Microsoft account

Microsoft account logo

A Microsoft account or MSA[1] (previously known as Microsoft Passport,[2] .NET Passport, and Windows Live ID) is a single sign-on personal user account for Microsoft customers to log in to consumer[3][4] Microsoft services (like Outlook.com), devices running on one of Microsoft's current operating systems (e.g. Microsoft Windows computers and tablets, Xbox consoles), and Microsoft application software (including Visual Studio).

Overview

Microsoft account allows users to sign into websites that support this service using a single set of credentials - these usernames are in the same form as an email address. Microsoft account offers a user two different methods for creating an account:

  1. Use an existing e-mail address: Users are able to use their own valid e-mail address to sign up for a Microsoft account. The service turns the requesting user's e-mail address into a Microsoft account ID. Users may also choose a password of their own choice.
  2. Sign up for a Microsoft e-mail address: Users can also sign up for a free e-mail account through Outlook.com or MSN, with Microsoft's webmail services designated domains (i.e. @hotmail.com, @outlook.com, @msn.com[a]) that can be used as a Microsoft account to sign into other Microsoft account-enabled websites.

The domains @live.com and @passport.com, as well as other domains are no longer offered, but existing accounts are maintained.

Microsoft websites, services, and apps such as Bing, MSN and Xbox Live use Microsoft account as a means of identifying users. There are also several other companies that use it, such as the Hoyts website which is hosted by NineMSN.

Windows XP and later has an option to link a local Windows user account with a Microsoft account, thus automatically logging users in to their Microsoft account whenever a service is accessed. Starting with Windows 8 and Windows Server 2012, Windows allows users to directly authenticate into their PCs using their Microsoft account rather than a local or domain user.[5]

Login methods

In addition to using an account password, users can login to their Microsoft account by accepting a mobile notification sent to a mobile device with Microsoft Authenticator, a FIDO2 security token or by using Windows Hello.[6] Users can also set up two-factor authentication by getting a time-based, single-use code by text, phone call or using an authenticator app.

Technical details

Users' credentials are not checked by Microsoft account-enabled websites, but by a Microsoft account authentication server. A new user signing into a Microsoft account-enabled website is first redirected to the nearest authentication server, which asks for username and password over an SSL connection. The user may select to have their computer remember their login: a newly signed-in user has an encrypted time-limited cookie stored on their computer and receives a triple DES encrypted ID-tag that previously has been agreed upon between the authentication server and the Microsoft account-enabled website. This ID-tag is then sent to the website, upon which the website plants another encrypted HTTP cookie in the user's computer, also time-limited. As long as these cookies are valid, the user is not required to supply a username and password. If the user actively logs out of their Microsoft account, these cookies will be removed.

Relationship with work or school account

Microsoft also offer a work or school account which are set up by an administrator as part of an organization. These accounts are separate from Microsoft accounts (which is also called personal account) and cannot be merged, but may be used side-by-side by a user.[7][8] A work or school account uses the Azure Active Directory domain platform.[9]

History

Microsoft Passport, the predecessor to Windows Live ID, was originally positioned as a single sign-on service for all web commerce. Microsoft Passport received much criticism. A prominent critic was Kim Cameron, the author of The Laws of Identity,[10] who questioned Microsoft Passport in its violations of those laws. He then joined Microsoft in 1999 after his company was acquired and was its chief architect of access and identity until his 2019 retirement, helping to address those violations in the design of the Microsoft Account identity meta-system. As a consequence, Microsoft Accounts are not positioned as the single sign-on service for all web commerce, but as one choice of many among identity systems.

In December 1999, Microsoft neglected to pay their annual $35 "passport.com" domain registration fee to Network Solutions. The oversight made Hotmail, which used the site for authentication, unavailable on December 24. A Linux consultant, Michael Chaney, paid it the next day (Christmas), hoping it would solve this issue with the downed site. The payment resulted in the site being available the next morning.[11] In Autumn 2003, a similar good Samaritan helped Microsoft when they missed payment on the "hotmail.co.uk" address, although no downtime resulted.[12]

In 2001, the Electronic Frontier Foundation's staff attorney Deborah Pierce criticized Microsoft Passport as a potential threat to privacy after it was revealed that Microsoft would have full access to and usage of customer information.[13] The privacy terms were quickly updated by Microsoft to allay customers' fears.

In July and August 2001, the Electronic Privacy Information Center and a coalition of fourteen leading consumer groups filed complaints[14] with the Federal Trade Commission (FTC) alleging that the Microsoft Passport system violated Section 5 of the Federal Trade Commission Act (FTCA), which prohibits unfair or deceptive practices in trade.[15] In August 2002, Microsoft agreed to settle the resulting FTC charges. As part of the settlement, Microsoft was required to implement and maintain a comprehensive security program, as well as being prohibited from misrepresenting information practices.[16]

Microsoft had pushed for non-Microsoft entities to create an Internet-wide unified-login system.[17] Examples of sites that used Microsoft Passport were eBay and Monster.com, but in 2004 those agreements were canceled.[18] In August 2009, Expedia sent notice out stating they no longer support Microsoft Passport / Windows Live ID.

In 2012, Windows Live ID was renamed Microsoft account.[19][20]

Features

Microsoft account is the website for users to manage their identity. Features of a Microsoft account include:

  • updating user's information such as first and last names, address, etc. associated with the account;
  • updating user settings, such as preferred language or preferences for email communications;
  • changing or resetting user passwords;
  • close the account;
  • view billing details associated with the accounts.

Integrated with

The following is a list of computer programs and web services that support using Microsoft Account as the credentials required for the authentication process.

Web authentication

On August 15, 2007, Microsoft released the Windows Live ID Web Authentication SDK, enabling web developers to integrate Windows Live ID into their websites running on a broad range of web server platforms - including ASP.NET (C#), Java, Perl, PHP, Python and Ruby.[21][22]

Support for OpenID

On October 27, 2008, Microsoft announced that it was publicly committed to supporting the OpenID framework, with Windows Live ID becoming an OpenID provider.[23] This would allow users to use their Windows Live ID to sign into any website that supports OpenID authentication. There had been no update on Microsoft's planned implementation of OpenID since August 2009,[24] however since November 2013 Microsoft have publicly participated in OpenID Connect interoperability testing.[25][26]

Security vulnerabilities

On June 17, 2007, Erik Duindam, a web developer in the Netherlands, reported a privacy and identity risk, saying a "critical error was made by Microsoft programmers that allows everyone to create an ID for virtually any e-mail address."[27] A procedure was found to allow users to register invalid or currently used e-mail addresses. Upon registration with a valid e-mail address, an e-mail verification link was sent to the user. Before using it however, the user was allowed to change the e-mail address to one that did not exist, or to an e-mail address currently used by someone else. The verification link then caused the Windows Live ID system to confirm the account as having a verified email address. That flaw was fixed two days later, on June 19, 2007.[28]

On April 20, 2012, Microsoft fixed a flaw in Hotmail's password reset system that allowed anyone to reset the password of any Hotmail account. The company was notified of the flaw by researchers at Vulnerability Lab on the same day[29] and responded with a fix within hours — but not before widespread attacks as the exploitation technique spread quickly across the Internet.[30][31]

On December 3, 2015, a security researcher discovered a vulnerability in the Adobe Experience Manager (AEM) software used on signout.live.com and reported it to the Microsoft Security Response Center (MSRC). This vulnerability enabled full-administrative access to the AEM Publish nodes' OSGi console and made it possible to execute code inside of the JVM through the upload of a custom OSGi bundle. The vulnerability was confirmed to have been resolved on May 3, 2016.[32]

