Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Newest
  1. Anonymous
    2025-04-06T19:13:01+00:00

    Passkeys are not 'easier' for me. I don't know what they are. I did not set them up so I do not know their values. When prompted to respond to a QR code I get taken to a site I've never heard of 'fido' or 'sido' or something like that. Backing out and simply using my passwords requires several more steps.

    How can I get rid of this passkey mess?

    Thank you, Rick

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-04-06T10:51:41+00:00

    Microsoft's problem is the combination of these other issues, since by trying to still follow the standard as written, it's resulted in the creation of the ever-increasing mess of menus and other complexity that's driving users nuts, including myself which I'd initially ascribed only to Microsoft having left passkey management completely out of Windows 10, I assume in an attempt to force users to the Windows 11 platform, but leaving an extremely bad taste in the mouths of those like SirBlain and others coming in utter confusion to relatively complex discussions like this one.

    Unless Microsoft can force a reset with the other major developers like Google and Apple, the act of taking the passkey systems into a platform specific implementation may allow them to solve some of the problems and simplify its operation, but the fragmentation this creates will obviously kill the cross-platform options for authenticators which is precisely what Google claimed they were trying to protect when that initial standards definition failure occurred.

    Unfortunately, if these issues can't be resolved, as at least one of you has stated, this all leaves only the technically skilled among us with any useable combinations of passwords, managers and/or 2FA using authenticators, since the complexity of operating, maintaining and recovering those is showing up in these forums as problematic for most typical consumer users as well.

    Certainly, this whole thing starts with Amazon popping up a system prompt without asking first and we're all confused. And of course it will end up setting up passkeys in addition to passwords, which means it doesn't provide any protection because my insecure authentication method is still out there. That's how we got here.

    But once I found out what Passkeys were, the problem quickly turns into Microsoft again for a whole host of reasons.

    Firstly, it pops up a modal dialog box. Now I can't use Firefox at all until I decide to finish my login to Amazon. Okay, that's kindda stupid, because what it means is I should in theory be able to pop these dialog boxes up whenever I want and just really annoy you with them. I wonder if you've inserted any protection against putting them in ads? If not, that could be fun. Just to randomly annoy people.

    Anyway, this modal popup offers me to log in with the pincode to my computer. Because of course, my desktop PC does not have biometric sign-in, and even if it did you can still use the pincode. Now, the pincode has a much lower security than my password for my password manager, because my password manager's password is much longer and uses letters and symbols as well.

    Once we get past all this terrible security of having 3 different ways to compromise my account, my passkey gets saved on my passwords database. Where is that? Well, let's search for it on Windows! So I search for passkeys. I get nothing except the chance to open Bing to search for it in my least favourite browser. Now, an idiot or extremely tech illiterate person (such as a very old retired plumber, let's say) is going to stop here and get confused, but thankfully for me I am a software engineer, so I decide to look through the now open browser and find out about passkeys in English.

    So I write "pass" into my search bar now and find "Administrer netværksadgangskoder", which is the old passwords page from Windows Vista. It does not have passkeys. Because the people who worked at Microsoft at the time were actually smart and knew that passwords = adgangskode, I would assume therefore passkey should be adgangsnøgle, but it isn't. Microsoft just sort of forget about that because the current Windows team is absolutely clueless.

    I go back on the internet and find out that it is in settings. So I go into settings and I look into "Sikkerhed", which doesn't help because that settings panel is absolutely huge since Microsoft just can't help themselves but make my system insecure by harvesting literally all my data and all the data about my dog unless I withdraw consent, and here are all the 3 billion ways in which I can withdraw consent.

    Alright great, so now I look it up again and find out it's under accounts. After scrolling past the advertisement for a PC Game Pass and Office 365, which are products that I don't want to buy and almost instinctively turns my away from that settings page if I can help it because I hate ads, I find them under the name "Adgangsnøgler". I would think that accounts would be Windows accounts since this is Windows settings, but okay.

    I can't interact with these things at all. I cannot open or see them, I cannot copy their information. I really just can't do anything. They are glued into my Microsoft account. Further still, the settings page is not called "Adgangsnøgler" in search, it's called "Indstillinger for adgangsnøgle" which is grammatically incorrect (direct translation is Settings for Passkey) and also inconsistent. Furthermore, if I search for Adgangsnøgle and hit enter a little too fast it goes on Bing instead of opening the passkeys window because Windows searches the web faster than your computer, which is INSANE but a topic for another time, and woe be the day where the first result is a scamsite ad at the top of the search results... Worse still, searching for "Adgangsnøgler", which if you recall is the name of the settings panel, will not include "Adgangsnøgle" because that doesn't contain the plural r at the end - the plural r which must grammatically be there, so it isn't found when searching for the actual title of the settings panel.

    But that's okay, because I still have KeePassXC and it has support for passkeys! And not only does it have support for them, I can see information about them and export them into JSON files. Oh wow, imagine that. Good thing too that gives me a popup saying don't leave these files lying around. Good advice!

    So how do I put passkeys into KeePassXC? Well.... Microsoft's implementation simply does not offer that option. Amazon will popup the Windows security dialog on Firefox or Chrome, and it has no option to use KeePassXC. Fortunately, KeePassXC has a workaround for this! Through an extension it can hijack the prompt, and then KeePassXC will offer the key instead. Okay.

