Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-06-11T01:10:08+00:00

    Rob thank you for the explanation regarding 'FIDO'. I don't know why Microsoft does not provide an explanation of what FIDO is, how it relates to their passkeys, and the purpose, use, set up of passkeys. All that I have seen is somewhat gibberish.

    Was this answer helpful?

    0 comments No comments
  2. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-06-10T21:48:20+00:00

    There is nothing wrong with long passwords / strong passwords. 90% of the population should not have to "get rid of all passwords" just because the 10% can't stop writing them on sticky notes or just using 123456 etc. No one is ever going to know my 15 character password! And no website or system should be storing it! The password HASH is what gets stored! And with 256+ bit encryption it would take 1000 years to reverse engineer it! With "passkeys" (the latest tech FAD) if someone gets ahold of my phone now they can log-in to EVERYTHING ? SERIOUSLY ? HOW IS THAT "BETTER" ?? Asinine !!!

    G LB,

    There's a simpler set of methods including keyloggers, infostealer malware and the most utterly simple and common method of phishing the user himself for the password that are how something like 95% of the stolen Microsoft accounts have actually occurred in the last few years.

    Passwords are useless, regardless of complexity, length, or even how often you change them if it's not constantly, since once captured they're typically tried by bots within minutes, and the account loss is over before you ever have a chance to react. We see it posted here many times a day, though a bit less recently, since Microsoft had worked with the FBI and others around the world to take down the infamous Lumma Infostealer operation.

    Disrupting Lumma Stealer: Microsoft leads global action against favored cybercrime tool - Microsoft On the Issues

    Unfortunately, regardless of how skilled you might believe you are with your password management, it only takes a single one of the above methods working once to lose an account, while at least any 2-Factor authentication method and preferably something more modern like an authenticator app or passkeys will provide better protection.

    Microsoft itself has entirely stopped any ability for their internal support to aid in direct recovery of personal accounts, since there's simply no consistent way to verify they're aiding the correct person and not a criminal instead. That means if you can't provide the relatively rigid details the automated system requires in order to prove your identity, the account is lost. And since the criminals understand how to change these appropriately to avoid being blocked, their bots will often have the account details changed to prevent your recovery entirely before you can even react as I mentioned.

    Believe what you wish, if you only use a password and haven't had your account stolen yet, it's simply because you're lucky and most likely the criminals haven't truly targeted you yet. It's simply a matter of time and desire, nothing more.

    Rob

    Was this answer helpful?

    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-06-10T21:25:15+00:00

    There is nothing wrong with long passwords / strong passwords. 90% of the population should not have to "get rid of all passwords" just because the 10% can't stop writing them on sticky notes or just using 123456 etc. No one is ever going to know my 15 character password! And no website or system should be storing it! The password HASH is what gets stored! And with 256+ bit encryption it would take 1000 years to reverse engineer it! With "passkeys" (the latest tech FAD) if someone gets ahold of my phone now they can log-in to EVERYTHING ? SERIOUSLY ? HOW IS THAT "BETTER" ?? Asinine !!!

    That sounds Great except it is a LIE!

    Enigma was secure, DES was secure, the CLIPPER Chip was secure as were hundreds of others algorithms that were deployed to secure data & communications; until they were compromised or broken by advances in technology!!! Just for your edification: DES was broken in a challenge with was held in a competition held three different years in a row! 6 weeks , 6 days and lastly hours…

    Returning to my issue. Last time I checked I purchased the computer and paid for the OS as part of the computer purchase. I am the one paying for middlesoft online services and it’s my data!!!! If I want to use 4096 bit encryption or none at all it is my choice to do so!!! If I want to use “password” as my password then I WILL! It is Not ms’s business what I do with the things I purchased!!!!

    The Customer is Always Right!!!! Please pass this along to the CEO along with some Klingon toilet paper aka sandpaper!!!

    Larry Hoffman2,

    You're wasting your breath complaining here, since no one who needs to will see it, as Microsoft itself doesn't monitor these forums, though that may at least partially change in a few weeks when as the notice now appearing at the top of these forums indicates, these forums will migrate into the Microsoft Learn Q&A Forums structure and include a few actual internal Microsoft employees as posters.

    IN either case though, the correct way to get your preferences registered with Microsoft's developers is to use the Feedback option built into Windows 10 or 11 itself, since this gets posted with both the text and any added upload that you choose to include, making it far more detailed and useful to help explain what you're seeing or wishing to have changed.

    That will likely always be the preferred method to register your thoughts, since anything else can be lost in translation by whomever you might ask to tell someone else, who tells someone else..., you hope. See the problem?

    Rob

    Was this answer helpful?

    0 comments No comments