Why Does Microsoft Require Authenticator for Passkeys? | Troubleshooting Guide
Question details
The user wants to know why Microsoft accounts do not accept all third-party password managers for passkeys, instead defaulting to platform or specific authenticator apps.

- Product
- Microsoft Account
- Device & OS
- not provided
- Scenario
- Setting up or authenticating a Microsoft account using passkeys.
- Observed behavior
- Microsoft prompts for platform authentication, security keys, or its own Authenticator app instead of seamlessly integrating with the user's preferred third-party password manager.
Ensure your web browser and third-party password manager extension are updated to the latest versions, as passkey support relies on modern WebAuthn standards.
Configure and Verify Third-Party Password Manager Compatibility
Check if your preferred password manager supports Microsoft account passkeys and manually trigger it during the login process.
Microsoft relies on the FIDO2/WebAuthn standard for passkeys. By default, operating systems often intercept passkey requests to use built-in tools like Windows Hello or Apple Keychain. To use a third-party password manager, the app's browser extension must be properly configured to intercept these requests.
Open your browser's extension manager and ensure your third-party password manager (e.g., 1Password, Bitwarden) is updated to a version that explicitly supports passkeys.
Log in to your Microsoft account, navigate to 'Security', select 'Advanced security options', and click 'Add a new way to sign in or verify'.
When prompted to use Windows Hello or a security key, look for an option such as 'Use another device', 'More choices', or simply click 'Cancel' on the system dialog. This often allows your password manager extension to step in and save the passkey.
Use Platform Authentication or a Hardware Security Key
If your third-party authenticator is incompatible, use native device security features or a physical FIDO2 security key.
Looking for a Hassle-Free Office Suite? Try WPS Office
If managing Microsoft account security settings and mandatory authenticators is becoming a burden, consider switching to an office suite that offers a simpler experience. WPS Office is a lightweight, highly compatible alternative that lets you focus on your work without complex account dependencies.
- 1. Download the software: Visit the official WPS website to download the free WPS Office installer.
- 2. Install and launch: Run the installer, open the application, and immediately start creating documents, spreadsheets, or presentations.
- 3. Save in standard formats: Save your files locally in standard Microsoft Office formats ensuring seamless sharing with colleagues.

Frequently Asked Questions
Can I use standard authenticator apps like Google Authenticator for Microsoft passkeys?
No. Apps like Google Authenticator are designed for standard Two-Factor Authentication (TOTP codes). Passkeys use FIDO2 cryptographic keys, which require a compatible password manager, hardware security key, or platform authenticator like Windows Hello.
Why is Windows Hello overriding my password manager when creating a passkey?
Operating systems like Windows prioritize their native passkey managers (Windows Hello) over browser extensions. To use a third-party password manager, you usually need to dismiss the Windows Hello prompt or select 'More choices' to allow the extension to capture the request.
What should I do if my preferred authenticator application is simply not accepted by Microsoft?
Check your password manager's documentation to ensure it supports Microsoft account passkeys. If it is unsupported, you will need to rely on Microsoft Authenticator, Windows Hello, Apple Keychain, or a physical FIDO2 hardware security key for passkey functionality.




