
A Microsoft account or MSA (previously known as Microsoft Passport,
.NET Passport, and Windows Live ID) is a
single sign-on personal
user account
A user is a person who uses a computer or network service.
A user often has a user account and is identified to the system by a username (or user name).
Some software products provide services to other systems and have no direct end use ...
for
Microsoft
Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
customers to
log in to consumer Microsoft services (like
Outlook.com), devices running on one of Microsoft's current
operating system
An operating system (OS) is system software that manages computer hardware and software resources, and provides common daemon (computing), services for computer programs.
Time-sharing operating systems scheduler (computing), schedule tasks for ...
s (e.g.
Microsoft Windows
Windows is a Product lining, product line of Proprietary software, proprietary graphical user interface, graphical operating systems developed and marketed by Microsoft. It is grouped into families and subfamilies that cater to particular sec ...
computers and tablets,
Xbox
Xbox is a video gaming brand that consists of four main home video game console lines, as well as application software, applications (games), the streaming media, streaming service Xbox Cloud Gaming, and online services such as the Xbox networ ...
consoles), and Microsoft
application software
Application software is any computer program that is intended for end-user use not operating, administering or programming the computer. An application (app, application program, software application) is any program that can be categorized as ...
(e.g.
Microsoft Office
Microsoft Office, MS Office, or simply Office, is an office suite and family of client software, server software, and services developed by Microsoft. The first version of the Office suite, announced by Bill Gates on August 1, 1988, at CO ...
,
Microsoft Teams
Microsoft Teams is a team collaboration platform developed by Microsoft as part of the Microsoft 365 suite. It offers features such as workspace chat, video conferencing, file storage, and integration with both Microsoft and third-party applicat ...
).
Overview
Microsoft account allows users to sign into websites that support this service using a single set of credentials - these
usernames are in the same form as an
email address An email address identifies an email box to which messages are delivered. While early messaging systems used a variety of formats for addressing, today, email addresses follow a set of specific rules originally standardized by the Internet Enginee ...
. Microsoft account offers a user two different methods for creating an account:
#Use an existing e-mail address: Users are able to use their own valid e-mail address to sign up for a Microsoft account. The service turns the requesting user's e-mail address into a Microsoft account ID. Users may also choose a password of their own choice.
#Sign up for a Microsoft e-mail address: Users can also sign up for a free e-mail account through Outlook.com or MSN, with Microsoft's webmail services designated
domains (i.e. @hotmail.com, @outlook.com, @msn.com) that can be used as a Microsoft account to sign into other Microsoft account-enabled websites.
Both methods don't require, as of 2025, mobile verification.
The domains @live.com and @passport.com, as well as other domains are no longer offered, but existing accounts are maintained.
Microsoft websites, services, and apps such as
Bing
Bing most often refers to:
* Bing Crosby (1903–1977), American singer
* Microsoft Bing, a web search engine
Bing may also refer to:
Food and drink
* Bing (bread), a Chinese flatbread
* Bing (soft drink), a UK brand
* Bing cherry, a varie ...
,
MSN and
Xbox Live
The Xbox network, formerly known and commonly referred to as Xbox Live, is an online multiplayer gaming and digital media delivery service created and operated by Microsoft Gaming for the Xbox brand. It was first made available to the origina ...
use Microsoft account as a means of identifying users. There are also several other companies that use it, such as the
Hoyts
The HOYTS Group of companies in Australia and New Zealand includes HOYTS Cinemas, a cinema chain, and Val Morgan, which sells advertising on cinema screens and digital billboards.
The company was established by dentist Arthur Russell in Melbo ...
website which is hosted by
NineMSN
Nine.com.au (formerly Ninemsn) is an Australian news website, owned by Nine Entertainment. It was originally established as a 50:50 joint venture between Microsoft and PBL Media (now Nine Entertainment) in 1997 as "Ninemsn." Microsoft sold its ...
.
