Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Newest
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-11-25T19:29:48+00:00

    I have a circular issue with the passkey requirement. I tried to sign into my amazon account today and suddenly, across all browsers and without any warning, I can't access any of my online accounts without a passkey. I hate these kinds of nazi-like tactics but fine, I need to order a winter hat so fine. I follow the link you provided, create a passkey and, lo and behold, amazon won't accept the passkey forced upon me by windows. The solution is to log into amazon to create a passkey they recognize, but, once again, I've been logged out of the account without warning and without my participation and consent. So now, I have no solution to this issue. All of the browsers I use are requiring this passkey. But the passkey isn't working. Thanks google. I swear you people are trained in the 7th circle of hell and nothing makes you people happier than tormenting the hapless victims of your insanity.

    Jenafire Jem,

    If you'd read my posts on the second page of this thread, you'd have seen that I don't consider Amazon's implementation of these passkeys either reasonable or functional, so you might have avoided creating that particular passkey altogether. Note that you replied to my early post in July, before I'd had the chance to see what other types of problems those in this and many other threads here are having using passkeys, after which I stopped recommending people with Windows 10 use them altogether and really started suggesting that most people should wait for Microsoft, Google and others work out the bugs with more experienced users first.

    In your particular case, I recommend that you instead go directly to Amazon to try and get some aid in regaining access to your account, since though those here can help with Microsoft and to a small extent using your phone with passkeys, the finger-pointing and confusion caused by the inconsistent visual interfaces these various companies are using with passkeys are what's truly causing these problems.

    If you do want to try and get help here with your Amazon passkey issues, then you should start your own thread and describe the specific issues with your Amazon account completely, since adding your post in this old thread both won't get it noticed by others and really just adds to the confusion over what your particular issues might be.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-11-25T06:26:13+00:00

    I have a circular issue with the passkey requirement. I tried to sign into my amazon account today and suddenly, across all browsers and without any warning, I can't access any of my online accounts without a passkey. I hate these kinds of nazi-like tactics but fine, I need to order a winter hat so fine. I follow the link you provided, create a passkey and, lo and behold, amazon won't accept the passkey forced upon me by windows. The solution is to log into amazon to create a passkey they recognize, but, once again, I've been logged out of the account without warning and without my participation and consent. So now, I have no solution to this issue. All of the browsers I use are requiring this passkey. But the passkey isn't working. Thanks google. I swear you people are trained in the 7th circle of hell and nothing makes you people happier than tormenting the hapless victims of your insanity.

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-11-02T20:01:47+00:00

    This is a really really bad take. I would suggest to do something research on the negative aspects of key passes and how they are not better than passwords. They are just another option that is trying to do the same thing. The bigger issue is this feel more like a c-suite idea which gained some traction and now IT is trying to salvage it from being a very bad idea. To say insecure passwords are better than biometrics is something that I suggest you actually research into how they can be circumvented before you get pwned.

    Cmoney619,

    You should probably read all of my posts in this thread before responding, since I have noted in later posts that there are problems, especially when Windows 10 is involved, since the inconsistent methods used by both 3rd-party websites and in some cases even Microsoft itself to display passkey prompts or perform management cause their own confusion and difficulties that the typical consumer often can't resolve.

    There has been a lot of work put into the passkey system, since it's the first attempt I've seen at making a public key cryptography system work on a global scale, with support by and for virtually every organization including governments and their websites regardless of who's physical platform or operating system is being used.

    The problem with public key cryptography is that it's highly complex, so coming up with a way to make it possible for your everyday consumer to use and manage these keys was never going to be easy, and the initial attempts to rollout the FIDO2 Passkey system to users is definitely showing that it's not all going to work seamlessly.

    It's not the passkeys themselves that are the bad idea, it's the typical issue of too many ways to do the same thing that's unnecessarily confusing, while for Microsoft I think the biggest problem is that people just need a simple way to use and manage these on their own individual PC devices, rather than the confusing options of sharing the passkeys with other devices like their smartphones, etc.

    If the only device that was supported by default was a local passkey store on the device itself, with other optional storage locations like the smartphone or even security keys that require the use of a confusing list of options only presented when a person chooses to add or select these instead, then it might be easier for the typical non-technical user to make use of these relatively invisible items, since virtual objects (passkeys) and the existence of them on multiple various devices are simply too much complexity for the average person to understand or visualize.

    As for where you stated, "To say insecure passwords are better than biometrics", I don't have any idea where you believe I said this, since everything I've written about passwords is they're highly insecure and useless and should die as quickly as possible.

    I've stated that passkeys are better than most anything else that exists and since FIDO2 uses Biometrics as one way to enable the secure use of passkeys, yes those are better than passwords and in fact many other legacy options like TOTP codes, since passkeys themselves can't be easily phished and are useless on other devices. So, I think you've misinterpreted one of my statements.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments