A Microsoft account or MSA (previously known as Microsoft Passport,
[Microsoft Passport: Streamlining Commerce and Communication on the Web](_blank)
/ref> .NET Passport, and Windows Live ID) is a single sign-on Microsoft user account for Microsoft
Microsoft Corporation is an American multinational corporation, multinational technology company, technology corporation producing Software, computer software, consumer electronics, personal computers, and related services headquartered at th ...
customers to log in to Microsoft services (like Outlook.com), devices running on one of Microsoft's current operating system
An operating system (OS) is system software that manages computer hardware, software resources, and provides common services for computer programs.
Time-sharing operating systems schedule tasks for efficient use of the system and may al ...
s (e.g. Microsoft Windows
Windows is a group of several Proprietary software, proprietary graphical user interface, graphical operating system families developed and marketed by Microsoft. Each family caters to a certain sector of the computing industry. For example, W ...
computers and tablets, Windows Phone
Windows Phone (WP) is a discontinued family of mobile operating systems developed by Microsoft for smartphones as the replacement successor to Windows Mobile and Zune. Windows Phone featured a new user interface derived from the Metro desi ...
s, and Xbox
Xbox is a video gaming brand
A brand is a name, term, design, symbol or any other feature that distinguishes one seller's good or service from those of other sellers. Brands are used in business, marketing, and advertising for rec ...
consoles), and Microsoft application software
Application may refer to:
Mathematics and computing
* Application software, computer software designed to help the user to perform specific tasks
** Application layer, an abstraction layer that specifies protocols and interface methods used in a ...
(including Visual Studio
Visual Studio is an integrated development environment (IDE) from Microsoft. It is used to develop computer programs including web site, websites, web apps, web services and mobile apps. Visual Studio uses Microsoft software development platfor ...
).
History
Microsoft Passport, the predecessor to Windows Live ID, was originally positioned as a single sign-on service for all web commerce. Microsoft Passport received much criticism. A prominent critic was Kim Cameron, the author of ''The Laws of Identity,'' who questioned Microsoft Passport in its violations of those laws. He then joined Microsoft in 1999 after his company was acquired and was its Chief Architect of Access and Identity until his 2019 retirement, helping to address those violations in the design of the Windows Live ID identity meta-system. As a consequence, Windows Live ID is not positioned as the single sign-on service for all web commerce, but as one choice of many among identity systems.
In December 1999, Microsoft neglected to pay their annual $35 "passport.com" domain registration fee to Network Solutions
Network Solutions, LLC is an American-based technology company and a subsidiary of Web.com, the 4th largest .com domain name registrar
A domain name registrar is a company that manages the reservation of Internet domain names. A domain n ...
. The oversight made Hotmail
Outlook.com is a webmail service that is part of the Microsoft 365 product family. It offers mail, Calendaring software, calendaring, Address book, contacts, and Task management, tasks services.
Founded in 1996 by Sabeer Bhatia and Jack Smit ...
, which used the site for authentication, unavailable on December 24. A Linux
Linux ( or ) is a family of open-source Unix-like operating system
An operating system (OS) is system software that manages computer hardware, software resources, and provides common services for computer programs.
Time-sharing ...
consultant, Michael Chaney, paid it the next day (Christmas
Christmas is an annual festival commemorating the birth of Jesus Christ
Jesus, likely from he, יֵשׁוּעַ, translit=Yēšūaʿ, label=Hebrew/Aramaic ( AD 30 or 33), also referred to as Jesus Christ or Jesus of Nazareth (am ...
), hoping it would solve this issue with the downed site. The payment resulted in the site being available the next morning. In Autumn 2003, a similar good Samaritan helped Microsoft when they missed payment on the "hotmail.co.uk" address, although no downtime resulted.
In 2001, the Electronic Frontier Foundation's staff attorney Deborah Pierce criticized Microsoft Passport as a potential threat to privacy after it was revealed that Microsoft would have full access to and usage of customer information. The privacy terms were quickly updated by Microsoft to allay customers' fears.
In July and August 2001, the Electronic Privacy Information Center and a coalition of fourteen leading consumer groups filed complaints with the Federal Trade Commission (FTC) alleging that the Microsoft Passport system violated Section 5 of the Federal Trade Commission Act (FTCA), which prohibits unfair or deceptive practices in trade.