Windows XP
Windows XP is a major release of Microsoft's Windows NT operating system. It was released to manufacturing on August 24, 2001, and later to retail on October 25, 2001. It is a direct successor to Windows 2000 for high-end and business users a ...
and later has an option to link a local Windows user account with a Microsoft account, thus automatically logging users in to their Microsoft account whenever a service is accessed. Starting with
Windows 8
Windows 8 is a major release of the Windows NT operating system developed by Microsoft. It was Software release life cycle#Release to manufacturing (RTM), released to manufacturing on August 1, 2012, made available for download via Microsoft ...
and
Windows Server 2012
Windows Server 2012, codenamed "Windows Server 8", is the ninth major version of the Windows NT operating system produced by Microsoft to be released under the Windows Server brand name. It is the server version of Windows based on Windows ...
, Windows allows users to directly authenticate into their
PCs using their Microsoft account rather than a local or domain user.
Login methods
In addition to using an account password, users can login to their Microsoft account by accepting a mobile notification sent to a mobile device with Microsoft Authenticator, a
FIDO2
security token
A security token is a peripheral device used to gain access to an electronically restricted resource. The token is used in addition to, or in place of, a password. Examples of security tokens include wireless key cards used to open locked door ...
or by using
Windows Hello. Users can also set up
two-factor authentication
Multi-factor authentication (MFA; two-factor authentication, or 2FA) is an electronic authentication method in which a user is granted access to a website or Application software, application only after successfully presenting two or more distin ...
by getting a
time-based, single-use code by text, phone call or using an authenticator app.
Technical details
Users' credentials are not checked by Microsoft account-enabled websites, but by a Microsoft account authentication server. A new user signing into a Microsoft account-enabled website is first redirected to the nearest authentication server, which asks for username and password over an
SSL connection. The user may select to have their computer remember their login: a newly signed-in user has an encrypted time-limited cookie stored on their computer and receives a
triple DES
In cryptography, Triple DES (3DES or TDES), officially the Triple Data Encryption Algorithm (TDEA or Triple DEA), is a symmetric-key block cipher, which applies the DES cipher algorithm three times to each data block. The 56-bit key of the Dat ...
encrypted ID-tag that previously has been agreed upon between the authentication server and the Microsoft account-enabled website. This ID-tag is then sent to the website, upon which the website plants another encrypted HTTP cookie in the user's computer, also time-limited. As long as these cookies are valid, the user is not required to supply a username and password. If the user actively logs out of their Microsoft account, these cookies will be removed.
Relationship with work or school account
Microsoft also offer a ''work or school account'' which are set up by an
administrator as part of an organization. These accounts are separate from Microsoft accounts (which is also called ''personal account'') and cannot be merged, but may be used side-by-side by a user. A work or school account uses the
Azure Active Directory domain platform.
History
Microsoft Passport, the predecessor to Windows Live ID, was originally positioned as a
single sign-on service for all web commerce. Microsoft Passport received much criticism. A prominent critic was
Kim Cameron, the author of ''The Laws of Identity,''
who questioned Microsoft Passport in its violations of those laws. He then joined Microsoft in 1999 after his company was acquired and was its chief architect of access and identity until his 2019 retirement, helping to address those violations in the design of the Microsoft Account identity meta-system. As a consequence, Microsoft Accounts are not positioned as the single sign-on service for all web commerce, but as one choice of many among identity systems.
In December 1999, Microsoft neglected to pay their annual $35 "passport.com" domain registration fee to
Network Solutions
Network Solutions, LLC, formerly Web.com, is an American-based technology company and a subsidiary of Web.com, the 4th-largest .com domain name registrar, with over 6.7 million registrations as of August 2018. In addition to being a domain name ...
. The oversight made
Hotmail
Outlook.com, formerly Hotmail, is a free personal email service offered by Microsoft. It also provides a webmail interface accessible via web browser or mobile apps featuring mail, Calendaring software, calendaring, Address book, contacts, and ...
, which used the site for authentication, unavailable on December 24. A
Linux
Linux ( ) is a family of open source Unix-like operating systems based on the Linux kernel, an kernel (operating system), operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically package manager, pac ...
consultant, Michael Chaney, paid it the next day (
Christmas
Christmas is an annual festival commemorating Nativity of Jesus, the birth of Jesus Christ, observed primarily on December 25 as a Religion, religious and Culture, cultural celebration among billions of people Observance of Christmas by coun ...
