Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Newest
  1. Anonymous
    2025-06-15T01:48:33+00:00

    I have now learned that it is a waste of time to ask any question on a microsoft affiliated site. The following very minor registry edit that I found elsewhere worked.

    Disabling Passkey Prompts via Registry Editor

    1. Press the Windows key + R to open the Run dialog.
    2. Type "regedit" and press Enter to open the Registry Editor.
    3. Navigate to the following key:
    HKEY\_LOCAL\_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System
    4. Right-click on the right-hand side of the window and select "New" > "DWORD (32-bit) Value".
    5. Name the new value "NoPasskeyPrompt" and set its value to 1.
    6. Close the Registry Editor and restart your PC.
    

    EndFragment

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-06-13T07:28:54+00:00

    Hi Rob,

    About account recovery, you're focused too much on the tech; I'm focused on the legal. If I send a notarized signed document claiming my identity and backing it up with, say, a copy of my passport, then for legal purposes I am me, and Microsoft can trust that to recover my account. To a certain degree this could be challenging if my name would be "John Smith" living at "123 Main St"; one option - and it should be optional - would be (under the strictest of "we will use this only for account protection" contractual privacy commitments) to allow users to provide a greater degree of proof of their identity at the time of account creation, to better allow matching at a later time of need for account recovery.

    The United States has a structural distrust of central government (and, although now diminishing for very good reasons, excessive trust of corporations); I've lived in Europe for the past seventeen years, where it tends to go the other way; it is *trivial* for me to prove my identity - I have a national police issued ID card with an embedded digital certificate bound to my national ID number, and most truly-personal accounts (even down to many e-commerce sites) gather that ID (for tax purposes), so I could prove who I am for the purposes of account recover with nothing more than a web request form digitally signed by my ID card.

    Even in the US, online automatic global identity document verification services have long existed (see how ID.me performs its online sign up).

    This stuff is not rocket science. It's much more law, politics, and (problematically, unbridled) capitalism/ commercialism.

    We, in security and in usability, must know and remember - and instruct our bosses - about the legal and societal stuff surrounding our tech toys.

    Microsoft has most certainly not gotten (or, at high commercial levels, chosen to ignore) this fact.

    Going back to usability, you continue to fall into the falsehood of "The only application I'll ever run on my computer is Lotus 1-2-3" (this was the impetus of Microsoft creating the in-account application virtualization and eventually-enforced proper shared libraries), which of course today takes the form of "I'll only ever use Apple products". But, we don't; we do use multiple applications, multiple platforms. This "Windows Hello is GREAT IFF you ONLY use Windows" is not an acceptable argument for pushing the use of Passkeys. Not until true, uniform user experience, cross-platform synchronized passkeys, withOUT the trivial confusion of "is that really a passkey prompt or is that a clever hacker's browser iFrame?!", are deployed.

    And physical external keys like my handful of Yubikey FIDO2 keys are NOT simple. They're very secure, but they're a nuisance. They would either require (even assuming that most accounts allowed multiple passkeys to be associated, which most accounts do not) owning multiple of these things, to keep one each in each of the various places where I usually computer, or would require me to dig me one portable FIDO2 key out of my handbag over and over and over and over and over again throughout the day... just not practical.

    You are correct in your underlying theory, but your insistence that it's practical or usable *today* is simply wrong with current implementations, and I see no evidence of real movement toward the converged, well- (usably)-implemented version that would make passkeys an actually good idea for most people any time soon. (And even then, reducing authentication to the one single factor of "my device" remains a bad idea, weaker than whatever other authentication method + a physical second factor; yes, modern Windows kernels are much harder to get into to the depth that would allow directly accessing the TPM, but how hard is it for user-level malware to act like the human user and tell the passkeys prompt "yes, that's me, hackhackhackhackhack the website that just foolishly trusted only Windows Hello on *this* device to prove *that* identity?).

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-06-13T06:30:30+00:00

    You are indeed right that it only applies to S mode, but that's is because Microsoft locks the whole computer down, which is unacceptable, not because they made any architectural improvements.

    It's supposed to lock the applications down until the user specified otherwise, not the user itself!

    Asking for permission to use the camera should happen at device driver level, not appx level. Applications should have their file system sandboxed. Local/LocalLow/Roaming is good, but the system needs to ask if the application tries to read or write outside its own folder or those folders.

    The system should ask if i am application can write files in system folders or the registry. Regedit and Explorer get a carte blanche.

    Applications need to be able to specify to the OS that you should not be allowed to debug it or read its memory.

    Applications should be able to specify that their window cannot be recorded, and again this happens at display server level so no applications can. They just get s as black box instead. You already have it for DRM, why can't an EXE ask for this?

    And applications need to **** of the kernel, period. Especially anticheat. Popping up saying it needs to be an administration isn't enough. It needs to pop up saying "this application wants to install a driver to get full access to all memory in your system, are you okay with this?"

    Both Apple and flatpak has proven this can be done with any binary. Get to work.

    Was this answer helpful?

    0 comments No comments