Microsoft had pushed for non-Microsoft entities to create an Internet-wide unified-login system. Examples of sites that used Microsoft Passport were eBay
eBay Inc. ( ) is an American multinational e-commerce company based in San Jose, California
San Jose, officially San José (; ; ), is a major city in the U.S. state of California that is the cultural, financial, and political center o ...
and Monster.com, but in 2004 those agreements were cancelled. In August 2009, Expedia sent notice out stating they no longer support Microsoft Passport / Windows Live ID.
In 2012, Windows Live ID was renamed Microsoft account.
Overview
Microsoft account allows users to sign into websites that support this service using a single set of credentials. Users' credentials are not checked by Microsoft account-enabled websites, but by a Microsoft account authentication server. A new user signing into a Microsoft account-enabled website is first redirected to the nearest authentication server, which asks for username and password over an SSL connection. The user may select to have their computer remember their login: a newly signed-in user has an encrypted time-limited cookie stored on their computer and receives a triple DES encrypted ID-tag that previously has been agreed upon between the authentication server and the Microsoft account-enabled website. This ID-tag is then sent to the website, upon which the website plants another encrypted HTTP cookie in the user's computer, also time-limited. As long as these cookies are valid, the user is not required to supply a username and password. If the user actively logs out of their Microsoft account, these cookies will be removed.
Microsoft account offers a user two different methods for creating an account:
#Use an existing e-mail address: Users are able to use their own valid e-mail address to sign up for a Microsoft account. The service turns the requesting user's e-mail address into a Microsoft account. Users may also choose a password of their own choice.
#Sign up for a Microsoft e-mail address: Users can also sign up for an e-mail account with Microsoft's webmail services designated domains (i.e. @hotmail.com or @outlook.com that can be used as a Microsoft account to sign into other Microsoft account-enabled websites.
The e-mail domains @live.com, @msn.com and @passport.com are discontinued.
Microsoft websites, services, and apps such as Bing, MSN
MSN (meaning Microsoft Network) is a web portal
A web portal is a specially designed website that brings information from diverse sources, like emails, online forums and search engines, together in a uniform way. Usually, each information ...
and Xbox Live
The Xbox network, formerly and still sometimes branded as Xbox Live, is an online
In computer technology and telecommunications, online indicates a state of connectivity and offline indicates a disconnected state. In modern terminology, th ...
use Microsoft account as a mean of identifying users. There are also several other companies that use it, such as the Hoyts website which is hosted by NineMSN.
Windows XP
Windows XP is a major release of Microsoft's Windows NT operating system. It was release to manufacturing, released to manufacturing on August 24, 2001, and later to retail on October 25, 2001. It is a direct upgrade to its predecessors, Wind ...
and later has an option to link a Windows user account with a Microsoft account, thus automatically logging users in to their Microsoft account whenever a service is accessed. Starting with Windows Server 2012, Windows allows users to directly authenticate into their PCs using their Microsoft account rather than a local or domain user.
Profile
A feature of the Microsoft account service is the profile manager, named Profile, which was formerly part of Windows Live. It displays information about the particular user, their recent activities, and their relationship with other Windows Live users. It also provides the ability to connect with others through Skype
Skype () is a proprietary telecommunications application operated by Skype Technologies, a division of Microsoft, best known for VoIP-based videotelephony, videoconferencing and voice calls. It also has instant messaging, file transfer, ...
, and via social networks such as Facebook
Facebook is an online social media and social networking service owned by American company Meta Platforms. Founded in 2004 by Mark Zuckerberg with fellow Harvard College students and roommates Eduardo Saverin, Andrew McCollum, Dustin Mosk ...
, MySpace and LinkedIn.
Users can share some of their personal information such as interests and hobbies, and social information such as their favorites quote, hometown, or places lived previously. Profile also allows users to modify their privacy settings to decide what is shared.
Web authentication
On August 15, 2007, Microsoft released the Windows Live ID Web Authentication SDK, enabling web developers to integrate Windows Live ID into their websites running on a broad range of web server platforms - including ASP.NET
ASP.NET is an open-source, server-side web-application framework designed for web development to produce dynamic web pages. It was developed by Microsoft to allow programmers to build dynamic web sites, applications and services. The ...
