Why am I being asked for a Passkey? How do I turn off passkeys?

Anonymous
2024-07-22T21:51:35+00:00

I was opted into this without my knowledge, or without understanding how it works.

I have a solid understanding of Windows, and the security around it. But I do not understand why I suddenly am being forced to use, and constantly asked about passkeys, when I have not opted into them or set them up.

If I don't understand why I am being forced to use these, or why they are required, none of the less savvy users will. This will likely result in Microsoft spending more on tech support due to people being locked out of their devices.

Scenario: I have deleted the passkeys from my settings, and now my Edge logins have a discrepancy, because they are demanding passkeys that no longer exist.

For some reason, Windows is not allowing me to delete my Microsoft Passkey, because now that is required to sign in to my computer. I already have a PIN, a password, a fingerprint, and my face to sign in to my computer.

Is the only option logging out of my Microsoft Account and making it a local account to opt out of passkeys?

Passkeys need to be explained better if they are going to be a requirement, it needs to be a more gentle introduction.

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Rob Koch 26,055 Reputation points Volunteer Moderator
2024-07-23T03:59:03+00:00

You've been using a passkey to login to Windows since you enabled Windows Hello to perform Face, Fingerprint or PIN login methods, since they' re an integral part of that system. They simply weren't as visible in the past, since the Passkey Management and using them for 3rd-party apps or websites weren't yet supported.

As usual, the problem is there are many documents available covering these and some confusing differences between the Azure Business-based systems using something called Entra for authentication and the consumer version of these related to your Microsoft Personal account. I'll include documents from both here in case you are more technically interested but tell you which I'm providing.

The first is an overview for consumer accounts and should help you understand how crucial they are to Microsoft's future authentication systems intended to remove the need for passwords, so trying to escae them is utterly pointless.

New passkey support for Microsoft consumer accounts | Microsoft Security Blog

This next one has more technical detail and in the first sections describes in general how they work, while a later section is specific to the Microsoft implementation and shows how these functions relate to Windows Hello, the Edge browser and other similar portions of Windows. I wouldn't typically provide this to the average consumer, but it really makes their operation on Windows clear for those wanting to understand them more deeply.

WebAuthn APIs - Windows Security | Microsoft Learn

I think I'll stop there for the moment to make sure you want more iformation, since upon quick review, these two documents cover the basics, while there are many others that provide the How-to explanations for individual portions of passkey operation.

Rob

< EDIT > BTW, here's a FAQ document with some common questions about passkeys, the last of which is titled; How can I provide feedback about my experience with passkeys?

Passkeys frequently asked questions (FAQ) - Microsoft Support

If you click the question to view the answer, you'll find a link to the Windows Feedback where you can submit your comments directly to Microsoft. Anything you post in this forum will only be seen by those who browse here, while virtually no Microsoft employees ever do and so your posts here are only really seen by us volunteer or a few contract helpers.

Was this answer helpful?

10+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
quietman7 MVP Alumni 19,820 Reputation points Volunteer Moderator
2025-06-22T21:08:03+00:00

I appreciate your response. If a password and the multi-authentication code is not sufficient, what does a 'passkey' do?

Why doesn't Microsoft provide some easy-to-understand explanation of what a 'passkey' is and why it is different for every site?

I provided that information in a previous reply (page 11) but here are those and some more links by Microsoft with explanations.

Passkeys Authentication Across Platforms - How Passkeys Registration and Authentication Work Across Devices and Platforms

Quote

To combat such risks, phishing-resistant Passwordless authentication methods, including enhanced support for Microsoft Authenticator, have become critical.

Just for the record...Microsoft has long been a proponent of passwordless authentication for years so this is nothing new. Other industries have been moving in that direction too. .

In a nutshell...Passkeys are stored as secrets locally on a device and use a device's unlock mechanism such as Windows Hello biometrics (fingerprint or facial recognition) or PIN sign-In options to authenticate them before signing in. Passkeys can be used without the need for other sign-in challenges, making the authentication process faster and more convenient. A passkey is invisible, virtual and employ public-key cryptography (keypair concept: a private key and a public key). The passkey is purposely hidden from access inside the TPM (Trusted Platform Module).
 
TPM chip is an embedded crypto-processor in laptops and is designed to provide hardware-based, security-related functions (carry out cryptographic operations. The TPM is isolated from the main processor and functions as a vault (a lockbox for keys) so in the event of malware attack or breach, sensitive user data remains secure.

Was this answer helpful?

2 people found this answer helpful.
0 comments No comments

129 additional answers

Sort by: Most helpful
  1. Anonymous
    2024-10-03T17:25:20+00:00

    It's infuriating to be forced into programs like this. I was totally blindsided with a pop-up that forced me to create a passkey before I could use my computer, then forced it to be my login method. I'd had a local account set up and was so confused about what just happened.

