Microsoft wants you to ditch passwords for biometrics
CISO Bret Arsenault believes passwords aren't secure enough on their own


Microsoft has touted ambitions to move away from passwords and embrace biometric security for identification and authentication processes.
The company's chief information security officer Bret Arsenault told CNBC that online passwords should be eliminated as they do not adequately protect people, and biometrics should be used instead.
Arsenault noted that passwords on their own do not afford enough cyber security and that even the relatively simple and old technique of password spraying whereby a hacker tries to access large amounts of accounts at once by firing commonly used passwords at them can lead to organisations and online a services getting hacked as there's often no extra layer of security once a correct password has been inputted.
"The reality is, we still see a lot of attempts of people trying to password spray. The best way to protect against the password spray is to just eliminate passwords," said Arsenault, who did acknowledge that password security can be bolstered with multi-factor authentication.
"And so the thing that we are seeing is lots and lots of people just focused on eliminating that whole vector."
Microsoft is practising what Arsenault is preaching, with 90% of its 135,000-strong workforce already able to log into the company's corporate network without passwords. Instead, the workers use biometric technology, such as facial recondition or fingerprint scanning, to authenticate themselves.
The company will also scrap its old password expiration policies in Windows 10 in favour of a system that purges expiring passwords deemed no longer secure, and it will effectively force its users to update their passwords every few months once the Windows 10 May 2019 gets rolled out.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Such an anti-password stance is understandable given the increasing use of biometrics, from voice and image recognition to under-display fingerprint scanners in the latest Android smartphones.
However, there are still plenty of cases where biometrics can be duped and devices unlocked by people who shouldn't have such access. Recently, this was brought into the fore with the Nokia 9 PureView, which could be unlocked by pressing a packet of chewing gum against the phone's under-display scanner.
As such, there may be a need for biometric technology to evolve a little further before it can truly replace passwords, online or otherwise.
Roland is a passionate newshound whose journalism training initially involved a broadcast specialism, but he’s since found his home in breaking news stories online and in print.
He held a freelance news editor position at ITPro for a number of years after his lengthy stint writing news, analysis, features, and columns for The Inquirer, V3, and Computing. He was also the news editor at Silicon UK before joining Tom’s Guide in April 2020 where he started as the UK Editor and now assumes the role of Managing Editor of News.
Roland’s career has seen him develop expertise in both consumer and business technology, and during his freelance days, he dabbled in the world of automotive and gaming journalism, too.
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Lateral moves in tech: Why leaders should support employee mobility
In-depth Encouraging staff to switch roles can have long-term benefits for skills in the tech sector
By Keri Allan
-
Five things to consider before choosing an MFA solution
In-depth Because we all should move on from using “password” as a password
By Rene Millman
-
The IT Pro Podcast: Going passwordless
IT Pro Podcast Something you are, or something you have, could be more important than a password you know in the near future
By IT Pro
-
Podcast transcript: Going passwordless
IT Pro Podcast Read the full transcript for this episode of the IT Pro Podcast
By IT Pro
-
UK police fails ethical tests with "unlawful" facial recognition deployments
News A University of Cambridge team audited UK police use of the tech and found frequent ethical and legal shortcomings
By Rory Bathgate
-
Snapchat settles for $35 million in Illinois biometrics lawsuit
News The social media giant had been accused of improperly collecting, storing facial geometry in violation of state legislation
By Rory Bathgate
-
Home Office to collect foreign offenders' biometric data using smartwatch scheme
News Facial recognition and geolocation data will be matched against Home Office, Ministry of Justice and police databases
By Rory Bathgate
-
Southern co-operative faces legal complaint for facial recognition CCTV
News Rights group Big Brother Watch has written to the Information Commissioner to “stop unlawful processing”
By Rory Bathgate
-
Amazon gave police departments Ring footage without permission
News The tech giant has done this 11 times this year
By Zach Marzouk