Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Oldest
  1. Anonymous
    2025-04-05T20:59:15+00:00

    First, we don't all sit around staring at our screens - so a delay in replies to your "offer" is par for the course. Secondly, I don't think an "explanation" is what's missing here. Did you read through prior posts in this meandering thread? Clearly the issue is that Microsoft has designed something ("passkeys) that end-users tried and found cumbersome and irksome. With the technical expertise of Microsoft, they surely could have made the use of passkeys simple, obviously valuable to average end-users and NOT something that requires all these explanations and detailed instructions.

    Bottom line: No, not looking for a pitch on why passkeys, to use your term are "the future". Seriously?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-04-05T22:11:12+00:00

    Your post contains inaccuracies, unfortunately.

    " ... Microsoft has designed something ("passkeys) ... "

    Passkeys were created by the FIDO Alliance. Microsoft is a member of the FIDO Alliance, but so are hundreds of other companies.

    " ... end-users tried and found cumbersome and irksome ... "

    There will always be some people who can't figure things out, whether it's passkeys or something else. You don't need to figure anything out to use a passkey; all you need is a fingerprint or a face. The FIDO Alliance's technology takes care of the rest.

    " ... "the future". Seriously?"

    Believe it. Even the best passwords are no longer secure. With FIDO's technology there's nothing that can be stolen, exposed in a data breach, phished or socially engineered.

    The problems that websites are having with passkeys have nothing to do with the FIDO Alliance technology. That's happening because companies don't want to co-operate to make common interfaces.

    Was this answer helpful?

    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-04-05T22:35:36+00:00

    Oh good the technically inept are here to tell us what to do. Passkeys are dead. https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

    Okay NeighborDave0228,

    That blog article by a passkeys developer detailing the issues that developed between platforms and major developers like Google and others explains nearly everything I've personally seen and most confused user posts here in the forums as well, since it's these core issues with following the standard or simply ignoring them that create the fundamental issues behind the technical failures I've experienced with Windows 10 cross-platform operation, as well as the resulting structural interface problems that make them confusing for nearly anyone to use.

    If you read through that developer's history, you can see the issues created by Google and probably nearly everyone else now as well that have caused them to branch into both using their own authenticators for management, as well as needing to create more complexity in an attempt to patch the issues that the platform specific decisions are causing.

    So, the result at this point is that either an organization like Microsoft must make the decision to make the passkey system standards-based, but semi-proprietary by locking the user into their platform, or instead simply throw up their hands and drop passkeys altogether.

    It's interesting to me that it appears that Google was instrumental in fouling this up in the first place, though it appears that Apple was involved at least in terms of core implementation on their Keychain, which may also explain several threads I've seen personally regarding failed backups of the Microsoft Authenticator on Apple's Keychain as well.

    Microsoft's problem is the combination of these other issues, since by trying to still follow the standard as written, it's resulted in the creation of the ever-increasing mess of menus and other complexity that's driving users nuts, including myself which I'd initially ascribed only to Microsoft having left passkey management completely out of Windows 10, I assume in an attempt to force users to the Windows 11 platform, but leaving an extremely bad taste in the mouths of those like SirBlain and others coming in utter confusion to relatively complex discussions like this one.

    Unless Microsoft can force a reset with the other major developers like Google and Apple, the act of taking the passkey systems into a platform specific implementation may allow them to solve some of the problems and simplify its operation, but the fragmentation this creates will obviously kill the cross-platform options for authenticators which is precisely what Google claimed they were trying to protect when that initial standards definition failure occurred.

    Unfortunately, if these issues can't be resolved, as at least one of you has stated, this all leaves only the technically skilled among us with any useable combinations of passwords, managers and/or 2FA using authenticators, since the complexity of operating, maintaining and recovering those is showing up in these forums as problematic for most typical consumer users as well.

    Rob

    Was this answer helpful?

    0 comments No comments