    So now I can use cross-platform passkeys. Or at least my browser can, if I want to use something that isn't my browser, such as the Discord desktop app for instance, that simply wouldn't be possible even if they did add the option. Not so great. What's also not so great is that the Amazon implementation glitches out when trying to create a passkey. I can use those that I have, but I can't make new ones. It works elsewhere. Obviously something as simple as hiding your password behind biometrics should not be hard to implement for major tech giants... what?

    So, finally we have arrived at our destination. The problem is not passkeys. I could indeed put a passkey into a password storage solution and I could indeed sync it across my devices however I wanted.

    The problem is not with Apple, either, unless we count the part where they were apparently deleting them. That's obviously a bug, but if we look at what they actually implemented, we can see that within settings there's an integration popup wherein I can simply use Strongbox (aka KeePassXC on the mac) and now keepasses work systemwide. I don't have to fiddle with browser extensions or anything. Install the app, set it as default (it adds itself automatically) and go for it. Easy.

    But my Amazon.com passkey is still stuck on my Microsoft account. As far as I can tell there's no way to get it out. Fortunately, I can use my oh so very insecure password to generate an infinite amount of passkeys, so it's going to be alright.

    And then I come in here to be told that this thing is great and it's the future and it's the bee's knees.

    It's not. It's an absolute joke and everyone involved with its implementation on Windows and at Amazon should be ashamed of themselves. The people who implemented the cloud sync should be ashamed. The people who did the settings panel should be ashamed. The people who didn't offer integration should be ashamed. The people who did localisation should be ashamed. The people at Amazon who popped it up and had it say "Firefox requests" instead of "Amazon requests" should be ashamed. Amazon for popping it up without me asking for it should be ashamed. The people who created the serverside part of this should be ashamed.

    How can you advocate for this thing? Seriously now. Please.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-04-06T09:47:21+00:00

    < SNIP >

    The passkey popup you refer to comes from Amazon. They offer you the opportunity to sign in with a passkey instead of a username/password combination. If you agree, they will setup a passkey for you. Microsoft is not involved.

    If you find Amazon's process confusing, you should complain to Amazon.

    Chien Sage and others,

    I'm quoting this portion of your text only as an anchor, since there's several branches here now where we've all hijacked SirBlain's thread to discuss these issues with passkeys, but I believe it's the best place available currently due to the critical piece that NeighborDave0228 provided above via the following URL.

    https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

    To try and clarify the problem this developer exposed, the issue is actually within the FIDO Alliance WebAuthn specification, where the Authenticator Selection Extension (authnSel) and possibly other extensions that were removed from the Level 2 spec mention in the w3c/webauthn thread he linked within 'The Warnings' section of his blog article, create a quandary for developers attempting to support passkeys.

    Since this effectively breaks portions of the cross-platform portions of the spec, it leaves it to developers like Microsoft as a platform and Amazon as a potential website target for these services, to decide how to manage these issues between the Level 1 and Level 2 (and possibly later definitions of the spec that may have come since) are resolved and supported in their own implementations of passkeys.

    Since the developer's blog is from 26 April 2024, we don't know without further research what's changed in the specifications since, but his own description of the general degradation to workarounds and platform specific solutions to that point is precisely what I'd have expected as a result.

    My own previous comments here or in other threads that the various developers should follow the spec or major participants should provide guidance were made without knowledge of how the spec itself had apparently diverged and devolved since that point, or anything that may have occurred since. If it remains in a shambles or become even more fragmented since then, this means there's simply no stable base upon which at least cross-platform or 3rd-party authenticator development can be performed.

    That's why I stated in my previous post that the blog article explains virtually everything I've seen, since regardless of any particular interface or other issues an individual website implementation might have, if the spec itself has diverged, they'll never be able to build something that works for every possible revision or possibly any cross-platform support at all.

    That's likely why I was seeing my own issues with creating and eventually using the Amazon passkey with Windows 10, which though it supports Windows Hello as an anchor, has no local authenticator or management console for these, and as such depends on the Android phone authenticator in a cross-platform mode that has questionable support, along with other issues related to Google's own implementation as the developer's blog article also mentioned.

    It's also clear from this why the confusing sets of multiple menus with no clear pathway to perform the creation or use of passkeys in Windows, since the workarounds required to resolve all of the possible issues leaves no other option.

    It's also why I almost immediately saw the need for Microsoft to create their own authenticator within Windows itself, but that's precisely the undesired platform specific implementation you'd rather avoid. The reason for this is that if only a local platform implementation can work, regardless of the fact that might be simpler for users, it removes the ability for any external key backup outside a single platform and potential loss of the entire set of private keys as a result.

    We've already seen the results of a similar parallel set of issues with the Microsoft Authenticator, which though designed cross-platform by default using only Android or iOS-based apps, is riddled with common user issues such as backup and recovery of even the associated Microsoft Personal account if the smartphone is lost, damaged or simply traded in or factory reset.

    The key problem with using any of these is simple, the private keys for any of these are contained on the phone, but generally invisible to the user, who only typically sees the authenticator app as just that, like any other app that can be reinstalled at will. Understanding the virtual aspect of even relatively visible TOTP Code keys stored in the smartphone is difficult. Making them even less visible as is the case with passkeys means that only the most technically capable and able to visualize among us can hope to picture what's truly happening, unless the interfaces are designed to be simple and obvious to help the user visualize what's actually going on.

    Rob

    Was this answer helpful?

    0 comments No comments