), hoping it would solve this issue with the downed site. The payment resulted in the site being available the next morning. In Autumn 2003, a similar
good Samaritan helped Microsoft when they missed payment on the "hotmail.co.uk" address, although no downtime resulted.
In 2001, the
Electronic Frontier Foundation
The Electronic Frontier Foundation (EFF) is an American international non-profit digital rights group based in San Francisco, California. It was founded in 1990 to promote Internet civil liberties.
It provides funds for legal defense in court, ...
's staff attorney Deborah Pierce criticized Microsoft Passport as a potential threat to privacy after it was revealed that Microsoft would have full access to and usage of customer information. The privacy terms were quickly updated by Microsoft to allay customers' fears.
In July and August 2001, the
Electronic Privacy Information Center
The Electronic Privacy Information Center (EPIC) is an independent nonprofit research center established in 1994 to protect privacy, freedom of expression, and democratic values in the information age. Based in Washington, D.C., their mission i ...
and a coalition of fourteen leading consumer groups filed complaints with the
Federal Trade Commission (FTC) alleging that the Microsoft Passport system violated Section 5 of the
Federal Trade Commission Act (FTCA), which prohibits unfair or deceptive practices in trade. In August 2002, Microsoft agreed to settle the resulting FTC charges. As part of the settlement, Microsoft was required to implement and maintain a comprehensive security program, as well as being prohibited from misrepresenting information practices.
Microsoft had pushed for non-Microsoft entities to create an Internet-wide unified-login system. Examples of sites that used Microsoft Passport were
eBay
eBay Inc. ( , often stylized as ebay) is an American multinational e-commerce company based in San Jose, California, that allows users to buy or view items via retail sales through online marketplaces and websites in 190 markets worldwide. ...
and
Monster.com, but in 2004 those agreements were canceled. In August 2009, Expedia sent notice out stating they no longer support Microsoft Passport / Windows Live ID.
In 2012, Windows Live ID was renamed Microsoft account.
Features
Microsoft account is the website for users to manage their identity. Features of a Microsoft account include:
* updating user's information such as first and last names, address, etc. associated with the account;
* updating user settings, such as preferred language or preferences for email communications;
* changing or resetting user passwords;
* close the account;
* view billing details associated with the accounts.
Integrated with
The following is a list of computer programs and web services that support using Microsoft Account as the credentials required for the authentication process.
*
Windows 8
Windows 8 is a major release of the Windows NT operating system developed by Microsoft. It was Software release life cycle#Release to manufacturing (RTM), released to manufacturing on August 1, 2012, made available for download via Microsoft ...
and later
*
Windows Server 2012
Windows Server 2012, codenamed "Windows Server 8", is the ninth major version of the Windows NT operating system produced by Microsoft to be released under the Windows Server brand name. It is the server version of Windows based on Windows ...
and later
* Windows components
**
Calendar
A calendar is a system of organizing days. This is done by giving names to periods of time, typically days, weeks, months and years. A calendar date, date is the designation of a single and specific day within such a system. A calendar is ...
**
Cortana
**
Groove Music
**
Feedback Hub
**
Mail
The mail or post is a system for physically transporting postcards, letter (message), letters, and parcel (package), parcels. A postal service can be private or public, though many governments place restrictions on private systems. Since the mid ...
**
Movies & TV
**
Microsoft Store
The Microsoft Store (formerly known as the Windows Store) is a digital distribution platform operated by Microsoft. It was created as an app store for Windows 8 as the primary means of distributing Universal Windows Platform apps. With ...
**
Outlook Express
Outlook Express, formerly known as Microsoft Internet Mail and News, is a discontinued email and news client included with Internet Explorer versions 3.0 to 6.0. As such, it was bundled with several versions of Microsoft Windows, from Windows ...
**
People
The term "the people" refers to the public or Common people, common mass of people of a polity. As such it is a concept of human rights law, international law as well as constitutional law, particularly used for claims of popular sovereignty. I ...
