Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft ended password storage and autofill in Microsoft Authenticator in 2025, but it did not shut down the app or its authentication functions. Passwords synced to your Microsoft account were reported to remain available in Edge after you sign in. If you still rely on an Authenticator password, check that you can access it and set up an alternative sign-in method before replacing your phone or removing the app. Passkeys can improve sign-in security, but you must create them separately for each supported service.

What happened to passwords saved in Microsoft Authenticator?

Microsoft phased out Authenticator’s password-manager features in stages: adding or importing passwords stopped in June 2025, autofill was removed in July, and saved passwords became inaccessible through Authenticator starting August 1, 2025. The app itself was not discontinued. The change concerned password storage and autofill, not the app’s separate role in authentication. The Associated Press reported the transition and dates.

AP reported that passwords synced with a Microsoft account could still be accessed in Edge after signing in. Microsoft’s current instructions direct users to Microsoft Password Manager in Edge. Access and available screens can vary by account and device configuration.

How to check or recover your saved passwords

  1. Sign in to Edge with the Microsoft account that held the Authenticator data. Open Settings > Passwords and autofill > Microsoft Password Manager and look for saved entries. Microsoft notes that editing a saved password in the manager changes the stored entry; it does not change the password on that website.
  2. If Authenticator still offers an export option on your device, export before deleting or resetting anything. AP documented the historical path as Settings > Export Passwords during the transition. The feature has been retired, so this may no longer be available and is not a guaranteed recovery method.
  3. If you cannot find an entry in Edge, use the affected service’s own password-reset process. Do not assume that a password has been changed or deleted at the service because it is missing from a manager.

Microsoft’s Password Manager support page says the feature requires a personal account profile. A work or school account may have features restricted by its IT administrator. If the passwords belong to a managed account, ask your organization’s administrator what access or recovery options are permitted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Does this affect one-time codes or two-factor authentication?

The retirement of password autofill does not itself mean that Authenticator’s one-time codes, account authentication, or an organization’s multi-factor authentication enrollment were removed. Password management and authentication are distinct functions. For a work or school account, check with your administrator before changing an enrollment or relying on a new sign-in method; the available passkey options depend on organizational policy. Microsoft Entra’s passkey FAQ describes how administrators manage passkeys and related policies.

What a passkey does—and does not do

A passkey is a credential registered with a particular website or app. It uses a public/private key pair: the service stores the public key, while the private key stays with the user’s device or credential manager. At sign-in, the device proves possession by signing a challenge rather than sending a password to the service. A passkey is created service by service; it does not automatically convert passwords saved in Authenticator or work on every website.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Microsoft describes passkeys as phishing-resistant because a passkey is tied to the domain for which it was created, so an impostor domain should not be able to prompt the device to use that credential. This does not make every aspect of an account impossible to compromise: device security, account recovery, and social engineering still matter. Microsoft characterizes passkeys as multi-factor authentication because use combines possession of the credential with an unlock method such as a biometric or PIN. Microsoft says biometric data stays on the device and is not shared with Microsoft. Read Microsoft’s passkey explanation.

Choose a passkey storage method you can recover

Passkeys differ in where they are kept and how they are available on other devices. Consider recovery, device control, compatibility with your services and devices, and whether an organization manages the account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Option Portability and recovery Useful consideration
Device-bound passkey Stays on the device where it was created; it does not sync. If that device is lost, the credential cannot be restored from Microsoft Authenticator. Can suit stricter device-control needs, but set up another sign-in or recovery method, or another credential where the service allows it.
Synced passkey Stored in a credential manager or cloud service and available on that provider’s devices, subject to the provider’s account and recovery protections. Can make changing devices easier; check the provider’s recovery safeguards and whether the service and devices support the passkey.

Microsoft says Authenticator passkeys are device-bound and cannot sync. For organizational deployments, Microsoft Entra recommends device-bound passkeys for administrators and highly privileged users and synced passkeys for other users. That is an organization-focused recommendation, not a universal rule for personal accounts. See Microsoft Entra’s guidance.

Check device and account compatibility before setting up passkeys

Microsoft’s current passkey support page lists Windows 10 or newer, macOS Ventura or newer, ChromeOS 109 or newer, iOS 16 or newer, Android 9 or newer, and FIDO2 hardware security keys. It lists Microsoft Authenticator passkeys as requiring iOS 17 or newer or Android 14 or newer. Microsoft Password Manager passkeys are listed as available only in Edge 142 or newer and were described as rolling out. Requirements and availability can change; check the latest guidance and confirm support on both your device and the service where you want to sign in. Microsoft’s passkey support page provides its current requirements.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

A FIDO2 security key is optional, not a requirement for passkeys or for retrieving Authenticator passwords. Before choosing one, confirm that the services you use support security keys or passkeys and that the key’s connector or NFC mode works with your devices.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A practical order for moving to passkeys

  1. Secure access to your existing passwords. Check Edge with the Microsoft account used by Authenticator, and use the service’s password-reset process for anything you cannot recover.
  2. Keep a backup way to sign in. Before relying on a device-bound passkey, confirm that the service offers another sign-in or recovery option, or register another credential if permitted.
  3. Register a passkey with each supported service. Use that service’s security or sign-in settings, or follow its registration prompt. Keep using a password where passkeys are not supported or have not been configured.
  4. For managed accounts, confirm policy first. Ask your IT administrator which providers and methods are allowed before enrolling, removing a device, or changing authentication settings.

Microsoft reported that password attacks occurred at a rate of 7,000 per second in 2024, more than double its reported 2023 rate; this is a Microsoft-reported figure quoted by AP, not an independently validated measurement in the cited reporting. It gives context for Microsoft’s promotion of stronger sign-in methods, but it does not mean that every passkey setup is automatically safer if recovery and device access are neglected. AP’s report attributes the figure to Microsoft.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.