Microsoft Makes Passkeys the Default: What Changed and How to Set One Up

Microsoft now sets passkeys as the default for all new accounts in 2026, enabling over 1.5 billion users to adopt secure, passwordless login methods using biometrics and device authentication.

May 02, 2025 - 14:56
Updated: 4 days ago
109.5k
Microsoft Makes Passkeys the Default: What Changed and How to Set One Up

Quick answer: A passkey is a passwordless login that uses a cryptographic key pair stored on your device and unlocked with a fingerprint, face or PIN. In May 2025 Microsoft announced that new Microsoft accounts would be passwordless by default. Passkeys resist phishing because they only work on the genuine website.

Key takeaways

  • Passkeys replace passwords with a key pair. The private key stays on your device and is unlocked locally.
  • They resist phishing because the browser only offers a passkey to the real domain it was created for.
  • Microsoft announced in May 2025 that new accounts default to passwordless. Check Microsoft's documentation for the current status of existing accounts.
  • Keep a recovery method and register more than one passkey.
  • Admins should plan enrolment, device support and recovery before forcing change.

What is a passkey?

A passkey is a login credential built on the FIDO2 and WebAuthn standards. When you create one, your device generates a pair of keys. The public key is stored by the website. The private key stays on your device, protected by your screen lock, fingerprint or face. To sign in, the website sends a challenge, your device signs it after you unlock it, and the site checks the signature with the public key. No shared secret travels over the network, so there is nothing for a phishing page or a database breach to steal. The FIDO Alliance passkey overview explains the idea.

What did Microsoft announce?

In May 2025, Microsoft said that new Microsoft accounts would be passwordless by default, and that existing users could move to passkeys and other passwordless methods. Rollout details change over time, and the figure of "1.5 billion users" that circulated in headlines is not something this article can verify, so it is not repeated here. For the current state of any account type, read the guidance on Microsoft Learn.

Why are passkeys more secure than passwords?

  • Phishing resistance: the browser binds a passkey to the domain. A lookalike site cannot trigger it.
  • No reuse: every site gets its own key pair.
  • No password database to steal: servers hold public keys, which are useless to an attacker.
  • Built-in second factor: device possession plus a local unlock gives two factors in one step.

How do you set up a passkey on a Microsoft account?

  1. Sign in to your Microsoft account in a browser and open the security settings.
  2. Choose the option to add a new way to sign in or verify, and pick passkey.
  3. Approve the prompt on your device with your fingerprint, face or PIN.
  4. Repeat on a second device, or use a hardware security key, so you have a backup.
  5. Keep a recovery method up to date, such as a verified phone number or email.

Menu names change, so follow the on-screen wording rather than a fixed path.

What should organisations plan?

TopicQuestion to settle
Device supportDo all staff devices and browsers support passkeys?
EnrolmentHow will users register, and who verifies identity for the first one?
RecoveryWhat happens when a phone is lost? Helpdesk fraud is a real risk.
PolicyWhich accounts must use phishing-resistant methods first, such as admins?
Legacy appsWhich systems still need passwords and how are they protected meanwhile?

Do passkeys have limitations?

Yes. Syncing passkeys through a platform account ties your security to that account. Moving between ecosystems is still clumsy. Shared accounts are awkward. Recovery processes can become the weak point. For these reasons security teams usually keep a fallback and protect it carefully.

Common mistakes

  • Registering only one passkey, then losing the device.
  • Keeping a weak password or SMS recovery on the account, which an attacker can use instead.
  • Assuming passkeys fix everything. Malware on the device and stolen session cookies are still threats.

Next steps

For the Google side of the story, read whether Google passkeys are safe. To study identity and access in depth, see our Azure security technologies course, which covers Microsoft identity controls.

Related reading

Frequently Asked Questions

A passkey is a passwordless credential made of a key pair. The private key stays on your device and is unlocked with a fingerprint, face or PIN, and the website stores only the public key to verify your sign-in.

Microsoft announced in May 2025 that new Microsoft accounts would be passwordless by default. Rollout for existing accounts and enterprise tenants differs, so check Microsoft's documentation for the current position for your account type.

Yes for most threats. They resist phishing because they only work on the real domain, they are never reused and servers do not hold secrets worth stealing. They do not stop malware on a compromised device.

Use another registered passkey or a security key, or your recovery method, to sign in, then remove the lost device. That is why you should register at least two sign-in methods and keep recovery details current.

Yes. Many platforms sync passkeys across your devices through your account, and you can also register separate passkeys per device or use a hardware security key. Each website lists the passkeys you have added.

A passkey combines something you have (the device) with something you are or know (the unlock), so it acts as strong multi-factor sign-in by itself. Some services still ask for extra checks on risky logins.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.