I appreciate your response and it confirms my suspicions. Now I can get out of this community thread. I don't want the option for passkeys but after going into my Microsoft account, Google, Amazon etc, I admit defeat. The passkey option has never been activated on my end but I still deal with it. Thanks again!
If you enabled Windows Hello while setting up your device, then you created the root passkey for logging into your Windows account, since that's how Microsoft implemented the ability to log into Windows using FIDO2 via Windows Hello Biometric and/or PIN as the verification method.
Once that initial Windows Hello-based key is setup on your device, your Microsoft account also has the ability to login to your account via passkey, while websites like Amazon can recognize that your device is passkey enabled via Windows Hello, leading to the potential that some of these websites may prompt you to add a passkey in order to login more securely there in the future.
Though Chien Sage is correct that passkeys are the future and for Microsoft passwords are really already dead, since I never use my own password anymore due to my Microsoft Surface Go tablet's Windows Hello performing Microsoft account authentication automatically, unfortunately the installed Windows 10 only provides login to other websites using roaming (i.e. cross-platform) authentication via another authenticator such as a smartphone or a 3rd-party security key.
Since Windows 10 doesn't have a fully capable Platform (or 'bound') authenticator or any management interface like the one in Windows 11, it's difficult to visualize or understand what's truly going on during the setup process for a new passkey, and basically impossible to manage or view them via Windows 10 itself, which is why I've chosen to wait until I get a Windows 11 device to try and use passkeys other than the Windows Hello login itself.
Though in theory passkeys are much easier to use than passwords, since you don't have to remember much of anything once they're initially created, it's the almost completely invisible aspects of these virtual items stored in your computer's TPM that make them confusing, especially when the actual passkeys are stored on a second device like your phone, since both devices are then necessary to create the passkey and later login using them.
I understood all of this before trying to create the first passkey for Amazon and still had lots of difficulty setting it up, and then even had trouble using it, until I realized the added issues created by Windows 10.
The mistake Microsoft and the other major platforms like Apple and Google made was to try and implement cross-platform authentication right away, since that's the most confusing method and potentially requires both some hardware configuration of Bluetooth and a good basic understanding of how passkeys work by the user. That's why all of the added menus to use them with Windows and most of the confusion as well.
If Microsoft had fully implemented passkeys via a local Platform authenticator in Windows 10, as well as used these local authenticator apps instead as the first way to login, they'd have been much easier to use, since by default you'd have not needed a set of menus to choose an authenticator device, unless you already had another authenticator like a security key setup as well, since these are also typically using the same FIDO2 passkeys stored in that separate device.
Instead, since Microsoft must support virtually any combination of supported computer (Windows 10 or 11), authenticator (local Platform with Windows 11, Android or iOS smartphone, dozens of 3rd-party security keys, etc.) we immediately had all sorts of new menus and all of the potential problems that come with them, which if a particular user only had and needed the authenticator built-in to Windows 11, wouldn't need to exist. At least not until a person decided they wanted to add the ability to use their passkeys while on other people's PC's, such as at work or school, or at a friend's house for things like logging into your bank or your own Amazon account for example.
The complexity in all of this isn't really in using the passkeys themselves, since that's automatic and easy, it's in knowing where your private key(s) are stored (local PC TPM, phone, or security key) and whether they're actually there, since because they're basically invisible, the only way to know is either a management interface like in Windows 11, or simply try to use them to determine where they actually are, since the appropriate device will popup a request for you to authenticate using your biometric (e.g. Face via camera, Fingerprint reader) on your PC, phone, or security key.
This all takes a lot to explain, and I'll include an appropriate document from Microsoft following this paragraph with explanations of the terms I've used and passkeys in general, but in truth, it's far easier to use once operating than it sounds. The problem is really getting it to initially operate, since until you begin to understand most of what I've mentioned above, it can seem daunting to someone without Chien's or my knowledge, since we have a technical background and are thus able to visualize things lie invisible network keys, the TPM, authenticator and other similar concepts that aren't intuitive for most people.
What Is FIDO2? | Microsoft Security
Rob