Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,160 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,830 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

3 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Anonymous
    2025-06-20T12:40:54+00:00

    This system is terrible, and the replies have all been 'the billionaire companies are forcing this on you so get used to it.' That's so backwards and condescending to people who are rationally frustrated by this.

    When I go to log in to my outlook account and I click on the username field, instead of just putting in my saved username, it demands a passkey...or...I can START to type my email address and it will allow me to select it. The passkey doesn't prevent me from logging in, it just pushes itself as the main choice that I then have to inconvenience myself to get around. And I will because I am no using a passkey, biometrics, 2fa, or any of that because it is NOT. CONVENIENT.

    Worse, when I do finally enter my email address and submit it, it does not give me a password field, but rather a 'get a code to sign in' prompt. I do not want to get a code to sign in. I want to use my password, and so I again have to click 'other ways to sign in' which then brings up a menu. This gives me pin, biometrics, and finally 'password.'

    I check my email 10 times a day for various reason, and now, instead of just clicking 'username/password' and having it autofill, I have to navigate menus and dodge Microsoft creep to accomplish what took a single click a month ago.

    Listen, this is inconvenient, annoying, and unnecessary. I already stopped using Windows, and the inability to disable this is going to lead to me rejecting microsoft products in totality.

    "this is just your life now" is going to harm microsoft, not me.

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-12-19T22:59:22+00:00

    Just wanna say: Thank you for engaging honestly and openly.

    I think your last few paragraphs are likely describing the issue for a few more technical users, while SirBlain has better described the issue as it relates to the typical personal user of Microsoft's products.

    I don't think so. Nagging people to try things that aren't relevant to them at that moment, or at all, is just generally annoying. For anybody. Whether it's placing game advertisements on a Windows Professional install automatically, enabling keyboard shortcuts that make normal OS interactions impossible, or just popping up little speech and hint bubbles up all over the place, or being unable to find local files in favor of searching Bing, or associating Edge with literally 50 file types that all have to be changed with an extra warning independently, or any number of other silly things.

    Nobody appreciates any part of that.

    Why are they focusing on stuff like this instead of fixing the broken file indexer to power features like system-wide search, or provide a preview feature, or fixing the local backup solution, or reducing resource usage to leave more for our games and applications, or improving how applications scale with resolution if different displays have different display scalings, or unifying their settings apps? It's taken 10 years now and we're still not there.

    Basic OS functionality is left to rot. What are we doing here?

    However, what I don't think many other than people like those trying to aid others here understand is that the security issues caused by passwords have grown exponentially as new methods like passkeys and other 2FA methods are finally gaining popularity, resulting in a massive increase in 'last gasp' successful account thefts using passwords, especially of those like gaming accounts that are easily sold by organized criminal gangs.

    I don't know what kind of passwords people are using, but I want to note that I am now 34 years old and I have lost 1 account to theft. Ever.

    The problem really isn't as big as you think it is.

    Passwords are truly useless as 'security' now, since there are simply so many ways they can be captured or stolen, meaning they must be removed as soon as possible from all accounts, not just those belonging to less technically capable users. It's truly surprising how many people post that they knew better then to make the simple mistakes that resulted in losing their accounts, or getting scammed, or any of a number of different ways that criminal organizations have found to monetize the average home computer owner. And even here we're seeing the same issues happen to those using Google or Apple products, so Microsoft isn't the only one having to deal with this, simply the largest.

    Perhaps it might be an idea to stop allowing any application to read the clipboard at any time without a shortcut even while not the active window? Maybe it's time to stop allowing applications that don't have focus to read every keystroke?

    Or actively doing it on iOS until Apple has to step in? Or, perhaps, actually allowing users to register their own secret service as they can on both macOS and Linux? Then our passwords wouldn't be in our minds or our clipboards.

    Now I'm gonna get a bit harsh, but I really do laugh a bit being told that it's for security on Microsoft Windows systems.

    How can you possibly claim to be doing this for security when any app can capture any part of memory on the user's account at any time for any reason? You can attach yourself as a debugger to anything and read the memory of virtually any user space process and even modify their memory. Video game companies are making drivers that are bluescreening people in order to prevent you from attaching debuggers to particular processes.

    You can make background daemons and services that steal your passwords. You can modify important system files. The standard Windows executable format is still used and it isn't compatible with ANY granular security systems in Windows 11 at all. You either disable them for one or for all. Elevantion prompts never inform you abotu what the program intends to do. It's just a carte blanche yes/no.

    Do .exe files not have signatures or checksums? Yes, they do. Not inherently but almost all of them do or they'll warn you. Sure, have a fallback, but really...

    The other thing that most probably don't think about is that unless they're purchasing something from Microsoft other than the Windows that comes with a new device, there likely isn't much reason for Microsoft to care if they lose them as a customer, since last I read that copy of Windows typically nets them something around or possibly less than $50, while the true money is made from subscriptions to things like Microsoft 365 (e.g. Office), the added Cloud storage this includes or other products like games.

    Listening to you is why I personally suspect Microsoft would be fine with losing customers that don't truly want to use their products, since from their standpoint it's really the commercial users who also need their employees to have access from their home machines or those wanting Microsoft 365 themselves for either small business or personal use that are the customers they really want to retain.

    First and foremost, $50 per license would make them $12bln per year at 80% market share. That's not nothing. Windows may be dwindling by comparison now, but it's by far their biggest investments and legacy.

