Skip to main content

Microsoft rolls out passwordless login for all Microsoft accounts


 

Microsoft is rolling out passwordless login support over the coming weeks, allowing customers to sign in to Microsoft accounts without using a password.

The company first allowed commercial customers to rollout passwordless authentication in their environments in March after a breakthrough year in 2020 when Microsoft reported that over 150 million users were logging into their Azure Active Directory and Microsoft accounts without using a password.

Rolling out to all Microsoft accounts


Starting today, Redmond announced that users are no longer required to have a password on their accounts.

Instead, they can choose between the Microsoft Authenticator app, Windows Hello, a security key, or phone/email verification codes to log into Microsoft Edge or Microsoft 365 apps and services.

“Now you can remove the password from your Microsoft account and sign in using passwordless methods like Windows Hello, the Microsoft Authenticator mobile app or a verification code sent to your phone or email,” said Liat Ben-Zur, Microsoft Corporate Vice President.

“This feature will help to protect your Microsoft account from identity attacks like phishing while providing even easier access to the best apps and services like Microsoft 365, Microsoft Teams, Outlook, OneDrive, Family Safety, Microsoft Edge and more.”

As Microsoft Corporate Vice President for Security, Compliance, and Identity Vasu Jakkal added, threat actors use weak passwords as the initial attack vector in most attacks across enterprise and consumer accounts. Microsoft detects 579 password attacks every second, with a total of 18 billion incidents each year.

“One of our recent surveys found that 15 percent of people use their pets’ names for password inspiration. Other common answers included family names and important dates like birthdays,” Jakkal said.

“We also found 1 in 10 people admitted reusing passwords across sites, and 40 percent say they’ve used a formula for their passwords, like Fall2021, which eventually becomes Winter2021 or Spring2022.”

How to go passwordless right now


To start logging in to your Microsoft account without a password, you first need to install the Microsoft Authenticator app and link it to your personal Microsoft account.

Next, you have to go to your Microsoft account page, sign in, and turn on the ‘Passwordless Account” under Advanced Security Options > Additional Security Options.

The last steps require you to follow the on-screen prompts and approve the notification displayed by the Authenticator app.

More info on using a passwordless method to sign in to your account is available on Microsoft’s support website.

“Passwordless solutions such as Windows Hello, the Microsoft Authenticator app, SMS or Email codes, and physical security keys provide a more secure and convenient sign-in method,” Microsoft explains.

“While passwords can be guessed, stolen, or phished, only you can provide fingerprint authentication, or provide the right response on your mobile at the right time.”

Originally published at https://www.bleepingcomputer.com.

Comments

Popular posts from this blog

Ex-Twitter employees accused of spying for Saudi Arabia

Two former employees of Twitter have been charged in the US with spying for Saudi Arabia. The charges, unsealed on Wednesday in San Francisco, allege that Saudi agents sought personal information about Twitter users including known critics of the Saudi government. Court documents  named the two as Ahmad Abouammo, a US citizen, and Ali Alzabarah, from Saudi Arabia. A third person, Saudi citizen Ahmed Almutairi, is also accused of spying. The New York Times says it is the first time that Saudi citizens have been charged with spying inside the United States. What are the charges? The charges allege Mr Almutairi acted as an intermediary between the two Twitter employees and Saudi officials. Ahmad Abouammo appeared in a Seattle court on Wednesday and was remanded in custody pending another hearing due on Friday. He is also charged with falsifying documents and making false statements to the FBI. Mr Abouammo is said to have left his job as a media partnership manager for

Mega Comparison: Zoom vs Skype vs Microsoft Teams vs Google Meet vs Google Duo vs Messenger Rooms

Video calling tools have lately been topping the download charts due to the sudden surge in work from home culture. However, with the number of options available in the market, it gets quite confusing for people to settle with one. So, we tried some of the most popular services such as Zoom, Skype, Microsoft Teams, Google Meet, Duo, and Messenger Rooms for you to decide which one’s a better choice. Read on. Zoom vs Skype vs Microsoft Teams vs Google Meet vs Google Duo vs Messenger Rooms: Which one’s better? Zoom Video Call Being the current most popular video call service in the market, Zoom has got all the features and quirks one would demand. Everything works fine except for the virtual background feature, which needs you to have uniform lighting and an easily distinguishable background. Usage:  Zoom can be used by anyone, ranging from friends and family to small office meetings and large enterprise conferences. Cost:  Zoom is free to use, with the basic plan having certain limitatio

Google teams up with security companies to catch bad apps before they hit the Play Store

It’s calling the partnership the ‘App Defense Alliance’ Google announced  today that it’s teaming up with three security companies to help identify malicious apps before they’re published on the Play Store and can potentially do harm to Android users. The company is calling this partnership the App Defense Alliance. Android is on over 2.5 billion devices, according to Google, and the company says that makes the platform “an attractive target” for abuse. That abuse can take the form of hidden malware or secret code designed to spy and siphon away sensitive user data. This seems to be particularly true of the Play Store — over the past year or so, Google has had to take  action   against   multiple   developers  for releasing apps on the Play Store using scammy ad practices. By forming the App Defense Alliance, Google is enlisting security companies ESET, Lookout, and Zimperium to help scan for bad apps before they hit the Play Store in the first place. Google already builds