Now, users will authenticate using device PINs or biometrics as the tech giant prevents over 7,000 password attacks every second, which is nearly twice as much as in 2023.
Microsoft declared today that all new accounts will be set to passkeys by default rather than traditional passwords, marking a significant step toward a passwordless future. The move, which takes effect immediately, is the result of a ten-year effort to modernize digital authentication techniques for billions of people globally.
Passwords will no longer need to be created or remembered since users creating new Microsoft accounts will now authenticate using biometric alternatives like fingerprint scans, facial recognition, or device PINs. To use these alternative techniques, current account holders can change their passwords in the account settings.
The Need For Security
Microsoft’s change coincides with an increase in online attacks. The organization now stops about 7,000 password attacks every second, which is roughly twice as much as it did in 2023.
“As passkeys become the new standard, expect increased pressure from cyberattackers on any accounts still protected by passwords or other phishable sign-in methods,” Microsoft stated in its news release.
Recent studies have clearly shown how vulnerable standard passwords are. Even strong password rules have not been enough to fend off contemporary dangers, according to a study that examined over one billion credentials that were taken by infostealer malware in a 12-month period.
The Operation Of Passkeys
In contrast to passwords, passkeys generate credentials that are kept on users’ devices using public-key cryptography. Users only need to use a PIN or integrated biometrics to confirm their identity when logging in.
“Passkeys cannot be guessed, reused, or exposed in data breaches,” according to security company Secfense. Because the secret authentication key never leaves the user’s device, it is impervious to credential theft and phishing efforts.
Prior to the formal default change, Microsoft estimates that more than 99% of users who sign into Windows devices with Microsoft accounts already use passwordless ways, demonstrating the widespread use of these options.
Increasing Industry Momentum
The FIDO Alliance, an industry group advocating for more robust authentication standards, sponsored the first World Passkey Day, which falls on the same day as Microsoft’s announcement.
According to a recent FIDO Alliance poll, 35% of respondents said they had at least one account hack in the previous 12 months as a result of a weak password. 54% of customers who are familiar with passkeys think they are more practical than passwords, and 53% think they provide better protection.
Promising outcomes have been claimed by early adopters, such as a 70% boost in conversion rates at password manager Dashlane, a 98% decrease in mobile account takeover fraud at CVS Health, and a 12-fold speedup in login times for users of the Japanese train firm Tokyu.
With 84% of customers now familiar with passkeys, the FIDO Alliance observes that “Once users experience the convenience of a frictionless login, they are more likely to embrace or even expect it elsewhere.”

