Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-04-06T01:12:01+00:00

    Once again, you're totally missing the point of mine and others' comments about how useless we found the passkeys.

    Maybe you got such a kick out of correcting my "inaccuracies" that you simply spiraled even further into irrelevant technical jargon.

    Certainly, I realize you know a lot about passkeys and obviously you're eager to show what you know. So, reading your reply gives me an opportunity to learn about something called the FIDO Alliance. Wow. So impressive! And, add to that your fascinating insight that the real fault lies not with that FIDO Alliance (sounds like a glorified dog kennel) but with those dastardly "companies" that "don't want to cooperate to make common interfaces."

    I hope it gave you some satisfaction to correctly place the blame where it belongs!

    But what good is that for those of us who encountered this pointless pop-up plague in our user experience? What's the home or office computer user supposed to do while those uncooperative "companies" figure out how their "common interfaces" are supposed to work? When will all these companies work through their uncooperative attitude about "making common interfaces"?!

    I hope you can read "facetious" in between the lines here. Your explanation leads us even closer to peak absurdity.

    Look. I started my inquiry in this "community" thread simply to see why I kept bumping into the "passkey" pop-up in my Amazon account. I soon learned I could work around it. I have no use for a device or function that requires the end-user to wade through convoluted instructions, explanations and advice just to log in to my email or use an Amazon account. I've never had a problem with my brokerage, my bank, credit card companies, research websites for my academic work or other sites. If passkeys is, as you say, "the future", that "FIDO Alliance" you told us about will sure have their work cut out for them. I assure you, after what I've seen and after reading through the comments of the more technically experienced in this thread, I am even more convinced that I have ZERO need for a passkey.

    However, you also mentioned earlier that passkeys don't require a brain to use. Well, how nice. We might as well leave such time-wasting discussions as these to the braindead. Have at it. Enjoy your passkeys!

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  2. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-10-04T19:19:27+00:00

    after 30 years using aol and yahoo why i have to use passkey

    Because those are just 2 infamous examples of companies that have had multiple and often huge breaches of user accounts and information George, which is why passwords are so useless as a 'security' measure and have to die.

    Read any of the articles found by searching for either AOL or Yahoo and the word 'Breach' to see all the problems that these companies have had, which whether they were caused by passwords or not, typically resulted in all of the customer passwords being exposed, along with other personal data.

    aol breach at DuckDuckGo

    Yahoo breach at DuckDuckGo

    Passkeys will basically end the loss of these 'secrets' and many if not all of the breaches that result as well, since the administrators of the firms involved won't be using passwords anymore either, which causes most of the problems.

    Rob

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-10-03T18:31:56+00:00

    Shawn,

    Passkeys are something that all of the major names like Apple, Google, Microsoft and others are supporting to replace the insecure passwords with a technically easier to use system that's far more secure.

    I know that change is difficult, especially for those who believe that by using their devices at home they're somehow 'safer' than those using them either mobile or in other locations like work. But in reality, with the Internet and online criminals, you're inherently no safer than anyone online today, which is why the PIN and biometrics are being used to make it easier than remembering long, complex passwords that can still be easily stolen and abused by criminals anyway.

    Here's a relatively easy to understand overview of passkeys and how they work, so you can learn why this new system exists and why you won't be allowed to use them to access websites without a PIN or biometrics, and instead need to keep using, changing and making ever more complex passwords the websites will require otherwise.

    Passkeys overview - Microsoft Support

    Of course, if you never use your PC to login to any other websites, then the need for passkeys would only be for your Microsoft account, in which case you wouldn't need them and assuming there's nothing on your home PC that you don't want anyone who walks into your house and plays with or steals the device to have or see, then you might still want to remove all authentication.

    But I have yet to meet anyone who truly uses their PC this way, that is unless it's a second alternate PC that's used only for some special purpose like local media or private gaming that doesn't otherwise need to login to any 3rd-party websites. I actually have one of these, but then that's also not connected to the Internet, so I simply don't ever get the prompts to connect it to a Microsoft account, so the problem doesn't exist.

    Rob

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments