Microsoft Makes Passkeys the Default: What Changed and How to Set One Up
Microsoft now sets passkeys as the default for all new accounts in 2026, enabling over 1.5 billion users to adopt secure, passwordless login methods using biometrics and device authentication.
Quick answer: A passkey is a passwordless login that uses a cryptographic key pair stored on your device and unlocked with a fingerprint, face or PIN. In May 2025 Microsoft announced that new Microsoft accounts would be passwordless by default. Passkeys resist phishing because they only work on the genuine website.
Key takeaways
- Passkeys replace passwords with a key pair. The private key stays on your device and is unlocked locally.
- They resist phishing because the browser only offers a passkey to the real domain it was created for.
- Microsoft announced in May 2025 that new accounts default to passwordless. Check Microsoft's documentation for the current status of existing accounts.
- Keep a recovery method and register more than one passkey.
- Admins should plan enrolment, device support and recovery before forcing change.
What is a passkey?
A passkey is a login credential built on the FIDO2 and WebAuthn standards. When you create one, your device generates a pair of keys. The public key is stored by the website. The private key stays on your device, protected by your screen lock, fingerprint or face. To sign in, the website sends a challenge, your device signs it after you unlock it, and the site checks the signature with the public key. No shared secret travels over the network, so there is nothing for a phishing page or a database breach to steal. The FIDO Alliance passkey overview explains the idea.
What did Microsoft announce?
In May 2025, Microsoft said that new Microsoft accounts would be passwordless by default, and that existing users could move to passkeys and other passwordless methods. Rollout details change over time, and the figure of "1.5 billion users" that circulated in headlines is not something this article can verify, so it is not repeated here. For the current state of any account type, read the guidance on Microsoft Learn.
Why are passkeys more secure than passwords?
- Phishing resistance: the browser binds a passkey to the domain. A lookalike site cannot trigger it.
- No reuse: every site gets its own key pair.
- No password database to steal: servers hold public keys, which are useless to an attacker.
- Built-in second factor: device possession plus a local unlock gives two factors in one step.
How do you set up a passkey on a Microsoft account?
- Sign in to your Microsoft account in a browser and open the security settings.
- Choose the option to add a new way to sign in or verify, and pick passkey.
- Approve the prompt on your device with your fingerprint, face or PIN.
- Repeat on a second device, or use a hardware security key, so you have a backup.
- Keep a recovery method up to date, such as a verified phone number or email.
Menu names change, so follow the on-screen wording rather than a fixed path.
What should organisations plan?
| Topic | Question to settle |
|---|---|
| Device support | Do all staff devices and browsers support passkeys? |
| Enrolment | How will users register, and who verifies identity for the first one? |
| Recovery | What happens when a phone is lost? Helpdesk fraud is a real risk. |
| Policy | Which accounts must use phishing-resistant methods first, such as admins? |
| Legacy apps | Which systems still need passwords and how are they protected meanwhile? |
Do passkeys have limitations?
Yes. Syncing passkeys through a platform account ties your security to that account. Moving between ecosystems is still clumsy. Shared accounts are awkward. Recovery processes can become the weak point. For these reasons security teams usually keep a fallback and protect it carefully.
Common mistakes
- Registering only one passkey, then losing the device.
- Keeping a weak password or SMS recovery on the account, which an attacker can use instead.
- Assuming passkeys fix everything. Malware on the device and stolen session cookies are still threats.
Next steps
For the Google side of the story, read whether Google passkeys are safe. To study identity and access in depth, see our Azure security technologies course, which covers Microsoft identity controls.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0