{"id":90277,"date":"2019-12-11T16:00:56","date_gmt":"2019-12-12T00:00:56","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\/?p=90277"},"modified":"2023-05-15T23:02:35","modified_gmt":"2023-05-16T06:02:35","slug":"go-passwordless-strengthen-security-reduce-costs","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2019\/12\/11\/go-passwordless-strengthen-security-reduce-costs\/","title":{"rendered":"Go passwordless to strengthen security and reduce costs"},"content":{"rendered":"
We all know passwords are inherently unsecure. They\u2019re also expensive to manage. Users struggle to remember them. It\u2019s why we\u2019re so passionate about eliminating passwords entirely. Passwordless solutions, such as Windows Hello, FIDO2 security keys, and the Microsoft Authenticator app, provide more secure and convenient sign-in methods. But transitioning your organization to passwordless authentication takes time and careful planning. You may wonder where to start and how long it will take to realize benefits. Today, we examine:<\/p>\n
<\/a><\/p>\n Microsoft passwordless solutions include Windows Hello, the Microsoft Authenticator app, and FIDO2 security keys.<\/em><\/p>\n The goal of user authentication protocols, including passwords, is to verify user identity. But just because a user knows a password doesn\u2019t mean they are the person they claim to be. In fact, 81 percent of breaches leverage stolen or compromised passwords.1<\/sup> Passwords are not unique identifiers.<\/p>\n To improve security, we need a better way to uniquely identify users. This is where biometrics come in. Your iris, fingerprint, and face are unique to you\u2014nobody else has the same fingerprint, for example. Passwordless solutions, like Windows Hello, rely on biometrics instead of passwords because biometrics are better at accurately identifying a user.<\/p>\n Biometrics, like other personal identifying information (PII), may raise privacy concerns. Some people worry that technology companies will collect PII and make it available to other entities. Or that their biometric image might get stolen. That\u2019s why Microsoft and other security companies in the Fast IDentity Online (FIDO) Alliance developed the FIDO2 standard to raise the bar for securing credentials. Rest assured, Microsoft uses FIDO2-compliant technology that does NOT<\/strong> view, store, or transfer ANY<\/strong> biometric images.<\/p>\n Here\u2019s how it works:<\/p>\n Technologies like Windows Hello are secure, convenient, and safeguard user privacy.<\/p>\n <\/a><\/p>\n Users can sign in to Windows Hello with a fingerprint scan. The fingerprint image is turned into a unique identifier stored on the device. It does not get stored by Microsoft.<\/em><\/p>\n To help you think about the costs associated with passwords, we\u2019ll share some numbers from Microsoft\u2019s own experience rolling out passwordless to its users. After about a year since Microsoft began this journey, most users don\u2019t use a password to authenticate to corporate systems, resources, and applications. The company is better protected, but it has also reduced costs.<\/p>\n Passwords are expensive because users frequently forget them. For every password reset Microsoft incurs, soft costs are associated with the productivity lost while a user can\u2019t sign in. The company also incurs hard costs for every hour a Helpdesk administrator spends helping a Microsoft user reset their password.<\/p>\n Microsoft estimated the following costs before rolling out passwordless to its employees:<\/p>\n As of today, Microsoft has achieved the following benefits from its passwordless rollout:<\/p>\n Whether you\u2019re ready to roll out a passwordless authentication strategy today or in a few years, these steps will help get your organization ready.<\/p>\n <\/a><\/p>\n The Microsoft Authenticator app can be used to augment a password as a second factor or to replace a password with biometrics or a device PIN for authentication.<\/em><\/p>\n If you aren\u2019t ready to go passwordless, enable MFA to reduce your odds of a breach. We also recommend that you ban the most easily guessable passwords. Azure AD processes 60 billion authentications in a month and uses the telemetry to automatically block commonly used, weak, or compromised passwords for all Azure AD accounts, but you can add your own custom banned passwords, too.<\/p>\n Microsoft passwordless solutions include Windows Hello, the Microsoft Authenticator app, and FIDO2 security keys from select partners. Each can help you accomplish the following:<\/p>\n Read more about Microsoft passwordless solutions<\/a>.<\/p>\nBiometric technology improves security and safeguards user privacy<\/h3>\n
\n
Improve security, reduce costs, and increase productivity<\/h3>\n
\n
\n
Going passwordless starts with Multi-Factor Authentication<\/h3>\n
\n
Learn more<\/h3>\n
\n