{"id":89518,"date":"2019-06-10T09:00:44","date_gmt":"2019-06-10T16:00:44","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\/?p=89518"},"modified":"2023-05-15T22:58:02","modified_gmt":"2023-05-16T05:58:02","slug":"advancing-windows-10-passwordless-platform","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/06\/10\/advancing-windows-10-passwordless-platform\/","title":{"rendered":"Advancing Windows 10 as a passwordless platform"},"content":{"rendered":"
Passwords can be frustrating, difficult to remember, and easily hacked or stolen. That\u2019s why our vision for Windows is one of a passwordless platform<\/strong>\u2014a world where users don\u2019t have to deal with the pains of a password.<\/p>\n With the release of Windows 10, version 1903<\/a>, we\u2019re bringing Windows 10 closer to delivering our passwordless user and security promises<\/a>, with new features that we\u2019re excited for you to try out:<\/p>\n <\/p>\n Figure 1. Passwordless Windows Hello sign-in to Windows 10.<\/em><\/p>\n A passwordless phone number Microsoft account is exactly what it sounds like\u2014a Microsoft account that can be created with just your phone number in mobile Office apps like Word, OneNote, or Outlook on your iOS or Android device. It unlocks all the benefits of a Microsoft account, and most importantly, it doesn\u2019t require a password.<\/p>\n <\/p>\n Figure 2. Creating a passwordless phone number Microsoft account for Word Mobile on an iOS device.<\/em><\/p>\n Now for the first time ever, you can go to Settings and add a passwordless phone number Microsoft account to your device and use the Microsoft Authenticator app, or an SMS code roundtrip, to sign in for the first time\u2014no password needed! This is enabled with an added web sign-in capability on the Windows lock screen. After that, Windows Hello is set up for an end-to-end passwordless experience.<\/p>\n <\/p>\n Figure 3. Adding a Microsoft account to Windows through the Settings app.<\/em><\/p>\n In addition to supporting passwordless phone number Microsoft account sign-in, the web sign-in capability can be used with any Microsoft account\u2014even if it\u2019s just a regular email account. You can try it out by adding a Microsoft account to Windows, signing in for the first time with the Microsoft Authenticator app (make sure it\u2019s already set up for your Microsoft account), and setting up Windows Hello face, fingerprint, or PIN for later sign-ins\u2014all without a password!<\/p>\n <\/p>\n Figure 4. First time Microsoft account sign-in to Windows with the Microsoft Authenticator app.<\/em><\/p>\n In November 2018, we announced<\/a> the ability to use Windows Hello and FIDO2 compliant Microsoft-compatible security keys for passwordless sign-in on the web with a Microsoft account. Additionally, the FIDO Alliance recently announced<\/a> that with Windows 10, version 1903, Windows Hello is a FIDO2 certified authenticator.<\/p>\n With this announcement, you can use Windows Hello or FIDO2 compliant Microsoft-compatible security keys<\/a> for sign-in to the web on Windows 10. This is available on Mozilla Firefox version 66 and above<\/a> and will soon be supported on Chromium-based browsers, including Microsoft Edge on Chromium<\/a>, when signing in to a Microsoft account and other websites supporting FIDO authentication.<\/p>\n <\/p>\n Figure 5. Using Windows Hello to sign in to a Microsoft account on Firefox.<\/em><\/p>\n To learn how to enable FIDO authentication, watch Enabling your application and services to use passwordless authentication<\/a> and read Windows Hello FIDO2 certification gets you closer to passwordless<\/a>.<\/p>\n We know that users occasionally forget their Windows Hello PIN, so we wanted to provide our Microsoft account users with a revamped \u201cI forgot my PIN\u201d experience above the Windows lock screen with the same look and feel as signing in on the web. Just like first time sign-in, you can use the Microsoft Authenticator app instead of a password to reset your PIN when signing in.<\/p>\n <\/p>\n Figure 6: Streamlined Windows Hello PIN recovery experience above lock.<\/em><\/p>\n While there\u2019s still a ways to go in our passwordless platform journey, we\u2019re excited for you to try these new features and let us know what you think. Comments, questions, and feedback are all welcome! You can reach out to us at pwdlessQA@microsoft.com or by posting in the Windows 10 Feedback Hub app.<\/p>\n","protected":false},"excerpt":{"rendered":" With the latest update, users can add passwordless phone number accounts to Windows, sign in for the first time with the Microsoft Authenticator app, and more.<\/p>\n","protected":false},"author":96,"featured_media":89525,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ep_exclude_from_search":false,"_classifai_error":"","footnotes":""},"content-type":[3662],"topic":[],"products":[],"threat-intelligence":[],"tags":[3822,3819],"coauthors":[2112],"class_list":["post-89518","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","content-type-news","tag-microsoft-security-insights","tag-windows"],"yoast_head":"\n\n
Adding a passwordless phone number Microsoft account to Windows<\/h3>\n
Passwordless sign-in to Windows for the first time with the Microsoft Authenticator app<\/h3>\n
Windows Hello certified as a FIDO2 authenticator for passwordless sign-in on the web<\/h3>\n
Streamlined Windows Hello PIN recovery above the lock screen<\/h3>\n
Let us know what you think<\/h3>\n