Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-06-11T20:21:06+00:00

    It's a little off-topic, but still germane to Microsoft's attempts to force users into using passkeys; your claim that Microsoft has eliminated any realistic opportunity for people to recover accounts is telling. This isn't because there isn't a reasonable way to prove account ownership - legal proofs of identity have been a thing for thousands of years. It's because the big tech companies don't want to spend the money to respect this most basic aspect of user autonomy, and regulation hasn't forced them to.

    The 15-character-password adamant person certainly should have included "plus good 2-factor".

    With the terrible (confusing, ripe for social engineering) user experience of passkeys today, competent unique strong password plus phishing-resistant 2FA is less likely to result in a user being engineered into giving up full access to an account; and the argument about keyloggers and other "game is already over, they've got control over the end-user's device" applies to passkeys to (and possibly in spades, because ANY out of band 2FA would defend against that, whereas "my device IS me" passkeys implementations are MORE susceptible once a user's device has been compromised).

    Jay Libove - 2,

    Well thought out issues, but I think you've missed something in your first and last case mentioned.

    The actual reason that Microsoft has had to drop the ability for individuals to recover their personal accounts via Microsoft Support, which I should also have indicated is primarily when all of the account identity data has been modified by an attacker, since otherwise you could simply use the automated online form or similar automated method to recover it yourself, is that there's no longer any truly guaranteed method to confirm identity stored within the account.

    You're correct that there are approved forms of identity like the now common US Real ID that was finally recently required for flying even domestically, though the federal law that mandated its use was initially passed in 2005. However, as you mentioned, no such ID requirement has ever been made for the use of Microsoft or most other similar personal online accounts except those like Airbnb.

    Unfortunately, these accounts have over time become the rough equivalent of our personal web identity, which is why without the storage of and a method to verify something like the Real ID against the person making contact, since even using a person to perform this task creates the potential for employee-leveraged fraud, it's not likely we'll see this form of true ID verification at least until the AI apps have progressed to the point where the likely still optional storage of your Real ID with the account could be used to validate your identity. The problem I still see here though, is that Microsoft's recent changes to their own IR-based Windows Hello Face system to avoid face-ID spoofing, likely means that much better cameras may be required in order to make this sort of AI system effective.

    As for the current passkey system, I agree it's still confusing and needs work to become fully effective for typical consumer use, though once a person understands how to initially create them on a Windows 11 system, their use from what I've heard is so easy that I don't believe that's really where the true user problems lie.

    Though I agree there appears to be a theoretical potential for a kernel-based malware and bot to abuse a local authenticator, getting malware embedded that deeply into Windows isn't as common anymore, and even if it occurs, unlike with local password managers or other clear-text authentication methods like TOTP, neither access to the Private Key stored in the TPM nor the creation of a passkey that could be used from another device would be possible.

    And it's still simple to avoid this issue by simply using a cross-platform device such as a phone or other external FIDO2 security key device to store and perform the authentication instead, since that's functionally similar to the out-of-band 2FA devices you mentioned, but with the added security that's provided by use of the TPM or similar phone-based encryption chip and no direct access to the Private Key it stores of any sort, since the FIDO2 challenge process doesn't allow for it.

    Since the primary Windows Hello process and Private Key are contained within the TPM firmware and kernel of the device, this would require a complete compromise of the firmware or core drivers of the device in order to compromise a Microsoft account, which though theoretically possible with some modern malware, it's far less likely than it used to be unless the device owner himself became directly involved in the compromise during otherwise normal operation.

    Casual malware operating outside of the kernel would never really have the ability to do any of this, so I find it far less likely than the compromise of any current authentication method, which as the Lumma and other similar infostealer malware have shown, can quickly collect passwords, transmit to C&C servers, and exit before their presence is even known.

    Rob

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-06-11T18:52:59+00:00

    It's a little off-topic, but still germane to Microsoft's attempts to force users into using passkeys; your claim that Microsoft has eliminated any realistic opportunity for people to recover accounts is telling. This isn't because there isn't a reasonable way to prove account ownership - legal proofs of identity have been a thing for thousands of years. It's because the big tech companies don't want to spend the money to respect this most basic aspect of user autonomy, and regulation hasn't forced them to.

    The 15-character-password adamant person certainly should have included "plus good 2-factor".

    With the terrible (confusing, ripe for social engineering) user experience of passkeys today, competent unique strong password plus phishing-resistant 2FA is less likely to result in a user being engineered into giving up full access to an account; and the argument about keyloggers and other "game is already over, they've got control over the end-user's device" applies to passkeys to (and possibly in spades, because ANY out of band 2FA would defend against that, whereas "my device IS me" passkeys implementations are MORE susceptible once a user's device has been compromised).

    Was this answer helpful?

    0 comments No comments
  3. quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
    2025-06-11T01:54:22+00:00

    Rob thank you for the explanation regarding 'FIDO'. I don't know why Microsoft does not provide an explanation of what FIDO is, how it relates to their passkeys, and the purpose, use, set up of passkeys. All that I have seen is somewhat gibberish.

    Here are some links by Microsoft with explanations.

    BTW...these security enhancements are the new norm in today's world due to hackers and the number of data breaches breaches reported where extensive amounts of personal/financial/business information (including usernames and passwords) is stolen by hackers, then leaked or published for sale on the Dark Web. Criminals can then use that information for identity theft, hacking, extortion and any number of other nefarious purposes. We as users of this technology must take steps to minimize the risk of all sorts of threats, not just Microsoft sign-in attempts. Passwords combined with multi-factor authentication (MFA) are no longer sufficient to fully protect you.

    Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

    Quote

    To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

    Was this answer helpful?

    0 comments No comments