Skip to main content
Self-Hosting & Privacy

Is Microsoft's Password Manager Good Enough?

Microsoft's password manager left Authenticator in 2025 and now lives in Edge. An honest, current decision guide: what the free built-in tool does well, exactly where it breaks (cross-browser, sharing, mobile passkeys), and who should reach for a dedicated manager instead.

milanbuha00August 3, 20267 min read
ShareXin
Is Microsoft's Password Manager Good Enough?

You opened Microsoft Authenticator to grab a password and it was gone — no vault, no autofill, just 2FA codes and a note about Edge. Or you set up a new Windows laptop and Edge cheerfully offered to save every login you typed. Either way the question is the same: is the thing Microsoft already gives you for free actually good enough, or do you need to go pay for a real password manager?

The honest answer is "it depends, and it changed a lot in 2025." Microsoft spent last year quietly moving its password features around, and most guides you'll find still describe a setup that no longer exists. So here is what Microsoft's built-in manager really is today, exactly what it does well, and the specific points where it breaks.

TL;DR

  • Microsoft's password manager is no longer in Authenticator. In 2025 passwords moved to Microsoft Password Manager, surfaced through Edge and synced to your Microsoft account.
  • It's genuinely fine for a one-person, all-Windows, all-Edge setup: free, encrypted, with breach monitoring and a password generator built in.
  • It breaks the moment you go cross-browser, cross-platform, or need to share a login — there's no proper sharing, and passkey sync is Windows-only.
  • Authenticator still matters — it kept your 2FA codes and Entra passkeys; it just stopped storing passwords.
  • If you live in more than one browser or on an iPhone, a dedicated manager is worth it; if you want to own the vault, self-hosting is the ceiling.

KEY-STAT: 3 phases — Microsoft removed Authenticator's password features in three steps across mid-2025 — first new saves, then autofill, then all access

What "Microsoft's password manager" even is in 2026

This is where almost everyone gets confused, because the answer moved. For years the advice was "save your passwords in Microsoft Authenticator." That's dead. Per Microsoft's own autofill-changes support page, the app stopped accepting new saved passwords in June 2025, autofill stopped in July 2025, and by mid-August 2025 saved personal info was no longer accessible in Authenticator at all.

Your passwords weren't deleted — they were synced to your Microsoft account and surfaced through Microsoft Edge. So "Microsoft's password manager" today means one thing: the vault built into Edge and Windows, called Microsoft Password Manager. That's the product this article judges.

Note

Authenticator didn't die — it just narrowed. It still generates your two-factor 2FA codes and still stores Entra passkeys for work sign-ins. Only the password-storage and autofill piece went away. If your codes are fine, nothing about your logins broke; they just live in Edge now.

What it actually does well

Give Microsoft credit: the built-in manager is a real tool, not a toy. It's free, it's already on every Windows PC, and there's nothing to install if you use Edge.

Passwords are encrypted in transit and at rest when sync is on, tied to your Microsoft account. It ships a password generator, and its breach-checking feature, Password Monitor, compares your saved logins against known-leaked credential databases and flags weak or reused entries with a one-click link to change them. That's the same category of protection the paid managers charge for.

As of Edge 142 in November 2025, it also saves and syncs passkeys through your Microsoft account, so a passkey you create on one Windows PC follows you to the next. For a single person living inside Windows and Edge, that's a coherent, zero-effort setup that covers the basics competently.

Tip

If you're staying on the built-in manager, do two things today: set Edge as your autofill provider in Windows settings so logins actually fill, and open Edge → Settings → Profiles → Passwords and turn on Password Monitor. The breach alerts are the single most valuable feature here and they're off by default for many users.

Where it breaks

The cracks show up the instant your life isn't 100% Windows-and-Edge.

Cross-browser is second-class. Your passwords live in Edge. Use Chrome or Firefox and you're installing the Microsoft autofill extension and hoping — it's not the seamless, everywhere experience a dedicated manager gives you. If you've already decided to leave Edge for privacy reasons, as weighed in our browser privacy comparison, the built-in manager becomes a reason to keep a browser you were trying to drop.

There's no real sharing. Dedicated managers let you share a single login with a partner or a team member without either of you seeing the raw password, and revoke it later. Microsoft's built-in vault has no equivalent. For a household or a small team, that gap alone is disqualifying.

