Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Oldest
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-05-08T22:41:58+00:00

    They have more chance of guessing a 4 digit pin than a 8 character password which is far from easy to guess. Do you work for Microsoft?

    You're making the same obvious mistake that everyone who doesn't understand what a Window Hello PIN actually is always makes, since there are multiple reasons what you're stating is incorrect.

    The 4-digit PIN only works on the device itself, while the password is for your Microsoft account that's accessible from anywhere in the world, meaning that an attacker can't use the PIN unless they have physical access to your device.

    If an attacker gains access to your password via any sort of remote attack such as a website hack or installing malware on your device and either capturing it with a keylogger or getting it from a locally installed password manager app including stored within the Edge browser, they have one set of information required to access your online account, which is why 2FA is so important.

    Your PIN can't be captured via a keylogger app because it's entered when Windows isn't running (locked), and it's stored encrypted within the TPM module, so it's never accessible in text form anywhere even in the PC itself, it's just verified against the PIN you enter locally on the PC keyboard and if correct, you're logged into Windows locally.

    The TPM has anti-hammering protection that for version 2.0 locks the TPM after 32 tries, after which new entries are ignored until 10 minutes are elapsed and one additional try is allowed, again locking on failure, while waiting for 320 consecutive minutes with the device powered on allows the maximum of 32 additional tries. This 10-minute countdown timer only operates when the device is on or in sleep mode, so if the device shuts off automatically the number of tries remains constant. For this reason, I personally changed my own Windows 10 PIN to use 5-digits, so even if a thief has possession of the device, they'd need to realize that first, and then the number of possible PIN values increases from 10,000 to 100,000, while you can make that value even larger or I believe use alphabetic characters as well, though the risk of forgetting it yourself increases as a result.

    If you lose the device to theft, a thief will typically just reinstall Windows to sell it anyway, so unless you personally are a high-value target like a billionaire or similar, it's unlikely anyone would bother to try even 4-digit codes for many hours, days, or weeks (up to 7 days in front of the device trying a new code every 10 minutes if they work constantly and don't make obvious mistakes like retyping the same code, etc.) to access whatever it contains, by which time you should have either locked the device through your Microsoft account or hopefully managed to find it.

    Once the correct PIN is typed, Windows Hello uses your Private key stored encrypted in the TPM in a challenge process with login.microsoft.com to generate a transient passkey that's sent to the server to login, so no actual password is ever used or stored anywhere in this process, thus it can't be directly hacked like an actual password can. Without the Private key, the passkey itself is useless, so even if someone could capture it from the network, it'd be useless from anywhere other than that device at that particular time, so it can't be easily phished from the user himself like TOTP codes from your phone, email or even an Authenticator can.

    I've likely forgotten at least one or two other reasons a TPM-based PIN is more secure than a password, but hopefully you're beginning to get the point. A Windows Hello PIN is far more secure than any password can ever be, regardless how long, complex or careful you are personally about protecting it, since in reality it's simply a shared secret that you know that unfortunately the other end of the login connection must also know as well, while with a passkey involved, the website on the far end stores and uses its own Private key that's used along with your Public key to sign the challenge data they send during the process of requesting your passkey to confirm your identity, since your passkey actually contains that information and no username is actually needed with passkeys at all.

    Here's a search with multiple articles that likely say at least some of what I've stated above to verify if you wish. They likely say some of it in easier to understand language, I won't bother to look since I know enough already.

    Windows PIN vs password Microsoft.com at DuckDuckGo

    Amazon has some of the most annoying and I believe incorrectly implemented use of passkeys I've seen, which along with issues with passkey use on Windows 10 is why I've decided to wait until I get a Windows 11 device to use them. Even so, since Windows 10 has no built-in authenticator, I was able to stop Amazon's prompts for the passkey by simply disabling the Google Password Manager on my Android Phone, which since I use the Microsoft Authenticator instead wasn't a problem for me.

    Maybe it's a bigger problem with Windows 11, but I don't know why it would be, and I'd personally just start using passkeys instead if I had 11 anyway, since it's simpler and more secure for well implemented websites.

    Yes, there's lots of complex things to understand regarding Windows Hello, PIN's passkeys, etc., if you only feel safe if you understand them fully. But using them is far easier than that once you're properly setup with Windows Hello on Windows 11, so anyone with that should just start using passkeys instead. I know I would.

    Rob

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-05-13T03:53:14+00:00

    Moronic indeed. What a mess.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-05-13T03:53:46+00:00

    Good grief.

    Was this answer helpful?

    0 comments No comments