2025-05-04
New Microsoft Accounts are Passwordless by Default
One year after year Microsoft began offering passkey support for consumer accounts, the company has announced that all new Microsoft accounts will be passwordless by default. The move is intended to protect customers' credentials from stuffing, brute force, and phishing attacks. Current Microsoft customers who have not yet adopted passkeys will be encouraged to do so when they sign into their accounts. Other companies, including Apple and Google, are also developing passkey support under the aegis of the Fast Identity Online (FIDO) Alliance.
Editor's Note
The good news is you will be using passkeys with your Microsoft account and you can start setting passkeys on your Microsoft accounts today, and they will default to the strongest authentication option available. The bad news is you have to use Microsoft Authenticator, as Google Authenticator, Authy and similar apps are incompatible with their system, if you want to ditch your reusable password, which we should do, so authentication can't fall back to this option.

Lee Neely
We need more moves to strong authentication as default by the big consumer IT vendors and platforms. That does not eliminate all risk, but it raises the bar tremendously and allows IT security resources to focus on the remaining risk paths.

John Pescatore
Passkeys by default for new users is actually easier than transitioning existing users, and is a good practice.

William Hugh Murray
MSFT slowly but surely pushing the industry forward to see the end of passwords. I mean we've only been talking about the end of passwords for a decade or more. The tie-in with the FIDO WebAuthn standard is a plus if they don't force users to install their authenticator.

Curtis Dukes
Let's go passwordless. This does not mean you are always safe. It's just that we should make it harder!

Moses Frost
Read more in
Ars Technica: Microsoft’s new ‘passwordless by default’ is great but comes at a cost
The Register: Microsoft tries to knife passwords once and for all - at least for consumers
SecurityWeek: Microsoft Accounts Go Passwordless by Default
Help Net Security: New Microsoft accounts will be ‘passwordless by default’
The Hacker News: Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support
Bleeping Computer: Microsoft makes all new accounts passwordless by default
Microsoft: Pushing passkeys forward: Microsoft’s latest updates for simpler, safer sign-ins