementations, and I see no evidence of real movement toward the converged, well- (usably)-implemented version that would make passkeys an actually good idea for most people any time soon. (And even then, reducing authentication to the one single factor of "my device" remains a bad idea, weaker than whatever other authentication method + a physical second factor; yes, modern Windows kernels are much harder to get into to the depth that would allow directly accessing the TPM, but how hard is it for user-level malware to act like the human user and tell the passkeys prompt "yes, that's me, hackhackhackhackhack the website that just foolishly trusted only Windows Hello on *this* device to prove *that* identity?).

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-06-12T07:19:30+00:00

    [quote]Since the primary Windows Hello process and Private Key are contained within the TPM firmware and kernel of the device, this would require a complete compromise of the firmware or core drivers of the device in order to compromise a Microsoft account, which though theoretically possible with some modern malware, it's far less likely than it used to be unless the device owner himself became directly involved in the compromise during otherwise normal operation.[/quote]

    😂 That's funny.

    Especially since a lot of this has become about social engineering.

    Let's talk about Windows. Windows is an operating system where an install program will commonly ask for administrator privileges, which just so happens to look exactly the same as a prompt requesting full access to every device driver, the ability to install its own device drives, operate in ring 0, read the entire kernel and userspace memory, and in herbal just go ham.

    When you click this install button, EVERYTHING is on the table with the possible exception of removing files owned by SYSTEM.

    This is how anticheats operate for example.

    Nothing is secure in Windows because it is completely trivial to social engineer people due to the terrible security model. The TPM doesn't solve anything.

    It does on mac where applications are installed without admin privileges by just dragging programs into the Applications folder, and then you are asked for individual granular permissions when they want to do something, or on Linux increasingly where systems like Flatpak allow installing and sandboxing in the same way.

    Microsoft did develop AppX for a similar purpose, but it has failed to gain traction.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments