World Passkey Day: Advancing passwordless authentication

World Passkey Day: Advancing passwordless authentication


World Passkey Day is an opportunity to replicate on progress towards a shared aim: lowering our reliance on passwords and different phishable authentication strategies by accelerating passkey adoption. As cyberattacks turn into extra automated and AI-powered, every account is just as safe as its weakest credential. Real progress requires greater than including stronger sign-in choices—it requires eradicating phishable credentials and strengthening widespread assault paths like restoration flows. In partnership with the FIDO Alliance, Microsoft is committed to advancing passkey adoption by means of ongoing requirements work, lively participation in working teams, and different contributions to a passwordless future.

Passwords stay a significant supply of danger; they’re tough to handle and straightforward to steal. Along with weaker types of multifactor authentication, they’re additionally extremely weak to phishing: AI-powered campaigns drive click-through charges as excessive as 54%.1 In response, Microsoft is increasing passkey adoption throughout our ecosystem. We’re lowering reliance on legacy authentication and strengthening account restoration so it will not turn into a backdoor for cyberattackers.

“Instead of vulnerable secrets or potentially identifiable personal information, a passkey uses a private key stored safely on the user’s device. It only works on the website or app for which the user created it, and only if that same user unlocks it with their biometrics or PIN. This means passkey users can’t be tricked into signing in to a malicious lookalike website, and a passkey is unusable unless the user is present and consenting. These are some qualities that make passkeys a ‘phishing-resistant’ form of authentication.”

From Microsoft Digital Defense Report.

Passkey adoption continues to develop trade huge

Passkey adoption is accelerating: FIDO Alliance estimates 5 billion passkeys already in use worldwide.2 Across Microsoft’s shopper providers, together with OneDrive, Xbox, and Copilot, a whole lot of thousands and thousands of customers sign up with passkeys day-after-day.

There are many causes to decide on passkeys as the usual authentication technique over passwords. Sign-in success charges are considerably larger than with passwords, and publicity to credential-based assaults is considerably decrease.3 Organizations and particular person customers alike favor the less complicated, safer sign-in expertise passkeys supply.4

Inside Microsoft, we have eradicated weaker authentication strategies and rolled out phishing-resistant authentication, overlaying 99.6% of customers and units in the environment.5 It’s made signing in loads less complicated: no codes to enter, no additional prompts to handle, only a easy expertise for everybody.

Product updates throughout sign-in and restoration

Across Microsoft, we have been steadily constructing passkey help into each layer of the identification expertise from shopper accounts to enterprise entry with Microsoft Sign inand from device-based authentication like Windows Hello to Microsoft’s password manager. This work ensures individuals can create and use passkeys wherever they sign up, with a constant, phishing-resistant expertise throughout units, apps, and environments.

To make passkeys extra accessible, we’re increasing the place and the way individuals can use them:

  • Synced passkeys and passkey profiles in Microsoft Entra ID make it simpler to scale passwordless sign-in throughout numerous environments. We’re increasing flexibility in cloud passkey administration, together with help for bigger and extra complicated insurance policies, and transitioning tenants to a unified passkey profile mannequin.
  • Enter passkeys on Windows make it easy for customers to create and use device-bound passkeys immediately on private or unmanaged Windows units utilizing Windows Hello, and shall be typically out there in late May 2026.
  • Passkeys for Microsoft Enter External ID shall be typically out there late May 2026, so your customer-facing purposes can supply a extra seamless, consumer-grade sign-in expertise.
  • Passkey-preferred authentication in Microsoft Login ID (preview) detects registered strategies and prompts the strongest one first. If a passkey is registered, that is what the consumer sees—instantly.
  • On the patron facet, with Microsoft Password Manager, customers can now save and sync passkeys throughout units signed in with their Microsoft account, with help for iOS and Android rolling out quickly by means of Microsoft Edge.

Account restoration additionally performs a essential function in sustaining the integrity of identification techniques. Historically, it has been weak to cyberattackers who attempt to hijack the restoration course of, for instance by impersonating reputable customers and requesting new credentials.

Microsoft Entra ID account recoverytypically out there at this time, strengthens safety for restoration flows by enabling customers to regain entry to their accounts by means of a sturdy identification verification course of. Users can regain entry after dropping all authentication strategies by utilizing government-issued ID and biometric face checks. At basic availability, we’re increasing our identity verification ecosystem with two new companions—1Kosmos and CLEAR1—becoming a member of our current companions Au10tix, IDEMIA, and TrueCredential.

Removing phishable credentials from consumer accounts

Strengthening authentication is necessary, however lowering danger means eliminating phishable credentials totally. Microsoft is continuous to section out legacy strategies and transfer customers towards phishing-resistant authentication. Starting in January 2027, security questions will be removed as a password reset option in Microsoft Entra ID on account of their susceptibility to guessing and social engineering.

The rationale is easy: enhancing sturdy strategies whereas eradicating weak ones shrinks the assault floor. This is more and more pressing as AI brokers act on behalf of customers. If an identification is compromised, cyberattackers can leverage these brokers to entry techniques, execute workflows, and function inside current permissions. Organizations want to handle this danger shortly.

A safer and usable future

Last yr, Microsoft joined dozens of organizations in taking the Passkey Pledge, a dedication to accelerating the adoption of phishing-resistant authentication and to transferring past passwords. Since then, we have seen significant progress, from a whole lot of thousands and thousands of better-protected shopper accounts to large-scale deployments throughout organizations like our personal.

What as soon as felt like a long-term shift is lastly gaining actual momentum: authentication is turning into less complicated, safer, and passwordless.

For a extra in-depth perspective on how cyberattackers attempt to bypass authentication by means of fallback strategies and restoration flows—and the right way to deal with these gaps—read our companion post.

Getting began

Organizations that need to strengthen their identification safety posture can allow passkeys for his or her customers and prolong coverage protections throughout each sign-in and restoration eventualities.

Get began with a phishing-resistant passwordless authentication deployment in Microsoft Enter ID.

Individuals can create and use passkeys for his or her private accounts for higher safety and comfort.

To be taught extra about Microsoft Security options, go to our website. Bookmark the security blog to maintain up with our professional protection on safety issues. Also, observe us on LinkedIn (Microsoft Security) and@MSFTSecurity) for the most recent information and updates on cybersecurity.


1Microsoft Digital Defense Report 2025.

2FIDO Alliance reports mainstream global usage on World Passkey Day. FIDO Alliance, 2026.

3Synced passkeys and high assurance account recoveryMicrosoft Enter weblog. December 16, 2025.

4FIDO Alliance Champions Widespread Passkey Adoption and a Passwordless Future on World Passkey Day 2025FIDO News Center. May 1, 2025.

5Microsoft Security and Future Initiative (SFI) Progress Report—November 2025.

Leave a Reply

Your email address will not be published. Required fields are marked *