Instead of typing a reusable password, a user can sign in to a supported app or website with a passkey using a face, fingerprint, or PIN . Some coverage describes passkeys as WebAuthn-based credentials that use public-private key cryptography, with the private key stored on the user’s device
.
Depending on the device and service, Microsoft’s passwordless options can include passkeys, Windows Hello-style biometric or PIN sign-in, the Microsoft Authenticator app, and physical security keys .
The announcement does not mean every existing Microsoft account immediately loses password sign-in. Microsoft and related coverage frame the default change around brand-new or newly created Microsoft accounts .
Existing users can still move in the same direction. Microsoft says users can visit account settings to delete their password, and the company is encouraging broader adoption of passkeys where supported .
The main caveat is compatibility. Microsoft describes passkeys as a sign-in method for supported apps and websites, so users should make sure they have reliable passkey access and recovery options before removing an existing password .
Microsoft’s security argument is that passwords are a common weak point. The company’s announcement was framed around reducing password-based attacks such as phishing, brute-force attacks, and credential stuffing .
Passkeys are designed to be phishing-resistant because they replace the shared password model with device-based authentication on supported services . Microsoft is also pitching the change as easier for users: RCPmag reported Microsoft’s claim that passkey sign-ins succeed about 98% of the time, compared with about 32% for password sign-ins
.
For new Microsoft accounts, expect the sign-up process to steer you toward passwordless sign-in first. For existing accounts, the change is more of an invitation than an automatic lockout: add a passkey, confirm your recovery methods, and only then consider deleting the password from account settings .