    SirBlain, if you want to get around the passkey this is the solution I used: Settings > Accounts > Your Info. There under "Account Settings" choose "Sign in with a local account instead".

    In my case, I want no sign-in. So, I went to Netplwiz to set it to allow a sign in without a password. In my case, I had to create a NEW local account, which meant I had to toggle the password requirement on and back off again so it would prompt me for my new local account password.

    Microsoft: I don't want to have to login to my home desktop PC - I'm the only one with access to it! Stop forcing me into it and tell me what's going on when changes like this happen!

    Was this answer helpful?

    100+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-10-13T18:36:47+00:00

    To those who respond "passkeys are more secure" "get with the change", you are not quite correct.

    For users who refuse strong 2FA/MFA and for whom passkeys replace simple, repeated, passwords-only, yes, IF passkeys are easier for them to use than other, stronger authentication mechanisms, then "drink the Kool-Aid" might be good advice.

    But for those of us who already use much stronger 2FA/MFA mechanisms such a FIDO2 USB keys, push-MFA, or even old fashioned Google Authenticator-style TOTP 2FA (along with a very strong, unique password) PASSKEYS AS THE INDUSTRY IS PUSHING THEM ARE *WEAKER* because they make all security only as weak as the security of the user's end-user device (a Windows system or a mobile phone).

    To Microsoft, Google, etc: as the original poster requests, give us a way to disable passkeys of the "Hi, thanks for logging in to your Amazon account with truly strong MFA! Now GIVE US A WEAKER PASSKEY! GIVE! POP-UP! INTERFERE! PROMPT! NAG!" sort.

    PLEASE!

    Was this answer helpful?

    100+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2024-10-14T01:37:04+00:00

    Rob wrote:

    Jay,

    You're partially correct in that truly more secure methods like certain FIDO2 USB keys do exist, and in fact are considered more secure by Microsoft itself, but at the moment the problem is the plethora of possible methods potentially causing confusion for everyone, especially the less technically knowledgeable consumer users that Microsoft must inherently be more concerned about. Eventually the confusing and inconsistent interfaces will become more consistent and polished, removing these sorts of issues for everyone, but as always that takes more time than we typically expect.

    Confusing, friction-adding security interfaces have always been the bane of getting users to adopt security.

    The current implementation is fatally flawed.

    Rob continues:

    It's the methods of interaction that these require causing the interface problems at present, since the fact that an individual using a PC may have either a FIDO2 USB, smartphone-based authenticator, or even neither of these at all that leads to the need to display all of these options, regardless of whether the primary user of the machine only uses one of these methods.

    The problem with the current implementation is not "... the need to display all of those options".

    The problem with the current implementation is the way in which those options are presented to the user.

    The primary way these 'options' are presently presented to the user is a pop-up that interferes with the user's experience:

    * this pop up occurs _after_ the user has _already successfully strongly authenticated_ urging the user to adopt something that is not appropriate for their needs. or,

    * this pop up occurs during an authentication for which a passkey is not an option that the user has yet configured, requiring the user to take two steps: the non-obvious 'cancel' followed by 'try some other way', before the user sees the valid-for-his-current-authentication-process option "code generator".

    Rob asserts:

    However, both the push notifications and legacy TOTP code methods have already shown their age, having basically the same exact phishing and/or interception issues that passwords have always had as well, leading to attackers creating multiple methods recently that have tricked even relatively knowledgeable people like gamers. We've seen these mentioned here many times here, where, for example, fake Discord servers have been set up to entice gamers to join by entering their Microsoft credentials and then prompting them for the associated push notification response, which the attackers' scripts are using to autofill their account theft process in the background.

    So, though I understand what you're saying, just as I do for those arguing for extremely long and complex passwords in threads here as well, these inherent flaws in this logic have grown exponentially of late, with any weakness these methods might have being exploited by attackers at an increasing rate.

    This is incorrect. The combination of any modern fairly strong 2nd factor (even legacy TOTP) with a password manager (e.g. LastPass, 1Password, etc) which validates the origin of the authentication request before offering matching entries from the user's password vault, is sufficiently strong. You may be able to phish my human eyes with a homograph attack (as discussed here https://www.xudongz.com/blog/2017/idn-phishing/ ) with an "apple.com" example at https://www.xn--80ak6aa92e.com - although I note that Chrome itself now warns about this before showing the user a webpage with a URL bar that _looks_ like apple.com .. but isn't ... BUT the password manager will not be fooled.

    So, no, I do NOT have to you use broken user experience of passkeys in order to be protected.

    I've been in security for about thirty five years. "We know better, we'll shove it down your throat, despite that we haven't got the user experience even remotely acceptable as yet" is not the right way to improve security. It provokes backlash and resistance.

    Was this answer helpful?

    90+ people found this answer helpful.
    0 comments No comments