Passkey sync is narrow. The November 2025 passkey launch is real but limited: per Microsoft's Edge passkey announcement, sync is Windows-only, for personal Microsoft accounts only (not Entra work accounts), and not available on mobile. The plugin to use those passkeys outside Edge was still "coming soon" at launch. If you're on an iPhone or a Mac, this headline feature doesn't reach you yet.

Warning

Everything here is tied to your Microsoft account, and leaving isn't a one-click affair. To move to another manager you export a CSV from Edge and import it elsewhere — and note that any payment info Authenticator once held was deleted, not migrated. Decide before you're deep in, not after.

Microsoft built-in vs a dedicated manager: the honest matrix

Here's the whole decision on one screen. "Self-host" means running your own vault, like Bitwarden's open-source core (Vaultwarden) on a home server.

What mattersMicrosoft built-inDedicated (e.g. Bitwarden)Self-hosted (Vaultwarden)
CostFreeFree tier or ~$10/yrFree (your hardware)
Works everywhereWindows + Edge firstAll OSes + all browsersAll OSes + all browsers
Cross-browser autofillExtension, clunkyNative, seamlessNative, seamless
Secure sharingNoYesYes
Passkey syncWindows/MSA onlyCross-platformCross-platform
Breach monitoringYes (Password Monitor)YesManual/add-on
You own the dataNo (Microsoft account)No (their cloud)Yes (your server)

The full head-to-head on the dedicated options — Bitwarden, 1Password, KeePassXC and Dashlane — is in our dedicated password manager comparison. The pattern is clear: the built-in manager wins on zero-effort convenience and loses on portability and control.

Who it's genuinely fine for

If you're one person, on Windows, using Edge as your only browser, with low-stakes logins and no interest in setup, the built-in manager is honestly fine. It's free, encrypted, and it warns you about breaches — which already puts you ahead of anyone reusing the same password everywhere. Don't let anyone shame you off it for a handful of forum and shopping accounts.

Who should use something else

Switch to a dedicated manager if any of these describe you: you use more than one browser, you mix Windows with an iPhone, Android or Mac, you need to share logins with family or a team, or you simply don't want your entire credential life anchored to a Microsoft account you might one day leave. Each of those is a wall the built-in tool hits and a dedicated manager doesn't.

What I use, and why

When I first set up my main Windows machine I ran exactly this stack — Edge saving passwords, Authenticator handling 2FA — and it was fine until it wasn't. The 2025 migration is what pushed me: watching a "your passwords are moving" banner appear made the account lock-in obvious in a way it hadn't been before.

In my homelab I now run Vaultwarden, the lightweight self-hosted Bitwarden server, in a container on Proxmox — the same box described in our homelab build guide. It syncs to every browser and phone I own, lets me share a vault with family, and the data sits on hardware I control instead of someone's cloud. That's the ceiling. Microsoft's built-in manager is the floor — a perfectly reasonable floor, but a floor. Knowing which one you actually need is the whole decision.

Frequently asked questions

Where did my passwords go in Microsoft Authenticator?

They were synced to your Microsoft account and are now accessed through Microsoft Edge, not the Authenticator app. Microsoft removed password storage from Authenticator in phases through mid-2025; the credentials themselves weren't lost, but any payment info the app stored was deleted rather than moved.

Is Microsoft's password manager safe?

For everyday use, yes — passwords are encrypted in transit and at rest under your Microsoft account, and Password Monitor warns you about breached or reused logins. Its weaknesses are about scope and portability, not encryption: no secure sharing, and a vault tied to one ecosystem.

Can I use Microsoft's password manager on Chrome or an iPhone?

Partly. On Chrome or Firefox you can install Microsoft's autofill extension, but it's clunkier than a dedicated manager's native app. On iPhone the experience is thin, and the November 2025 passkey sync is Windows-only — so a cross-platform user is better served elsewhere.

Microsoft password manager or Bitwarden?

Choose the built-in manager if you're a single Windows-and-Edge user who wants zero setup. Choose Bitwarden (or another dedicated manager) if you span multiple browsers or devices, need to share logins, or want cross-platform passkeys — the trade-offs are laid out in our dedicated comparison.

Related stories

More from Self-Hosting & Privacy

Stay in the loop

Get the latest articles delivered to your inbox. No spam, unsubscribe anytime.

Read next

Is Opera's Password Manager Safe to Rely On?

Opera's built-in password manager saves and autofills your logins, but it's the weakest of the mainstream browser vaults — no password generator and no breach monitoring. An honest audit of what it protects, whether it's safe to rely on, and the clean CSV path to export your passwords out.

Continue Reading