WHEN BY DEFAULT ISN’T REALLY BY DEFAULT

Microsoft Advances Passwordless Logins but Requires Its Own Authenticator App
Photo: Ars Technica

Microsoft Advances Passwordless Logins but Requires Its Own Authenticator App

Microsoft has announced that new user accounts will default to passwordless logins through passkeys, a move in line with broader industry efforts to eliminate traditional passwords. This initiative, developed in partnership with the FIDO Alliance, aims to improve security by replacing passwords with cryptographic keypairs that are more resistant to phishing and credential theft. However, there’s a significant limitation: users must install Microsoft’s own Authenticator app to fully go passwordless. While passkeys can be created and used with various devices and platforms, Microsoft disables full passwordless functionality if users rely on third-party authenticators like Google Authenticator or Authy. This caveat undermines the company’s marketing of the system as truly ‘passwordless by default.’ Passkeys work by generating a public/private keypair bound to a user’s device and a specific service URL, making them immune to password reuse and phishing. But unless the user adopts Microsoft’s specific app, passwords remain in place on the account, reducing the full potential of the security improvements. Critics argue that this requirement adds unnecessary friction and creates a barrier to adoption, especially given the promise of cross-platform ease touted by the FIDO Alliance. While the technology shows promise, the current implementation has room for improvement in terms of usability and true interoperability.

Leave a Reply

Your email address will not be published. Required fields are marked *