Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Newest
  1. Anonymous
    2025-05-14T19:44:40+00:00

    Hi Rob,

    Amazon is the only one I am having an issue with. How to I remove the passkey from there?

    Was this answer helpful?

    0 comments No comments
  2. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-05-14T19:00:35+00:00

    Greetings Rob: We seem to be talking past each other. You've missed my main point again. By "absurd", I clearly do not mean that there is no rationale for the passkeys and the other items you've explained. I'm simply saying that in practical terms, it's a waste of time to try to understand. I have ZERO intention of (as you say) "simply start[ing] to use passkeys locally on at least their Windows 11 system..." I'm a Windows 11 user and I do not use passkeys and I will not start to do so. The way this is presented to the user (in Microsoft Windows) is simply not advantageous for the way I use my system. I seriously doubt it's efficacy.

    I'm doing fine without passkeys and I will resist any attempt by Microsoft (or FIDO2, whoever that is) to force me to use them. I bypass the "passkey" reminder routinely, with Amazon and other sites, and have no hindrance doing what is important to me online and locally.

    I do indeed recognize you are knowledgeable about all this and that's great for you. I have found this whole topic (off and on over about six months in this "community" thread) to be confusing and worse, a colossal waste of time. Certainly, their reason for passkeys is not "absurd" but the way it's been rolled out, including the way you've explained it is, in my world "absurd". No offense intended to you. I'm simply expressing what I imagine MANY users must feel about "passkeys" at this point.

    But, hey, I'm a "boomer" (age 67) so maybe it's a generational thing.

    Hi, a very frustrated Microsoft customer, I'll respond generally to both you and the others who followed up with their own replies, since the theme is relatively consistent.

    It's not generational, since I'm the same age as you, but it is clearly related to technical background, since my career in computers and security makes understanding passkeys relatively easy, though the interfaces clearly need work.

    I do wonder if those having the most trouble with their use on Windows 11 have both biometric capabilities on those devices, as well as whether the smartphone issue is adding to the problems as someone else mentioned, since that's where I had the biggest issues with Windows 10 and Android.

    Though my own larger issue was with my initial test with Amazon, which absolutely everyone complains about, so it's clearly something in their implementation that's the problem there and I wonder if that's a result of the cross-platform authentication issues I saw with that website, meaning it's a deeper problem with that portion of the FIDO2 WebAuthn specification, upon which passkeys operate.

    My earlier explanation of the problem with passwords and why a PIN is better wasn't intended for easy reading, since I was pointing out the various technical reasons behind why passwords are really already dead and dangerous, regardless of how easy and functional various password managers may make them to use, since it's the core problem that they're a shared secret and too easily breached by any number of methods that make them unsafe and really useless in terms of security.

    The unfortunate truth though is that the current state of the passkey system requires too much of the user in terms of knowledge, since without it their operation is still relatively confusing as you've indicated.

    I guess what I should say is that if you already have an effective authentication system that at least includes 2-Factor Authentication, preferably that doesn't require a password if possible, then you're probably okay until Microsoft and others have time to polish their passkey operation.

    If not though, I personally wouldn't bother dedicating myself to useless efforts like password managers or even the still relatively difficult to use and more so maintain Microsoft or Google authenticators, because from everything I've seen here, those are at least as troublesome for most consumers as passkeys with Windows 11 will ever be.

    Since my use is Microsoft centric, the Android issues won't really be a problem unless I try to use both sets of devices and apps fully across both platforms, since the Microsoft implementation with syncing across their Edge and Outlook for Android apps will make everything I truly need to authenticate to 3rd-party websites functional without a need for cross-platform operation.

    So, it's not just Windows 11, but really all Microsoft apps which I require, while on Android the only apps I really use are phone, camera, Gmail for Google communications only and a few others all of which require only a single Gmail account that I've separately defined 2-Factor authentication and backup for on the Google platform. Only contacts have ever been synced between the platforms, primarily to display incoming callers on the phone app, with everything else kept completely separate for many reasons.

    Anyone trying to cross-authenticate, sync or manage their Microsoft, Google, or Apple accounts in tandem across multiple physical planforms is simply asking for trouble, especially in terms of security, while I've personally always kept the platforms and security separate, with only the ability for one platform's email to be used as a second verification factor for the other.

    Rob

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-05-14T10:41:52+00:00

    KeePassXC does it for me. That works. But yeah Microsoft's implementation is utterly useless unless you're completely captured in their ecosystem, which you can't be because they don't make phones any longer.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments