Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
How the Oct. 7 attacks led to a multiyear destruction of Iran’s proxy militias

How the Oct. 7 attacks led to a multiyear destruction of Iran’s proxy militias

2 March 2026
‘This is Dubai’s ultimate nightmare’: Missile strikes rock safe-haven status of the Las Vegas of the East

‘This is Dubai’s ultimate nightmare’: Missile strikes rock safe-haven status of the Las Vegas of the East

2 March 2026
Trump’s action against Iran is yet another wobble for government debt, warns UBS

Trump’s action against Iran is yet another wobble for government debt, warns UBS

2 March 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » New Warning As Microsoft Confirms Password Deletion For 1 Billion Users
Innovation

New Warning As Microsoft Confirms Password Deletion For 1 Billion Users

Press RoomBy Press Room21 January 20256 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
New Warning As Microsoft Confirms Password Deletion For 1 Billion Users

“The password era is ending,” Microsoft has confirmed, warning its billion users that “bad actors know it, which is why they’re desperately accelerating password-related attacks while they still can.” And while the company “blocks 7,000 attacks on passwords per second… almost double from a year ago,” that’s not nearly enough. “Our ultimate goal.” it says, “is to remove passwords completely,”

Those billion passwords will be replaced with passkeys, which “offer an improved user experience by letting you sign in faster with your face, fingerprint, or PIN… They also aren’t susceptible to the same kinds of attacks as passwords. Plus, passkeys eliminate forgotten passwords and one-time codes and reduce support calls.”

But it’s not all smooth sailing. “Passkeys are the future of authentication, but widespread adoption faces challenges,” the UK government’s cybersecurity authority has just warned, outlining “significant bumps in the road ahead,” before Microsoft’s vision of a password-less future can become reality.

The use of passkeys seems to be binary — those who use them are likely to use them widely, while those that do not are yet to jump onboard at all. “In the two years since passkeys were announced and made available for consumer use, the FIDO Alliance says, “passkey awareness has risen by 50%… The majority of those familiar with passkeys are enabling the technology to sign in.”

The UK’s National Cyber Security Centre (NCSC) says “most cyber harms that affect citizens occur through abuse of legitimate credentials. That is, attackers have obtained the victim’s password somehow – whether by phishing or exploiting the fact the passwords are weak or have been reused… Passwords are just not a good way to authenticate users on the modern internet.”

But to go from where are today to ubiquitous deployment — enabling Microsoft and others to delete billions of basic, reused, crackable passwords — needs work. NCSC outlines ten critical issues holding back such mass adoption.

  1. “Inconsistent support and experiences: There are currently multiple ‘flavors’ of passkey available that providers and users need to understand… This complicates things for websites which want to offer effective passkey support but also want to know how the passkey is being handled by the user’s device
  2. Device loss scenarios: Users are largely unsure about the implications for their passkeys if they lose or break their device, as it seems their device holds the entire capability to authenticate. To trust passkeys as a replacement for the password, users need to be prepared and know what to do in the event of losing one – or all – of their devices.
  3. Migration issues: Passkeys are ‘long life’ because users can’t forget them or create one that is weak, so if they’re done well there should be no need to reset or update them. As a result, there’s an increased likelihood that at some point a user will want to move their passkeys to the Credential Manager of a different vendor or platform. This is currently challenging to do.
  4. Account recovery processes: For passkey-protected accounts, potential attackers are now more likely to focus on finding weaknesses in account recovery and reset requests – whether by email, phone or chat – and pivot to phishing for recovery keys. These processes need to be sufficiently hardened by providers to prevent trivial abuse by these attackers and to maintain the security benefits of using passkeys.
  5. Platform differences: Different platforms use different terms to describe the process of passkey logins, which can confuse users and put them off using passkeys. Vendors will need to work together and with the FIDO Alliance to agree on consistent, accessible language and avoid working in silos. This will help users have confidence in what they are using across their digital lives.
  6. Suitability for all scenarios: Using passkeys assumes that the user has exclusive, private access to an account or device for preparing and accessing the Credential Manager holding their passkeys. However, this is not always the case, such as in households where multiple people use the same phone
  7. Implementation complexity: It’s challenging to offer passkeys to users for services that currently use multiple domains for authentication (such as account.example.co.uk and account.example.com) and users might need multiple passkeys to sign in to what appears to be the same service.
  8. Inconsistent use: There’s no consensus on when passkeys should be used in a sign-in journey or how much assurance each ‘flavour’ of passkey provides. As a result, some websites choose to ask for a passkey and an additional factor, while others allow passkey-only sign-ins.
  9. Uncertainty around multi-factor status: Website owners and regulators haven’t yet reached a consensus on whether all ‘flavours’ of passkey count as ‘multi-factor’ (or equivalent) when the user is verified, typically with local-device biometrics or a PIN.
  10. Uncertainty around syncing and sharing: For critical and sensitive accounts where verifiable user identity is required, there’s uncertainty about whether passkeys which can be synced and shared are secure enough on their own.”

The good news is all of this is being worked, co-ordinated by FIDO and others and driven by technology providers and financial and other secure-by-design industries, all looking to finally end the scourge of all-too-easy attacks. “Achieving this vision,” NCSC says, “needs an intensified effort from all parties and greater collaboration to cohere the vision and prevent it fragmenting to the extent that users disengage.”

This is why Microsoft says it is moving slowly toward its goal, “understand[ing] where and when to invite users to enrol passkeys… We ran multiple user studies and tested every pixel in our nudge screen to answer the question, “What would motivate a user to stop what they’re doing and enrol a passkey?”

The challenge is that for passkeys to resolve the worsening threat landscape now being boosted by new AI-fueled attacks, this needs to go the whole way. “While enrolling passkeys is an important step,” Microsoft says, “it’s just the beginning. Even if we get our more than one billion users to enroll and use passkeys, if a user has both a passkey and a password, and both grant access to an account, the account is still at risk for phishing. Our ultimate goal is to remove passwords completely and have accounts that only support phishing-resistant credentials.”

2FA attack hacker password microsoft password attack microsoft warning msa attack passkey password hack windows warning
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

New Leak Signals Unprecedented Design Change

New Leak Signals Unprecedented Design Change

1 March 2026
Is Tourism A Tool Or A Threat?

Is Tourism A Tool Or A Threat?

1 March 2026
Trust In The AI Age

Trust In The AI Age

1 March 2026
LEGO Pikachu And Poke Ball (72152) Review: Lacking A Spark

LEGO Pikachu And Poke Ball (72152) Review: Lacking A Spark

1 March 2026
How The AI Boom Is Forcing A Clean Energy Reckoning

How The AI Boom Is Forcing A Clean Energy Reckoning

1 March 2026
MWC And The Race For Global Momentum

MWC And The Race For Global Momentum

1 March 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

Moltbook is the talk of Silicon Valley. But the furor is eerily reminiscent of a 2017 Facebook research experiment

6 February 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
The AI data center boom is creating a dire electrician shortage. That’s an opportunity for Gen Z

The AI data center boom is creating a dire electrician shortage. That’s an opportunity for Gen Z

2 March 20260 Views
Supreme Court limits Trump tariffs, but CFOs still face a volatile trade landscape

Supreme Court limits Trump tariffs, but CFOs still face a volatile trade landscape

2 March 20261 Views
Asian aviation stocks plunge as Iran war cancels flights over Middle Eastern airspace

Asian aviation stocks plunge as Iran war cancels flights over Middle Eastern airspace

2 March 20260 Views
Giannis Antetokounmpo’s partnership with a prediction market is the latest challenge for sports

Giannis Antetokounmpo’s partnership with a prediction market is the latest challenge for sports

2 March 20261 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
How the Oct. 7 attacks led to a multiyear destruction of Iran’s proxy militias

How the Oct. 7 attacks led to a multiyear destruction of Iran’s proxy militias

2 March 2026
‘This is Dubai’s ultimate nightmare’: Missile strikes rock safe-haven status of the Las Vegas of the East

‘This is Dubai’s ultimate nightmare’: Missile strikes rock safe-haven status of the Las Vegas of the East

2 March 2026
Trump’s action against Iran is yet another wobble for government debt, warns UBS

Trump’s action against Iran is yet another wobble for government debt, warns UBS

2 March 2026
Most Popular
Why Sequoia’s Alfred Lin isn’t worried about the SaaS-pocalypse

Why Sequoia’s Alfred Lin isn’t worried about the SaaS-pocalypse

2 March 20261 Views
The AI data center boom is creating a dire electrician shortage. That’s an opportunity for Gen Z

The AI data center boom is creating a dire electrician shortage. That’s an opportunity for Gen Z

2 March 20260 Views
Supreme Court limits Trump tariffs, but CFOs still face a volatile trade landscape

Supreme Court limits Trump tariffs, but CFOs still face a volatile trade landscape

2 March 20261 Views
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.