Microsoft Authenticator App to Remove Password Storage, Shifts to Passkeys by August 2025

Close-up of a young woman’s face with an overlaid glowing red grid pattern, illustrating facial recognition or facial mapping technology used for biometric identification or analysis.

Microsoft is implementing a major shift in its Authenticator app, transitioning away from traditional password storage to focus exclusively on passkeys, biometrics, and PINs for authentication purposes. The change, which takes effect August 1, 2025, represents a significant step in Microsoft’s broader strategy to eliminate passwords entirely by 2025.

The transition is occurring in multiple phases. In June 2025, Microsoft prevented users from adding or importing new passwords into the Authenticator app. Following this, in July 2025, the company disabled autofill functionality for stored passwords and payment methods. The final phase, scheduled for August 1, 2025, will see Microsoft permanently delete all remaining saved passwords from the Authenticator app.

The strategic shift comes in response to the growing prevalence of password-based attacks. Microsoft reports that consumer accounts face approximately 7,000 password-based attacks every second, including phishing attempts, credential stuffing, and password reuse exploits. Recent data from major security breaches involving 16 billion leaked credentials has further highlighted the vulnerabilities of traditional password systems.

As an alternative to traditional passwords, Microsoft is embracing passkeys, a modern authentication standard developed by the FIDO Alliance that has gained significant support from other major technology companies including Apple and Google. Passkeys use public-key cryptography to create unique digital credentials that are securely stored on users’ devices and can be accessed through biometric authentication methods such as fingerprint or facial recognition, or through device PINs.

The company has clarified that this change does not affect the Authenticator app’s two-factor authentication (2FA) capabilities or push notifications for Microsoft account logins, which will continue to function normally. The preservation of 2FA functionality is particularly important as organizations worldwide strengthen their authentication requirements.

Users currently using Microsoft Authenticator for password management are being advised to export their saved passwords and consider alternative solutions, such as dedicated password managers or Microsoft Edge’s password management features. The company has specifically highlighted Edge’s built-in password manager as a recommended alternative for users who wish to remain within the Microsoft ecosystem.

“Passkeys are a safer option compared with the risky password practices we use,” said Attila Tomaschek, CNET software senior writer and digital security expert. Tomaschek suggests that users requiring alternative password management solutions consider options such as 1Password or Bitwarden, both of which have recently enhanced their passkey support.

The process of setting up passkeys within the Authenticator app has been designed to be user-friendly, with the app providing guided prompts to assist users through the transition process. The approach supports Microsoft’s commitment to making passwordless authentication accessible to all users while maintaining robust security standards.

Sources: Audacy, CNET, CNET, The Independent