• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft sets passkeys default for new accounts; 15 billion users

Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support

You are here: Home / General Cyber Security News / Microsoft Sets Passkeys Default for New Accounts; 15 Billion Users Gain Passwordless Support
May 2, 2025

A year after Microsoft announced passkeys support for consumer accounts, the tech giant has announced a big change that pushes individuals signing up for new accounts to use the phishing-resistant authentication method by default.

“Brand new Microsoft accounts will now be ‘passwordless by default,'” Microsoft’s Joy Chik and Vasu Jakkal said. “New users will have several passwordless options for signing into their account and they’ll never need to enroll a password. Existing users can visit their account settings to delete their password.”

The Windows maker said it has also simplified the sign-in and sign-up user experience by prioritizing passwordless methods. Furthermore, the sign-in process now automatically detects the best available method on a user’s account and sets that as the default.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

For example, if an account has the option to sign in via a password and a “one time code,” the user will be prompted to login via one time code instead of the password. Once signed in, they will then be instructed to set up a passkey for optimal protection.

The latest move by Microsoft, along with its peers Apple, Google, Amazon, and others in recent years, represents a steady march toward a passwordless future. With password-based cyber-attacks continuing to be a lucrative initial access vector for bad actors, the adoption of passkeys heralds an important step for account security.

In September 2023, Microsoft rolled out support for passkeys in Windows 11, around the same time when Google made passkeys its default login method for all users globally. Then last year, it updated Windows Hello to support the technology.

Passkeys offer a more secure way of logging in to websites and applications by eliminating the need for passwords. Backed by the Fast Identity Online (FIDO) Alliance, passkeys rely on public/private key cryptography techniques to authenticate users.

Thus when a user registers with an online service, their client device (i.e., phone or PC) generates a new key pair. The private key is stored securely on the user’s device, while the public key is registered with the service.

During sign in, the client device uses the private key to sign a challenge after the device owner authenticates it using their biometric information (e.g., facial recognition or fingerprint).

Cybersecurity

In October 2024, the FIDO Alliance said it’s working with stakeholders to make passkeys and other credentials more easier to export across different providers and improve credential provider interoperability. More than 15 billion user accounts can sign in using passkeys instead of passwords as of December last year.

The open industry association, last month, also launched a Payments Working Group (PWG) to define and drive FIDO solutions for payment use cases.

The PWG is expected to “identify and evaluate existing and emerging solutions to address payment authentication requirement” and establish “guidelines for use of passkeys and/or proposed FIDO solutions along with existing payment technologies.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «fake security plugin on wordpress enables remote admin access for Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers
Next Post: MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks mintsloader drops ghostweaver via phishing, clickfix — uses dga, tls»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.