Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Oldest
  1. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-12-09T19:04:46+00:00

    You're already in the Microsoft Community in this thread, you're simply posting in the wrong place for the additional help you desire, though maybe SirBlain will return to try and provide an explanation if he's still monitoring his thread.

    You need to Ask a Question under the Get Started pull-down menu at the very top of this or any page here. This will want you to select your Windows Version and any other items you might use to describe the product (Windows, 10 or 11?) involved, as well as fill in the other fields including being as clear and complete as possible in describing what you'd like to do, which is using a local account on your PC.

    You can ask other questions about this and/or describe what you'd like to do and/or avoid, like passkeys or even using your Microsoft Account to login, for example, which will allow those reading to ask you additional questions to better try and help you create the situation you'd like. Using simple English words to describe that is actually best, though you can reference this thread by mentioning the title, which anyone here can easily view to see your initial post.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-12-18T16:34:15+00:00

    You do not have to use it. It's your computer, not theirs. Unfortunately one of the few ways I've found to opt out of their absolutely broken passkey implementation, is to sign out of your Microsoft account, and sign in as a local account on your computer.
    This has the added benefit of less privacy being violated by the dishonest employees that make up the entirety of the staff at Microsoft.

    Ain't this the truth.

    I'm an IT professional myself and I have very competent password management in the form of KeePass (XC and Strongbox) and my own cloud storage that I sync it with and a YubiKey.

    I have done it this way specifically to keep it compatible with all my computers, which can run any of the three major operating systems, and to keep it out of the hands of major tech companies who, despite their technical prowess, have turned their systems into "nagware" and even malware.

    The mac implementation just asks if I want to put it in Strongbox because I registered Strongbox as my password manager and the operating system respects that.

    But as usual Windows is a nagware spaghetticode monstrosity. It doesn't care that I have my own solution to any of this - it's going to pop up and it's going to nag me every single time until I relent (which I won't, I just actively avoid Windows as much as possible now).

    Leaving aside the case for passkeys, which is seriously suspect to anyone with even a modicum of competence and only has any value for the people who keep using the password "password1234" on all their accounts (which is not an insignificant amount of people I admit), this nagging isn't built in a way so it nags me to use passkeys - it's built in a way that nags me to use Microsoft's particular implementation of passkeys.

    This will not happen. If I end up in a situation where it is either WIndows with passkeys or no Windows, I am easily reaching the point now where all it takes is a straw to break the camel's back.

    I am sick of nagware, and Windows is infested with it, and it never seems to end. It's like the whole operating system consists of Clippy at this point.

    Was this answer helpful?

    9 people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-12-19T21:13:55+00:00

    ishayuG,

    I think your last few paragraphs are likely describing the issue for a few more technical users, while SirBlain has better described the issue as it relates to the typical personal user of Microsoft's products.

    However, what I don't think many other than people like those trying to aid others here understand is that the security issues caused by passwords have grown exponentially as new methods like passkeys and other 2FA methods are finally gaining popularity, resulting in a massive increase in 'last gasp' successful account thefts using passwords, especially of those like gaming accounts that are easily sold by organized criminal gangs.

    Passwords are truly useless as 'security' now, since there are simply so many ways they can be captured or stolen, meaning they must be removed as soon as possible from all accounts, not just those belonging to less technically capable users. It's truly surprising how many people post that they knew better then to make the simple mistakes that resulted in losing their accounts, or getting scammed, or any of a number of different ways that criminal organizations have found to monetize the average home computer owner. And even here we're seeing the same issues happen to those using Google or Apple products, so Microsoft isn't the only one having to deal with this, simply the largest.

    The other thing that most probably don't think about is that unless they're purchasing something from Microsoft other than the Windows that comes with a new device, there likely isn't much reason for Microsoft to care if they lose them as a customer, since last I read that copy of Windows typically nets them something around or possibly less than $50, while the true money is made from subscriptions to things like Microsoft 365 (e.g. Office), the added Cloud storage this includes or other products like games.

    Listening to you is why I personally suspect Microsoft would be fine with losing customers that don't truly want to use their products, since from their standpoint it's really the commercial users who also need their employees to have access from their home machines or those wanting Microsoft 365 themselves for either small business or personal use that are the customers they really want to retain.

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments