Microsoft makes new consumer accounts passwordless by default
From May 2025, new Microsoft accounts are created without a password at all and default to passkeys. Existing accounts keep their passwords. It is the largest default-passwordless move to date, across Windows, Microsoft 365, and Xbox sign-ins.
Microsoft announced on 1 May 2025 that new Microsoft accounts would be passwordless by default. A new account is never enrolled with a password at all and uses a passkey instead, across Windows, Microsoft 365, and Xbox sign-ins. Existing accounts are unaffected and keep their passwords.
Microsoft's own figures for the change: passkey sign-ins are roughly eight times faster than password plus MFA, and succeed about 98% of the time against roughly 32% for passwords. Treat vendor-reported success rates as directional, but the gap is large enough that the direction is not in doubt.
Why it matters
The significance is defaults, not technology. WebAuthn has been deployable for years, and adoption stalled because passwords remained the path of least resistance. A default that never creates a password removes the fallback that attackers rely on: there is no credential to phish, spray, or stuff.
For enterprises the read-across is direct. Consumers arriving at your service will increasingly expect passkey enrollment to be the normal path rather than an advanced option buried in security settings. If your passwordless rollout still treats passkeys as opt-in alongside a password of record, you are keeping the attackable credential while paying for the alternative. Our passkeys primer covers what changes operationally, particularly around recovery, which is where these programmes usually stall.
Related on Start with Identity
- BlogEntra ID makes passkeys the default, and retires SMS and voice in 2027
From September 2026 Entra ID auto-enables passkeys for users on SMS or voice. On 1 February 2027 those two methods stop working entirely, for every tenant, with
- BlogGoogle Workspace puts FIDO2 keys into the Windows login, days after Entra makes passkeys default
Google began rolling out FIDO2 security keys as a second factor at Windows sign-in for all Workspace customers on 13 July. Microsoft is making passkeys the defa
- BlogRSA brings passwordless authentication to Linux servers, closing its last password-only gap
RSA ID Plus now covers Linux servers, developer workstations, and critical infrastructure with FIDO-based passwordless sign-in, closing the gap where organizati
- RankingBest Passwordless CIAM Providers: Top 5 Platforms
The best passwordless CIAM providers in 2026: Stytch, Auth0, MojoAuth, Transmit Security, and Ping Identity. Ranked for passkeys, WebAuthn, magic links, and phi
- GuideConditional Access Policies: A Complete Implementation Guide for Microsoft Entra
Master Microsoft Entra conditional access with risk-based policies, device compliance rules, location-based restrictions, and real-world deployment patterns.
- Comparisoncrowdstrike-falcon-identity-vs-microsoft-defender-identity
Both bring identity threat detection and response (ITDR) to the directory layer, watching Active Directory and Entra ID for attacks like credential theft, later