Start with Identity
← Blog
News

Microsoft makes new consumer accounts passwordless by default

From May 2025, new Microsoft accounts are created without a password at all and default to passkeys. Existing accounts keep their passwords. It is the largest default-passwordless move to date, across Windows, Microsoft 365, and Xbox sign-ins.

By SWI Community TeamJun 25, 2025Updated Jul 27, 2026

Microsoft announced on 1 May 2025 that new Microsoft accounts would be passwordless by default. A new account is never enrolled with a password at all and uses a passkey instead, across Windows, Microsoft 365, and Xbox sign-ins. Existing accounts are unaffected and keep their passwords.

Microsoft's own figures for the change: passkey sign-ins are roughly eight times faster than password plus MFA, and succeed about 98% of the time against roughly 32% for passwords. Treat vendor-reported success rates as directional, but the gap is large enough that the direction is not in doubt.

Why it matters

The significance is defaults, not technology. WebAuthn has been deployable for years, and adoption stalled because passwords remained the path of least resistance. A default that never creates a password removes the fallback that attackers rely on: there is no credential to phish, spray, or stuff.

For enterprises the read-across is direct. Consumers arriving at your service will increasingly expect passkey enrollment to be the normal path rather than an advanced option buried in security settings. If your passwordless rollout still treats passkeys as opt-in alongside a password of record, you are keeping the attackable credential while paying for the alternative. Our passkeys primer covers what changes operationally, particularly around recovery, which is where these programmes usually stall.

Source: Microsoft Security Blog: pushing passkeys forward

Independent analysis. No vendor sponsorship.