Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Oldest
  1. Anonymous
    2024-11-25T22:32:52+00:00

    "inconsistent visual interfaces these various companies are using with passkeys are what's truly causing these problems."

    This is only a small part of it. Users being forced into it without their knowledge, consent, or even a tiny explanation of what these are or how they work is why there are problems here. Every single one of these companies needs to prompt the user, AFTER a successful login, not before, the prompt needs to offer an explanation of what a passkey is, how it works, why it's better than a password, and then give the user a gentle way to turn them on.

    Unfortunately this is actually the way it's working: User attempts to login, Windows/Google/Amazon/Browser immediately demands a passkey that does not exist, without the user having set one up at all, or even being aware of it.

    Hilariously, if you're on Windows 10, you have no way to access, view, manage, or delete those keys. It's one thing for iOS, Android, or Windows 11 to do this, since these users all have access to a passkey GUI that does not exist in Windows 10.

    Was this answer helpful?

    9 people found this answer helpful.
    0 comments No comments
  2. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-11-26T20:53:30+00:00

    Yes, SirBlain,

    You'll find in my later posts (possibly in this thread?) I've indicated that if Microsoft isn't going to provide a local interface for managing passkeys with Windows 10, they should simply drop them there altogether, since as you stated, the lack of information about these makes them basically nonfunctional for that operating system version, even for relatively skilled users like me.

    I agree that better information is required, but that's really all part of any good visual interface, since it should inherently lead you through the process step-by-step, with options to either learn more or even skip the process altogether at each critical point, none of which most of the handful of dialogs I ran into with Windows 10 ever actually did.

    Even the Google Android interface that prompted me to create a passkey on the device itself never told me where this would actually be stored, which is one of the most confusing aspects of passkeys since they can be flexibly created on either the current device when that's supported as with Windows 11, or instead on a second device like a smartphone when that supports them, along with having Bluetooth enabled on both devices to allow them to confirm they're in close proximity and thus not being remotely controlled by malware.

    All of these capabilities make passkeys both versatile and relatively easy to migrate copies from one device to another, but that's also where the greatest confusion comes in, since it requires a person to understand a virtual concept that's only typically handled by highly skilled members of IT or other engineers capable of visualization.

    Unfortunately, I know these are the types of people who initially created and tested passkeys, while instead of using a pilot group of everyday users in at least something like a large corporation to confirm the core interfaces made simple sense, they just threw them out into the public realm with no real warning built-in to understand what you're getting into.

    What I finally realized they should have done is begun with only the local passkeys creation concept with any new user and built from there, since understanding these invisible virtual objects on your local device is necessary to build the potential for using them cross-device.

    This also implies that the Windows 10 scenario should have never existed, since if they can't support them locally, they're functionally useless for most anyone without a smartphone anyway and having this pop up out of nowhere is massively confusing, while most less capable consumers likely have this older operating system. Since many of these will get replaced over the next year, bringing in the passkey concept with the new OS and local passkeys based on Windows Hello would fit quite well, with only a local interface required unless and until the device owner/user specifically requests this next step of making their smartphone a mobile carrier for use with other devices.

    You'll note this avoids the need for the popup choice of device selection initially as well, so the only thing the local device requires the user to learn is how to create and use the passkey itself for a website, which is quite enough of a concept to learn as you've implied.

    Creating the initial Login.Microsoft.com passkey with Windows Hello isn't truly a problem, but throwing a popup without any prior explanation obviously is, especially if it's not obvious how to bypass it until someone has the time to spend to learn its proper use.

    I actually meant most of the above with my earlier interface comment, but to the average person who's never programmed one themselves as I had quite early in my career, that seems like an oversimplification. The interface I created allowed a user to control an early LED sign used for marketing or other information display based on key combinations printed on the back of the included flat-panel keyboard, with hints printed above the keys on the front. Most people could manage basic use without ever reading a manual, which was good since the company took nearly a year to get one printed.

    So yes, I fully understand what you're saying, I just see this from a different point of view. But rather than having someone like me on the team that developed and released the passkeys, I'm betting they were basically all developers who hadn't ever been required to get in front of a group of their customers like I had as a network administrator in an educational institution for several years. Though in truth, that LED signage interface came earlier in my career and used some of the everyday people from all levels working in that same company for testing, with the only initial aid being to point out the quick-start user manual printed on the back of the keyboard.

    Rob

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-12-09T18:11:04+00:00

    This thread initiated by Sir Blain expresses exactly the severe annoyance I find with Microsoft RE their stupid "Passkey" system. Since my technical knowledge is much more limited than Sir Blain, I still find this baffling. However I am glad to see someone address the sheer stupidity and arrogance of the Microsoft "engineers" or whoever designs this stuff for the vast #'s of end-users like myself who simply need (or have been forced by circumstances) to use these wretched Microsoft Windows products.

    I seriously despise the way Microsoft ropes us into using their products and then gums it up with idiotic things like "passkeys". Sir Blain expressed with more precision the exact problem I've had repeatedly.

    Now, I wish I understood what Sir Blain means about simply logging into my local computer without logging into Microsoft. Oh how I wish I could do that easily. I have no idea what he's talking about. I doubt I'm the only end-user who would prefer that. IF there is intelligent life (who also knows how to communicate without all the Microsoft abbreviations and acronymns that are almost as bad as the Federal Government's alphabet soup of mind-numbing meaningless gobbledygook) I would SO appreciate (no kidding) a clear explanation of how to stop using Windows "passkeys" and the "Hello" prompts and simply USE MY OWN COMPUTER efficiently. How can I log in to my Windows computer in a local application without the Microsoft interference of asking for passkeys? How? Please, someone give a specific list of steps to help me do that. I would love it. And do NOT say go to the "community". That is a TOTAL WASTE OF TIME.

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments