Traditional Passwords Are No Longer Secure: Microsoft Calls for a Full Transition to Passkeys
5 hour ago / Read about 0 minute
Author:小编   

As the first Thursday of May, 'World Password Day,' approaches, Microsoft has issued a security initiative, urging users and businesses to accelerate the shift from traditional passwords to passkey authentication to combat cybersecurity threats. Microsoft points out that with the advancement of new attack methods such as AI, traditional passwords are increasingly vulnerable to risks like credential leakage and phishing attacks. Passkeys rely on local verification methods such as fingerprints, facial recognition, and device PINs, offering higher security. They effectively resist phishing attacks, prevent information theft, and provide simpler operation and faster login. As a key proponent, Microsoft has fully implemented passwordless transformations across its products and services. Newly registered Microsoft accounts enable passwordless mode by default, supporting login methods such as passkeys, biometrics, and security keys. Existing users can also manually remove their account passwords. Windows 11 has enhanced its passkey integration capabilities, ensuring compatibility with mainstream third-party password managers. The Edge browser supports syncing passkeys to mobile devices such as iOS and Android, enabling cross-platform usage scenarios. Currently, the widespread adoption of passkeys has become a consensus in the global tech industry, with FIDO Alliance data showing that 5 billion passkeys are already in use worldwide. Microsoft reveals that hundreds of millions of users have already adopted passkeys in consumer services like OneDrive and Xbox, with enterprise and internal systems also fully covered. Anti-phishing authentication covers 99.6% of users and devices, significantly simplifying the login process. To further strengthen account security, Microsoft announces that starting from January 2027, Microsoft Entra ID will no longer support password resets via security questions, preventing attackers from obtaining account recovery information through phishing methods.