Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-05-08T14:21:03+00:00

    Absolute rubbish. I now only have to put in a 4 figure number rather than an 8 character password consisting of letters numbers and symbols, how s that more secure?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-05-06T20:31:27+00:00

    Rob, I believe that anyone who uses Windows Hello (which is almost forced by default by Microsoft these days) "has" "passkeys" "enabled" in Windows, with no way to disable Chrome's web-through-Chrome-to-Windows "Ooooh, ooooh! Passkeys! Enabled! I WANT!" functionality for (many and more every day) websites.

    I get a "create a passkey" prompt Every. Single. Time. I log in to one of my Amazon accounts, for many Microsoft Cloud things, and I'm beginning to see them from other websites too. (It's almost enough to make a guy consider installing Safari on Windows, in hopes that as bad as Apple is, they don't do *that* particular thing...)

    -Jay

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2025-04-16T05:21:31+00:00

    I appreciate your response and it confirms my suspicions. Now I can get out of this community thread. I don't want the option for passkeys but after going into my Microsoft account, Google, Amazon etc, I admit defeat. The passkey option has never been activated on my end but I still deal with it. Thanks again!

    If you enabled Windows Hello while setting up your device, then you created the root passkey for logging into your Windows account, since that's how Microsoft implemented the ability to log into Windows using FIDO2 via Windows Hello Biometric and/or PIN as the verification method.

    Once that initial Windows Hello-based key is setup on your device, your Microsoft account also has the ability to login to your account via passkey, while websites like Amazon can recognize that your device is passkey enabled via Windows Hello, leading to the potential that some of these websites may prompt you to add a passkey in order to login more securely there in the future.

    Though Chien Sage is correct that passkeys are the future and for Microsoft passwords are really already dead, since I never use my own password anymore due to my Microsoft Surface Go tablet's Windows Hello performing Microsoft account authentication automatically, unfortunately the installed Windows 10 only provides login to other websites using roaming (i.e. cross-platform) authentication via another authenticator such as a smartphone or a 3rd-party security key.

    Since Windows 10 doesn't have a fully capable Platform (or 'bound') authenticator or any management interface like the one in Windows 11, it's difficult to visualize or understand what's truly going on during the setup process for a new passkey, and basically impossible to manage or view them via Windows 10 itself, which is why I've chosen to wait until I get a Windows 11 device to try and use passkeys other than the Windows Hello login itself.

    Though in theory passkeys are much easier to use than passwords, since you don't have to remember much of anything once they're initially created, it's the almost completely invisible aspects of these virtual items stored in your computer's TPM that make them confusing, especially when the actual passkeys are stored on a second device like your phone, since both devices are then necessary to create the passkey and later login using them.

    I understood all of this before trying to create the first passkey for Amazon and still had lots of difficulty setting it up, and then even had trouble using it, until I realized the added issues created by Windows 10.

    The mistake Microsoft and the other major platforms like Apple and Google made was to try and implement cross-platform authentication right away, since that's the most confusing method and potentially requires both some hardware configuration of Bluetooth and a good basic understanding of how passkeys work by the user. That's why all of the added menus to use them with Windows and most of the confusion as well.

    If Microsoft had fully implemented passkeys via a local Platform authenticator in Windows 10, as well as used these local authenticator apps instead as the first way to login, they'd have been much easier to use, since by default you'd have not needed a set of menus to choose an authenticator device, unless you already had another authenticator like a security key setup as well, since these are also typically using the same FIDO2 passkeys stored in that separate device.

    Instead, since Microsoft must support virtually any combination of supported computer (Windows 10 or 11), authenticator (local Platform with Windows 11, Android or iOS smartphone, dozens of 3rd-party security keys, etc.) we immediately had all sorts of new menus and all of the potential problems that come with them, which if a particular user only had and needed the authenticator built-in to Windows 11, wouldn't need to exist. At least not until a person decided they wanted to add the ability to use their passkeys while on other people's PC's, such as at work or school, or at a friend's house for things like logging into your bank or your own Amazon account for example.

    The complexity in all of this isn't really in using the passkeys themselves, since that's automatic and easy, it's in knowing where your private key(s) are stored (local PC TPM, phone, or security key) and whether they're actually there, since because they're basically invisible, the only way to know is either a management interface like in Windows 11, or simply try to use them to determine where they actually are, since the appropriate device will popup a request for you to authenticate using your biometric (e.g. Face via camera, Fingerprint reader) on your PC, phone, or security key.

    This all takes a lot to explain, and I'll include an appropriate document from Microsoft following this paragraph with explanations of the terms I've used and passkeys in general, but in truth, it's far easier to use once operating than it sounds. The problem is really getting it to initially operate, since until you begin to understand most of what I've mentioned above, it can seem daunting to someone without Chien's or my knowledge, since we have a technical background and are thus able to visualize things lie invisible network keys, the TPM, authenticator and other similar concepts that aren't intuitive for most people.

    What Is FIDO2? | Microsoft Security

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments