Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-01-20T04:49:04+00:00

    This "Passkey" garbage has run me around circles long enough. OK you made me have a photograph just to get into my computer and called it "Passkey", but it only works to turn on my computer. Everywhere I try to go anymore it tells me that "Windows Security" wants me too INSERT A PASSKEY, now it is no longer acceptable, WINDOWS WANT ME TO HAVE TO INSERT SOMETHING AS A PASSKEY WHEN I NEVER EVEN HAD A PASSKEY (except when WIN10 UNILATERALLY DECIDED THAT I NEEDED TO SHO THE COMPUITER MY FACE (which it then designed my face a "PASSKEY" THAT NEVER SEEMS TO WORK ANYWERE EXCEPT FOR BEING ABLE TO OPEN UP MY COMPUTER, I DO NOT HAVE ANYTHING CALLED PASSKEY TO INSERT SOMEWHERE INTO A COMPUTER THAT DOES NOT HAVE A SLOT LABELED "PASSKEY" [ALTHOUGH I HAVE INDEPENDENTLY DECIDED WHERE I WOULD NOW GLADLY INSERT AN OVERSIZE "PASSKEY" INTO, AND IT HAS NOTHING TO WITH COMPUTER HARDWARE!!!.

    I DO NOT KNOW HOW TO CONVINCE "WINDOWS SECURITY" THAT I DO NOT, NOR HAVE I EVER, HAD ANYTHING EVEN VAGUELY RESEMPLING A 'PHYSICAL PASSKEY, NOR DO I KNOW HOW MAKE ONE!!! HOW DO I GET INTO ANYTHING ON MY COMPUTGER WITH SOMETHING I NEVER HAD, NOR DO I EVEN KNOW WHAT IT IS.

    Lets reason this out. I paid for my computer, and inferrentially paid for the Win10 OS [since I doubt that the vendor is just 'givinge away "PASSKEYS", yet here we are now: "Windows Security" was not satisfied with telling me that i am already "NOT AUTHORIZED" to see, add onto, or deleted from information that is CONTAINED WITHIN A COMPUTER THAT I PAID FOR, and now, in another iteration of making themselves INDISPENSIBLE, by forcing me to try to figure our where to get a PHYSICAL PASSKEY (the FACE that is required to turn the computer on is not enough) to get into files that I also "OWN" but and not even certain exists, because I cannot even figure out what a physical passkey is, nor even if I were to have one I would not even have a clue as to where to INSERT IT INTO!!!.

    IT ALMOSTS SOUNDS LIKE "WINDOWS SECURITY" HAS NOW DEVELOPED ITS OWN PERSONAL INTERRUPTION OF MY ACCESS INTO MY OWN DATA ON MY OWN COMPUTER. IT ALMOST SOUNDS LIKE THE WORD "PASSKEY" IS A NEW VERSION OF WHAT THEY USED TO CALL "RANSOMWARE"

    DID I MISS SOMETHING?

    Was this answer helpful?

    8 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-02-11T00:41:33+00:00

    So this user's frustration is happening to at least 10,000 other people daily and they can't even post as much because inevitably a broken passkey has locked them out of their account.

    We could call them all wrong and point the fingers at them but ultimately, they are not able to use their computers, because of an absolutely broken, and low IQ implementation of passkeys.

    I meet a user like this dozens of times a week who are simply trying to operate their computer as they have been for decades and just cannot do so anymore because they are being demanded to provide something they never setup, and were never told about, and if they are being told about it it's not being explained properly.

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-12-09T18:11:04+00:00

    This thread initiated by Sir Blain expresses exactly the severe annoyance I find with Microsoft RE their stupid "Passkey" system. Since my technical knowledge is much more limited than Sir Blain, I still find this baffling. However I am glad to see someone address the sheer stupidity and arrogance of the Microsoft "engineers" or whoever designs this stuff for the vast #'s of end-users like myself who simply need (or have been forced by circumstances) to use these wretched Microsoft Windows products.

    I seriously despise the way Microsoft ropes us into using their products and then gums it up with idiotic things like "passkeys". Sir Blain expressed with more precision the exact problem I've had repeatedly.

    Now, I wish I understood what Sir Blain means about simply logging into my local computer without logging into Microsoft. Oh how I wish I could do that easily. I have no idea what he's talking about. I doubt I'm the only end-user who would prefer that. IF there is intelligent life (who also knows how to communicate without all the Microsoft abbreviations and acronymns that are almost as bad as the Federal Government's alphabet soup of mind-numbing meaningless gobbledygook) I would SO appreciate (no kidding) a clear explanation of how to stop using Windows "passkeys" and the "Hello" prompts and simply USE MY OWN COMPUTER efficiently. How can I log in to my Windows computer in a local application without the Microsoft interference of asking for passkeys? How? Please, someone give a specific list of steps to help me do that. I would love it. And do NOT say go to the "community". That is a TOTAL WASTE OF TIME.

    Was this answer helpful?

    7 people found this answer helpful.
    0 comments No comments