Summary
- Microsoft Edge removes the Custom Primary Password for its built-in password manager.
- Edge now uses Windows Hello or OS/device authentication to protect saved passwords.
- Windows Hello biometrics can't be phished; device login ties protection to your hardware and doesn't send data.
It's no secret that Microsoft wants to get rid of the password. This time last year, we saw Microsoft scrap passwords as the default option for new Microsoft accounts. You could still add one if you wanted, but the company would initially push for you to use a passkey or biometrics before you set one. Now, Microsoft Edge will no longer use a master password to unlock its password manager, and its alternatives should be a lot more secure.
Microsoft Edge will now use Windows Hello or your device's password
The Custom Primary Password is going away
If you use Microsoft Edge's built-in password manager, there's a good chance you've unlocked it using your Custom Primary Password. This is a 'master password' which you use to unlock your manager and access all of your online account details. It's really convenient to have, but if anyone learns of your Custom Primary Password, they could use it to access your account details.
A few months ago, Microsoft published an article titled "Keep your saved passwords private in Microsoft Edge." In it, the company announced that it was planning to get rid of the Custom Primary Password altogether:
On June 4, Custom Primary Password will be fully removed for opted‑in users. After this date, Microsoft Edge will automatically use device‑based authentication (such as Windows Hello, device password, or OS‑level authentication) to protect saved passwords.
Well, today's the day. Now that June 4th has arrived, people on Edge should be moved over to Windows Hello (which includes biometric logins) or log in using OS-level authentication. Going the Windows Hello route makes your account a lot more resilient to attacks than a Custom Primary Password, as it lets you use a fingerprint, face, or iris scan to access your account, which can't be phished or leaked.
However, if you don't use Windows Hello, you'll instead use your Windows device's login, which is bound to your computer's hardware and doesn't need to send data over the internet to authenticate you. Sounds like a win-win to me.
Microsoft is scrapping one of its apps and forcing people to use Edge instead
It's going away really soon, too.
