Microsoft says it has gained FIDO2 certification for Windows Hello, Windows 10's biometric authentication system, for the Windows 10 May 2019 update
Microsoft moves 800 million people closer to a no-password world. — Microsoft has passed another milestone on its quest to kill off passwords.
Context & Ripple Effects
This certification is the payoff to a four-year build-out: Microsoft committed Windows 10 to FIDO biometric authentication back in 2015, added FIDO2 passwordless support to Windows Hello in April 2018, and by November let users sign into a Microsoft Account with a standards-based security key and no username or password at all (security key support). Certification means the built-in biometric itself — not an add-on dongle — now counts as a compliant FIDO2 authenticator.
That matters because of scale: the May 2019 update puts a certified passwordless credential on roughly 800 million Windows 10 devices, turning every Hello-equipped PC into a FIDO2 platform authenticator rather than requiring users to buy a separate key.
First-order effects
- Windows 10 users on the May 2019 update can authenticate to any FIDO2-compliant relying party with Windows Hello directly — face, fingerprint, or PIN — instead of carrying a Yubico-style USB key or typing credentials.
- Microsoft's own account system becomes the immediate beneficiary: sign-ins to Microsoft Accounts can ride on the certified platform authenticator, cutting password entry and the reset flows that come with it.
Second-order effects
- Hardware key vendors like Yubico lose their monopoly on standards-based passwordless login for Windows users — the platform credential is free and already installed — pushing them to differentiate on portability across devices Microsoft doesn't control.
- Rival platforms and browser vendors face pressure to get their own authenticators FIDO2-certified, since websites adopting the standard will prefer credentials that work on the largest installed base.
Third-order effects
- If the pattern holds, passwordless stops being an opt-in feature and becomes the default identity layer of the OS — a trajectory Microsoft completed when it began letting users strip passwords from accounts entirely in favor of Authenticator, Hello, keys, or codes (2021 password removal).
- Certification bodies like the FIDO Alliance become gatekeepers of trust: once biometric hardware is the credential, compliance testing replaces password policy as the mechanism sites rely on to decide who gets in.
The trend: Authentication is migrating from shared secrets typed by users to device-bound biometrics certified against open standards, with Microsoft using its Windows install base to make the password optional first and obsolete later.