London Daily

Focus on the big picture.
Friday, May 30, 2025

Microsoft's passwordless plans lets users switch to app-based login

Microsoft's passwordless plans lets users switch to app-based login

Microsoft has announced users can now delete all passwords from their accounts and instead login using an authenticator app or other solution.

The technology giant made passwordless accounts available for business users of its products in March.

And that system is now being made available to all Microsoft or Windows users.

It said "nearly 100% of our employees" were already using the new, more secure system for their corporate accounts.


If passwordless login is enabled, users re-logging in to a Microsoft account will be asked to give their fingerprint, or other secure unlock, on their mobile phone.

And this is far more secure than using passwords, which can be guessed or stolen, according to Microsoft.

"Only you can provide fingerprint authentication or provide the right response on your mobile at the right time," it said.

Windows users will still be able to use quick-login features such as a Pin code, though.

Some rare exceptions will still need passwords, such as Office 2010, Xbox 360 consoles, and Windows 8.1 or earlier machines.

And if access to the authenticator app is lost - for example, if the phone it is installed on is lost or stolen or a user forgets when upgrading - backup options can be used, including:

*  Windows Hello facial recognition, which requires a compatible laptop or special camera
*  a physical security key, which must be used on the device logging in
*  Short Message Service (SMS) or email codes

But SMS and email are two of the most common channels for cyber-criminals targeting specific individuals

And Microsoft says security-conscious users who have two-factor authentication set up will need to have access to two different recovery methods.

Microsoft's messaging tells customers no passwords are more secure

Prof Alan Woodward, part of a research team investigating passwordless authentication, at the University of Surrey, called it "quite a bold step from Microsoft".

"This isn't just logging into PCs, it's logging into online services as well" - including important ones such as cloud storage, he said.

Microsoft laid out its reasons for the new system in a series of blog posts.

Security vice-president Vasu Jakkal wrote: "Passwords are incredibly inconvenient to create, remember, and manage across all the accounts in our lives.

"We are expected to create complex and unique passwords, remember them, and change them frequently - but nobody likes doing that."

The separate authenticator app - not pictured in this stock photo - is claimed to be more secure than a password

Instead, people tended to create insecure passwords that technically cleared the bar for using symbols, numbers or case sensitivity - but in order to remember them, used a repeated formula or the same password on multiple websites.

And that led to hackers guessing them or revealing them in a data breach and reusing them.

"Hackers don't break in, they log in," the blog post read.

'Pummelled home'


The new passwordless feature greets users with a box saying: "A passwordless account reduces the risk of phishing and password attacks."

And once the feature is set up, a confirmation tells users: "You have increased the security of your account and improved your sign-in experience by removing your password".

Microsoft's claims about poor password use were largely true, Prof Woodward said.

"The message has been pummelled home about what good password hygiene looks like - but it's easier said than done," he said.

Passwords were a decades-old concept "and maybe the time is now right to start looking for something different".

But there were no currently agreed standards.

"There are a number of different ways this could be done - and it would be good if everybody moved on, really, and tried to find a way of doing this," Prof Woodward said.

Newsletter

Related Articles

0:00
0:00
Close
Satirical Sketch Sparks Political Spouse Feud in South Korea
Indonesia Quarry Collapse Leaves Multiple Dead and Missing
South Korean Election Video Pulled Amid Misogyny Outcry
Asian Economies Shift Away from US Dollar Amid Trade Tensions
Netflix Investigates Allegations of On-Set Mistreatment in K-Drama Production
US Defence Chief Reaffirms Strong Ties with Singapore Amid Regional Tensions
Vietnam Faces Strategic Dilemma Over China's Mekong River Projects
Malaysia's First AI Preacher Sparks Debate on Islamic Principles
White House Press Secretary Criticizes Harvard Funding, Advocates for Vocational Training
France to Implement Nationwide Smoking Ban in Outdoor Spaces Frequented by Children
Meta and Anduril Collaborate on AI-Driven Military Augmented Reality Systems
Russia's Fossil Fuel Revenues Approach €900 Billion Since Ukraine Invasion
U.S. Justice Department Reduces American Bar Association's Role in Judicial Nominations
U.S. Department of Energy Unveils 'Doudna' Supercomputer to Advance AI Research
U.S. SEC Dismisses Lawsuit Against Binance Amid Regulatory Shift
Alcohol Industry Faces Increased Scrutiny Amid Health Concerns
Italy Faces Population Decline Amid Youth Emigration
U.S. Goods Imports Plunge Nearly 20% Amid Tariff Disruptions
OpenAI Faces Competition from Cheaper AI Rivals
Foreign Tax Provision in U.S. Budget Bill Alarms Investors
Trump Accuses China of Violating Trade Agreement
Gerry Adams Wins Libel Case Against BBC
Russia Accuses Serbia of Supplying Arms to Ukraine
EU Central Bank Pushes to Replace US Dollar with Euro as World’s Main Currency
Chinese Woman Dies After Being Forced to Visit Bank Despite Critical Illness
President Trump Grants Full Pardons to Reality TV Stars Todd and Julie Chrisley
Texas Enacts App Store Accountability Act Mandating Age Verification
U.S. Health Secretary Ends Select COVID-19 Vaccine Recommendations
Vatican Calls for Sustainable Tourism in 2025 Message
Trump Warns Putin Is 'Playing with Fire' Amid Escalating Ukraine Conflict
India and Pakistan Engage Trump-Linked Lobbyists to Influence U.S. Policy
U.S. Halts New Student Visa Interviews Amid Enhanced Security Measures
Trump Administration Cancels $100 Million in Federal Contracts with Harvard
SpaceX Starship Test Flight Ends in Failure, Mars Mission Timeline Uncertain
King Charles Affirms Canadian Sovereignty Amid U.S. Statehood Pressure
Trump Threatens 25% Tariff on iPhones Amid Dispute with Apple CEO
Putin's Helicopter Reportedly Targeted by Ukrainian Drones
Liverpool Car Ramming Incident Leaves Multiple Injured
Australia Faces Immigration Debate Following Labor Party Victory
Iranian Revolutionary Guard Founder Warns Against Trusting Regime in Nuclear Talks
Macron Dismisses Viral Video of Wife's Gesture as Playful Banter
Cleveland Clinic Study Questions Effectiveness of Recent Flu Vaccine
Netanyahu Accuses Starmer of Siding with Hamas
Junior Doctors Threaten Strike Over 4% Pay Offer
Labour MPs Urge Chancellor to Tax Wealthy Over Cutting Welfare
Publication of UK Child Poverty Strategy Delayed Until Autumn
France Detains UK Fishing Vessel Amid Post-Brexit Tensions
Calls Grow to Resume Syrian Asylum Claims in UK
Nigel Farage Pledges to Reinstate Winter Fuel Payments
Boris and Carrie Johnson Welcome Daughter Poppy
×