**
Windows Messenger
*
Windows Phone 7
Windows Phone 7 (WP7) is the first release of the Windows Phone mobile client operating system, released worldwide on October 21, 2010, and in the United States on November 8, 2010. It runs on the Windows CE 6.0 kernel. It serves as the successo ...
and later
**
Windows Phone Store
*
Bing
Bing most often refers to:
* Bing Crosby (1903–1977), American singer
* Microsoft Bing, a web search engine
Bing may also refer to:
Food and drink
* Bing (bread), a Chinese flatbread
* Bing (soft drink), a UK brand
* Bing cherry, a varie ...
*
Exchange Online
Outlook on the web (formerly Outlook Web App and Outlook Web Access) is a personal information manager web app from Microsoft. It is a web-based version of Microsoft Outlook, and is included in Exchange Server and Exchange Online (a component ...
*
Exchange Online Protection
*
Microsoft Office
Microsoft Office, MS Office, or simply Office, is an office suite and family of client software, server software, and services developed by Microsoft. The first version of the Office suite, announced by Bill Gates on August 1, 1988, at CO ...
*
Microsoft 365
Microsoft 365 (previously called Office 365) is a product family of productivity software, collaboration and Cloud computing, cloud-based Software as a service, services owned by Microsoft. It encompasses online services such as Outlook.com, One ...
(formerly Office 365)
*
Office Online
Microsoft Office, MS Office, or simply Office, is an office suite and family of client software, server software, and services developed by Microsoft. The first version of the Office suite, announced by Bill Gates on August 1, 1988, at COMDE ...
*
OneDrive
Microsoft OneDrive is a file-hosting service operated by Microsoft. First released as SkyDrive in August 2007, it allows registered users to store, share, back-up and synchronize their files. OneDrive also works as the storage Frontend and backe ...
(formerly SkyDrive)
*
Outlook.com (formerly Hotmail)
*
Skype
Skype () was a proprietary telecommunications application operated by Skype Technologies, a division of Microsoft, best known for IP-based videotelephony, videoconferencing and voice calls. It also had instant messaging, file transfer, ...
*
System Center Advisor
*
Visual Studio
Visual Studio is an integrated development environment (IDE) developed by Microsoft. It is used to develop computer programs including web site, websites, web apps, web services and mobile apps. Visual Studio uses Microsoft software development ...
*
Microsoft Azure
Microsoft Azure, or just Azure ( /ˈæʒər, ˈeɪʒər/ ''AZH-ər, AY-zhər'', UK also /ˈæzjʊər, ˈeɪzjʊər/ ''AZ-ure, AY-zure''), is the cloud computing platform developed by Microsoft. It has management, access and development of ...
(formerly Windows Azure)
*
Windows Insider Program
*
Windows Live Messenger
MSN Messenger (also known colloquially simply as MSN), later rebranded as Windows Live Messenger, was a Cross-platform software, cross-platform instant messaging client, instant-messaging client developed by Microsoft. It connected to the now-di ...
*
Windows Movie Maker
Windows Movie Maker (known as Windows Live Movie Maker for the 2009 and 2011 releases) is a discontinued video editing software program by Microsoft. It was first included in Windows Me on September 14, 2000, and in Windows XP on October 25, 200 ...
*
Windows Photo Gallery
*
Xbox network (includes PC Game Pass profile)
Web authentication
On August 15, 2007, Microsoft released the Windows Live ID Web Authentication SDK, enabling web developers to integrate Windows Live ID into their websites running on a broad range of web server platforms - including
ASP.NET
ASP.NET is a server-side web-application framework designed for web development to produce dynamic web pages. It was developed by Microsoft to allow programmers to build dynamic web sites, applications and services. The name stands for Ac ...
(
C#),
Java
Java is one of the Greater Sunda Islands in Indonesia. It is bordered by the Indian Ocean to the south and the Java Sea (a part of Pacific Ocean) to the north. With a population of 156.9 million people (including Madura) in mid 2024, proje ...
,
Perl
Perl is a high-level, general-purpose, interpreted, dynamic programming language. Though Perl is not officially an acronym, there are various backronyms in use, including "Practical Extraction and Reporting Language".
Perl was developed ...
,
PHP
PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. The PHP reference implementation is now produced by the PHP Group. ...
,
Python and
Ruby
Ruby is a pinkish-red-to-blood-red-colored gemstone, a variety of the mineral corundum ( aluminium oxide). Ruby is one of the most popular traditional jewelry gems and is very durable. Other varieties of gem-quality corundum are called sapph ...
