openideurope.eu

From Microsoft Passport to passkeys: 25 years of SSO

From Microsoft Passport and the Liberty Alliance to OpenID, social login, FIDO2 and passkeys: how the dream of one safe login for everything changed form.

HistoryPublished

Almost every decade since the late 1990s has produced a new answer to the same question: how can people sign in once, safely, and use many services? Microsoft Passport was the first answer to reach millions of people. Passkeys are the latest. The path between them runs through OpenID.

1999 to 2004: one company, one login

Microsoft launched Passport, later known as .NET Passport, in the late 1990s as a single account for the web, closely tied to Hotmail. The idea was convenient: one username and password, used on many participating sites. The design was entirely centralised. Microsoft held the accounts, Microsoft decided which sites could take part, and Microsoft saw the logins.

Concerns about privacy and control followed. Privacy groups raised objections in 2001, and in August 2002 Microsoft settled charges from the US Federal Trade Commission over its security and privacy promises for the service. By 2004 large partners such as eBay and Monster had ended their Passport agreements. The service itself continued under later names: Windows Live ID, and from 2012 the Microsoft account.

2001 to 2007: federation and OpenID

The unease over a single company holding everyone’s identity produced alternatives. A group of companies founded the Liberty Alliance in 2001 to build federated identity that no single party controlled. Their work fed into SAML, the standard for exchanging login assertions between organisations, which became an OASIS standard in 2002 and is still widely used in companies. See SAML and identity federation.

OpenID (2005) took the idea to consumers: anyone could be a provider, and no company owned the system. The OpenID Europe story belongs here, and the timeline shows how the big names arrived. In February 2007 Microsoft announced joint work with other vendors on connecting OpenID to its CardSpace identity system.

2008 to 2014: Microsoft joins OpenID, social login wins

The most telling sign was the reversal. In late October 2008 Windows Live ID became an OpenID provider, announced alongside a limited Google rollout, as told in Google and Windows Live join OpenID. The company that had once built the most centralised login now accepted a decentralised one.

It did not matter much for the mass market. Facebook’s login, then Google’s and others, took the consumer space, and the technical basis moved to OAuth 2.0 and OpenID Connect in 2014. See Why OpenID 2.0 faded.

2013 to 2022: the password itself becomes the target

All of those designs still used shared secrets, usually passwords. The next step was to remove them. The FIDO Alliance, formed in 2013, developed standards for logging in with public-key cryptography. Microsoft’s Windows Hello arrived with Windows 10 in 2015, offering a fingerprint, face or PIN stored on the device. In November 2018 Microsoft added password-free sign-in for Microsoft accounts through its Authenticator app, FIDO2 security keys and Windows Hello. The W3C made WebAuthn, the web side of FIDO2, a Recommendation in March 2019.

In 2022 Apple, Google and Microsoft jointly committed to support passkeys, the consumer-friendly form of FIDO credentials that can sync between devices. Apple introduced the term to the public at its developer conference in June 2022, Google followed with Android and Chrome support later that year, and Microsoft rolled out passkey support for Windows 11 in 2023.

What is different about a passkey

A passkey login does not depend on a provider seeing every sign-in, and the secret never leaves your device. The website stores only a public key. When you sign in, your device signs a challenge that is tied to the website’s real address. A fake site gets nothing it can reuse, which is the property OpenID lacked. The mechanics are in FIDO2 and WebAuthn and the practical side in passkeys explained.

Passkeys do not give you single sign-on in the old sense, because each website still needs its own credential. But the experience is similar: a touch or a glance, and no password to remember. For many people the password manager or the phone becomes the identity layer that Passport once tried to be.

The pattern behind 25 years

  1. Centralised convenience (Passport) is easy but concentrates power.
  2. Open federation (SAML, OpenID) spreads trust but is hard to use at scale.
  3. Platform login (Facebook, Google, Apple) is easy again, but depends on a few companies.
  4. Credentials on your device (passkeys, the EU wallet) aims for convenience without a company in the middle.

The EU Digital Identity Wallet is the next entry in that list, and it adds a legal basis. See From OpenID to the EU wallet. For how to use single sign-on safely today, read the guide to single sign-on.

Dates from public company and standards records; checked October 2026. Where sources differ on exact launch details of Passport, we state the period only.

More in History