( C#), Java
Java (; id, Jawa, ; jv, ꦗꦮ; su, ) is one of the Greater Sunda Islands in Indonesia
Indonesia, officially the Republic of Indonesia, is a country in Southeast Asia and Oceania between the Indian and Pacific oceans. It consist ...
, Perl
Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages. "Perl" refers to Perl 5, but from 2000 to 2019 it also referred to its redesigned "sister language", Perl 6, before the latter's name was offi ...
, PHP, Python and Ruby
A ruby is a pinkish red to blood-red colored gemstone, a variety of the mineral corundum ( aluminium oxide). Ruby is one of the most popular traditional jewelry gems and is very durable. Other varieties of gem-quality corundum are called ...
.
Support for OpenID
On October 27, 2008, Microsoft announced that it was publicly committed to supporting the OpenID
OpenID is an open standard
An open standard is a standard that is openly accessible and usable by anyone. It is also a prerequisite to use open license, non-discrimination and extensibility. Typically, anybody can participate in the developmen ...
framework, with Windows Live ID becoming an OpenID provider. This would allow users to use their Windows Live ID to sign into any website that supports OpenID authentication. There had been no update on Microsoft's planned implementation of OpenID since August 2009, however since November 2013 Microsoft have publicly participated in OpenID Connect interoperability testing.
Login methods
In addition to using an account password, users can login to their Microsoft account by accepting a mobile notification sent to a mobile device with Microsoft Authenticator, a FIDO2 security token or by using Windows Hello. Users can also set up two-factor authentication
Multi-factor authentication (MFA; encompassing two-factor authentication, or 2FA, along with similar terms) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting ...
by getting a time-based, single-use code by text, phone call or using an authenticator app.
Features
Microsoft account is the website for users to manage their identity. Features of a Microsoft account include:
* updating user's information such as first and last names, address, etc. associated with the account;
* updating user settings, such as preferred language or preferences for email communications;
* changing or resetting user passwords;
* close the account;
* view billing details associated with the accounts.
Integrated with
The following is a list of computer programs and web services that support using Microsoft Account as the credentials required for the authentication process.
*Windows 8
Windows 8 is a major release of the Windows NT operating system
An operating system (OS) is system software that manages computer hardware, software resources, and provides common services for computer programs.
Time-sharing operat ...
and later
* Windows Server 2012 and later
* Windows components
**Calendar
A calendar is a system of organizing days. This is done by giving names to periods of time
Time is the continued sequence
In mathematics, a sequence is an enumerated collection of objects in which repetitions are allowed and or ...
** Cortana
** Groove Music
** Feedback Hub
**Mail
The mail or post is a system for physically transporting postcards, letters, and parcels. A postal service can be private or public, though many governments place restrictions on private systems. Since the mid-19th century, national postal sy ...
** Movies & TV
**Microsoft Store
Microsoft Store (formerly known as Windows Store) is a digital distribution platform operated by Microsoft
Microsoft Corporation is an American multinational corporation, multinational technology company, technology corporation produ ...
**Outlook Express
Outlook Express, formerly known as Microsoft Internet Mail and News, is a discontinued email
Electronic mail (email or e-mail) is a method of exchanging messages ("mail") between people using electronic devices. Email was thus concei ...
**People
A person ( : people) is a being that has certain capacities or attributes such as reason, morality, consciousness or self-consciousness, and being a part of a culturally established form of social relations such as kinship, ownership of pr ...
** Windows Messenger
*Windows Phone 7
Windows Phone 7 is the first release of the Windows Phone mobile client operating system, released worldwide on October 21, 2010, and in the United States
The United States of America (U.S.A. or USA), commonly known as the United States ( ...
and later
** Windows Phone Store
* Bing
* Exchange Online
* Exchange Online Protection
*Microsoft Office
Microsoft Office, or simply Office, is the former name of a family of client software, server software, and services developed by Microsoft. It was first announced by Bill Gates on August 1, 1988, at COMDEX in Las Vegas. Initially a marketin ...