.
Support for OpenID
On October 27, 2008, Microsoft announced that it was publicly committed to supporting the
OpenID
OpenID is an open standard and decentralized authentication protocol promoted by the non-profit OpenID Foundation. It allows users to be authenticated by co-operating sites (known as relying parties, or RP) using a third-party identity provi ...
framework, with Windows Live ID becoming an OpenID provider. This would allow users to use their Windows Live ID to sign into any website that supports OpenID authentication. There had been no update on Microsoft's planned implementation of OpenID since August 2009. However, since November 2013 Microsoft has publicly participated in OpenID Connect interoperability testing.
Security vulnerabilities
On June 17, 2007, Erik Duindam, a web developer in the Netherlands, reported a privacy and identity risk, saying a "critical error was made by Microsoft programmers that allows everyone to create an ID for virtually any e-mail address." A procedure was found to allow users to register invalid or currently used e-mail addresses. Upon registration with a valid e-mail address, an e-mail verification link was sent to the user. Before using it however, the user was allowed to change the e-mail address to one that did not exist, or to an e-mail address currently used by someone else. The verification link then caused the Windows Live ID system to confirm the account as having a verified email address. That flaw was fixed two days later, on June 19, 2007.
On April 20, 2012, Microsoft fixed a flaw in Hotmail's password reset system that allowed anyone to reset the password of any Hotmail account. The company was notified of the flaw by researchers at Vulnerability Lab on the same day and responded with a fix within hours — but not before widespread attacks as the exploitation technique spread quickly across the Internet.
On December 3, 2015, a security researcher discovered a vulnerability in the
Adobe Experience Manager (AEM) software used on signout.live.com and reported it to the Microsoft Security Response Center (MSRC). This vulnerability enabled full-administrative access to the AEM Publish nodes'
OSGi
OSGi is an open specification and open source project under the Eclipse Foundation.
It is a continuation of the work done by the OSGi Alliance (formerly known as the Open Services Gateway initiative), which was an open standards organization fo ...
console and made it possible to execute code inside of the
JVM
A Java virtual machine (JVM) is a virtual machine that enables a computer to run Java programs as well as programs written in other languages that are also compiled to Java bytecode. The JVM is detailed by a specification that formally descri ...
through the upload of a custom OSGi bundle. The vulnerability was confirmed to have been resolved on May 3, 2016.
"Remote Code Execution (RCE) on Microsoft's 'signout.live.com'"
/ref>
See also
* Identity management
Identity and access management (IAM or IdAM) or Identity management (IdM), is a framework of policies and technologies to ensure that the right users (that are part of the ecosystem connected to or within an enterprise) have the appropriate acce ...
* Identity management system
* List of single sign-on implementations
These are some of the notable Single Sign-On (SSO) implementations available:
{, class="wikitable sortable" style="text-align: center;"
! Product Name
! Project/Vendor
! License
! Identity management platform
! Description
, -
, Accounts & SSO ...
Other identity services
* Active Directory Federation Services
* OpenID
OpenID is an open standard and decentralized authentication protocol promoted by the non-profit OpenID Foundation. It allows users to be authenticated by co-operating sites (known as relying parties, or RP) using a third-party identity provi ...
* Light-weight Identity
* Yadis
* Windows CardSpace
Identity management
* Liberty Alliance
* OASIS (organization)
The Organization for the Advancement of Structured Information Standards (OASIS; ) is an Trade association, industry consortium that develops Technical standard, technical standards for information technology.
History
OASIS was founded under ...
* Windows Hello
References
Further reading
Creating a Microsoft account
Introduction to Windows Live ID whitepaper
— Provides a brief overview of the Windows Live ID service in the context of Microsoft's overall identity strategy.
Understanding Windows Live Delegated Authentication whitepaper
— Describes how a Web site can use the Windows Live ID Delegated Authentication system to get permission to access users' information on Windows Live services.
Windows Live ID Federation whitepaper
— Describes the concept of identity federation and offers considerable detail about how the Windows Live ID service supports it.
External links
*
{{Microsoft Office
ID
Federated identity
Companies' terms of service
Microsoft