    Secondly, Microsoft earns no money from me storing my passkeys with them as opposed to other services. It literally is solely an expense. The reason for this is simply spaghetti. That's genuinely what I believe.

    I don't have a pathological dislike or disdain for Microsoft, and I don't have any reason to trust them any less than the other tech giants - though of course that invites comparison to companies like Google who release a "Do not track" flag in their browser and then proceeds to ignore them in their own ad network business. So... yeah.

    But really, I've used Skype (with a phone number!) and MSN Messenger and Office and I've played their video games like Halo and Age of Empires and MSFS and so on.

    I think Windows for ARM proves that it is not actually Microsoft that dominates - it's the WinTel cycle. Everybody's on Windows+x86 because all the apps are there and all the apps are there because everybody's there, see point one. It's a snowball that was created in the 9x days and it's still rolling. As long as backwards compatibility is reasonably maintained people will stay on the platform, and they pretty much ignore everything that's happened in the last 15 years, trying in various ways to "evade" the changes by just doing the same things they always did but slightly differently as buttons are moved around.

    Here's why it's important: If private customers get fed up and switch away from Windows, then they'll get annoyed at work too because they can't use their workflows from home, and then Microsoft's base will start eroding. But... as long as the WinTel machine keeps chugging along, it's going to take serious effort to chase people off. Being a bit annoying isn't gonna do it, and Microsoft is exploiting that fact to the hilt with implementations like this.

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments
  3. Rob Koch 26,160 Reputation points Volunteer Moderator
    2024-10-15T19:47:14+00:00

    Yes Jay, we still agree, just see different sides of the issue in certain cases.

    The Amazon issue you describe, though different than mine using Windows 10 and actually trying to use the Amazon passkey via first my Pixel 4a5g and then later a Pixel 8 upgrade early this year, resulted in an even worse set of experiences I'll briefly describe.

    Though it's supposed to be easy to use this cross-device passkey authentication as long as Bluetooth or a similar technology is enabled on both devices, I found this impossible with the initial 4a5g current with Android 14 at the time, and then flakey but basically functional with the Pixel 8 that shipped with Android 14.

    The problem with the Pixel 8 wasn't the device, but rather the flow and really just the decisions made by Amazon, since though I can't recall the specific issues I had setting up the passkey, the process seemed unnecessarily complex and didn't even make sense to me, so I'd expect the average consumer to simply be lost.

    The bigger issue for me at the tine though, was that Amazon apparently only saw the passkey as a password replacement and for some reason, not the full 2-Factor authentication process that it is, since it inherently requires both something you have (Private Key on local device), to be accessed using something you are (Biometric - Windows Hello Face in my case), or know (PIN) that's then presented to the website along with the public key during the challenge/response sequence that's part of the protocol.

    I described this process so you can see that passkeys are really already 2-Factor, so the requirement by Amazon at the time to also still require that I complete the authentication using the legacy TOTP interaction that they made available for 2FA a year or more ago, was simply pointless overhead. Since using the passkey via the smartphone also requires the added step of accepting the Biometric or PIN and I believe a second popup request after that's entered, this was already nearly as much work as the TOTP interaction but adding that legacy step was simply outright stupid.

    Thinking about your last description of the experience with the security key sounds just as stupid, so this is precisely what I was meaning when I said it's the inconsistent process, in this case including not treating either the security key or in fact the passkey sequence alone as 2-Factor that's really the problem. Amazon has stupidly decided to instead 'layer' these disparate means of 2-Factor on top of each other, creating a pointlessly excessive set of redundant sequences that as you mentioned, will only cause people NOT to use them even if they are actually more secure. I'll leave that portion of the subject here, since I think we now totally agree that it's Amazon's decisions regarding this process where the true problem lies in that case.

    I'll mention that I understand this is why those using security keys dislike the Windows dialog prompt as well, but in that case, I can see that Microsoft has a somewhat more complex set of potential issues to deal with, such as added users with Kiosk or other multi-user systems who may not use the same security key or similar device as another user of that same system. How to allow the branching logic required in order to support anyone who might use that system, while still streamlining this process for those who use it regularly, is really the problem. Though creating some sort of override that allows the device owner (Admin) to set this default, while still providing some sort of 'out' via a clickable link to allow temporary access to someone else might provide a solution.

    As for the TOTP portion of your response, I realized after my last post you might interpret it to mean killing off both that and other methods instantly, while in truth what I should have stated is that no future effort should go into legacy options like TOTP, assuming that the core issue of phishing these 'secrets' can't be resolved that is. The problem for most websites using these is that they have no way of knowing whether you're using a password manager or other secondary device unless there's some sort of layered software involved that the website interacts with, which as I understand it, some of these 3rd-party devices might actually have.

    My comment was focused on consumer accounts that in most cases won't be using such added devices, while the FIDO2 passkey system inherently requires some form of authenticator, as well as has varying degrees of ability defined for these, which both allows an authenticating website to confirm that the authenticator fulfills its specific requirements, as well as providing the ability to upgrade and future-proof the method. I suspect this requirement was created at the request of these 3rd-party authentication device manufacturers, precisely in order to allow those like a Password Manager feeding TOTP codes to be identified and approved by sites that support them.

    Rob

    Was this answer helpful?

    3 people found this answer helpful.
    0 comments No comments