* Office 365
* Office Online
* OneDrive (formerly SkyDrive)
* Outlook.com (formerly Hotmail)
*Skype
Skype () is a proprietary telecommunications application operated by Skype Technologies, a division of Microsoft, best known for VoIP-based videotelephony, videoconferencing and voice calls. It also has instant messaging, file transfer, ...
* System Center Advisor
*Visual Studio
Visual Studio is an integrated development environment (IDE) from Microsoft. It is used to develop computer programs including web site, websites, web apps, web services and mobile apps. Visual Studio uses Microsoft software development platfor ...
*Microsoft Azure
Microsoft Azure, often referred to as Azure ( , ), is a cloud computing
Cloud computing is the on-demand availability of computer system resources, especially data storage ( cloud storage) and computing power, without direct activ ...
(formerly Windows Azure)
* Windows Insider Program
*Windows Live Messenger
MSN Messenger (also known colloquially simply as "Messenger"), later rebranded as Windows Live Messenger, was a cross-platform instant messaging client, instant-messaging client developed by Microsoft. It connected to the Microsoft Messenger ser ...
* Windows Movie Maker
* Windows Photo Gallery
* Xbox network
Security vulnerabilities
On June 17, 2007, Erik Duindam, a web developer in the Netherlands, reported a privacy and identity risk, saying a "critical error was made by Microsoft programmers that allows everyone to create an ID for virtually any e-mail address." A procedure was found to allow users to register invalid or currently used e-mail addresses. Upon registration with a valid e-mail address, an e-mail verification link was sent to the user. Before using it however, the user was allowed to change the e-mail address to one that did not exist, or to an e-mail address currently used by someone else. The verification link then caused the Windows Live ID system to confirm the account as having a verified email address. That flaw was fixed two days later, on June 19, 2007.
On April 20, 2012, Microsoft fixed a flaw in Hotmail's password reset system that allowed anyone to reset the password of any Hotmail account. The company was notified of the flaw by researchers at Vulnerability Lab on the same day and responded with a fix within hours — but not before widespread attacks as the exploitation technique spread quickly across the Internet.
On December 3, 2015, a security researcher discovered a vulnerability in the Adobe Experience Manager (AEM) software used on signout.live.com and reported it to the Microsoft Security Response Center (MSRC). This vulnerability enabled full-administrative access to the AEM Publish nodes' OSGi
OSGi is an open specification and open source
Open source is source code
In computing, source code, or simply code, is any collection of code, with or without comments, written using a human-readable programming language
A progra ...
console and made it possible to execute code inside of the JVM through the upload of a custom OSGi bundle. The vulnerability was confirmed to have been resolved on May 3, 2016."Remote Code Execution (RCE) on Microsoft's 'signout.live.com'"
/ref>
See also
* Identity management
* Identity management system
* List of single sign-on implementations
Other identity services
* Active Directory Federation Services
* OpenID
OpenID is an open standard
An open standard is a standard that is openly accessible and usable by anyone. It is also a prerequisite to use open license, non-discrimination and extensibility. Typically, anybody can participate in the developmen ...
* Light-weight Identity
Light-weight Identity (LID), or Light Identity Management (LIdM) is an identity management system for online digital identities developed in part by NetMesh. It was first published in early 2005, and is the original URL-based identity system, lat ...
* Yadis {{Unreferenced , date= November 2013
Yadis is a communications protocol
A communication protocol is a system of rules that allows two or more entities of a communications system to transmit information via any kind of variation of a physica ...
* Windows CardSpace
Identity management
* Liberty Alliance
* OASIS (organization)
The Organization for the Advancement of Structured Information Standards (OASIS; ) is a nonprofit consortium
A consortium (plural: consortia) is an association of two or more individuals, companies, organizations or governments (or any ...
* Windows Hello
References
Further reading
Creating a Microsoft account
Introduction to Windows Live ID whitepaper
— Provides a brief overview of the Windows Live ID service in the context of Microsoft's overall identity strategy.
Understanding Windows Live Delegated Authentication whitepaper
— Describes how a Web site can use the Windows Live ID Delegated Authentication system to get permission to access users' information on Windows Live services.
Windows Live ID Federation whitepaper
— Describes the concept of identity federation and offers considerable detail about how the Windows Live ID service supports it.
External links
*
{{Microsoft Office
ID
Federated identity
Companies' terms of service
Microsoft