See also

Other identity services

Identity management

References

  1. ^ "Upcoming changes to Windows 10 Insider Preview builds [UPDATED 6/22]". Windows Experience Blog. June 19, 2015. Retrieved April 17, 2016.
  2. ^ Microsoft Passport: Streamlining Commerce and Communication on the Web
  3. ^ "What's the difference between a personal Microsoft account and a work or school account?". TECHCOMMUNITY.MICROSOFT.COM. Retrieved October 4, 2023.
  4. ^ "What is my user ID and why do I need it for Office 365 for business? - Microsoft Support". support.microsoft.com. Retrieved October 4, 2023.
  5. ^ "Windows 8: The official review". PCWorld. Retrieved November 24, 2023.
  6. ^ Warren, Tom (November 20, 2018). "You can now sign into a Microsoft Account without a password using a security key". The Verge. Vox Media. Retrieved November 27, 2018.
  7. ^ "Why you need a Microsoft account, or work or school account with Microsoft 365 or Office - Microsoft Support". support.microsoft.com. Retrieved November 24, 2023.
  8. ^ "Which account do you want to use? - Microsoft Support". support.microsoft.com. Retrieved November 24, 2023.
  9. ^ "What's the difference between a personal Microsoft account and a work or school account?". TECHCOMMUNITY.MICROSOFT.COM. Retrieved November 24, 2023.
  10. ^ Cameron, Kim (May 2005). "The Laws of Identity". Microsoft. Retrieved July 9, 2018.
  11. ^ Chaney, Michael (January 27, 2000). "The Passport Payment". Retrieved November 3, 2007.
  12. ^ Richardson, Tim (November 6, 2003). "Microsoft forgets to renew hotmail". The Register. Retrieved November 3, 2007.
  13. ^ Privacy terms revised for Microsoft Passport
  14. ^ "Complaint and Request for Injunction, Request For Investigation and for Other Relief" (PDF). Electronic Privacy Information center. July 26, 2001.
  15. ^ EPIC: Microsoft Passport Investigation Docket, http://epic.org/privacy/consumer/microsoft/passport.html
  16. ^ "Microsoft Settles FTC Charges Alleging False Security and Privacy Promises". Federal Trade Commission. August 8, 2002. Retrieved May 31, 2024.
  17. ^ Microsoft had pushed for non-Microsoft entities
  18. ^ Microsoft Passport Dumped By Ebay
  19. ^ Windows 8 Consumer Preview - FAQ
  20. ^ "What is a Microsoft account?". Microsoft. Retrieved August 2, 2012. Microsoft account" is the new name for what used to be called a "Windows Live ID.
  21. ^ LiveSide.net: Windows Live ID Web Authentication Is Final Archived October 23, 2008, at the Wayback Machine July 16, 2007
  22. ^ Live ID Team blog announcement: Windows Live ID Web Authentication SDK for Developers Is Released [dead link] July 15, 2007
  23. ^ Windows Live ID Becomes an OpenID Provider
  24. ^ Windows Live ID OpenID Status Update
  25. ^ "Microsoft publicly participates in OpenID Connect interoperability testing".
  26. ^ "Microsoft 365 documentation".
  27. ^ "Windows Live ID security breached" on erikduindam.com
  28. ^ Microsoft Windows Live Flaw Opened Door to Scammers Archived May 18, 2008, at the Wayback Machine
  29. ^ "Microsoft MSN Hotmail - Password Reset & Setup Vulnerability". Archived from the original on January 6, 2019. Retrieved April 28, 2012.
  30. ^ Twitter / @msftsecresponse: On Friday we addressed a reset function incident to help protect Hotmail customers, no action needed
  31. ^ Bright, Peter (April 27, 2012). "Microsoft patches major Hotmail 0-day flaw after apparently widespread exploitation". Ars Technica. Archived from the original on October 6, 2012. Retrieved October 21, 2012.
  32. ^ "Remote Code Execution (RCE) on Microsoft's 'signout.live.com'"
  1. ^ @msn.com addresses are only offered to MSN Dial-up and MSN Premium customers

Further reading

Read other articles:

Ini adalah nama Minahasa, marganya adalah Tengker Nagita SlavinaNagita dalam acara Ini TalkshowLahirNagita Slavina Mariana Tengker17 Februari 1988 (umur 36)Jakarta, IndonesiaKebangsaanIndonesiaNama lainNagita SlavinaAlmamaterUniversitas Nasional AustraliaPekerjaanAktrisModelPresenterPenyanyiProduser FilmBintang IklanPengusahaTahun aktif2000–sekarangDikenal atasDi Sini Ada SetanSuami/istriRaffi Ahmad ​(m. 2014)​Anak Rafathar Malik Ahmad Rayyanza Ma...

 

December 1985 volcanic eruption in Colombia Armero tragedyLahars covering the town of ArmeroDateNovember 13, 1985LocationNevado del Ruiz, Tolima, ColombiaCoordinates04°57′48″N 74°54′20″W / 4.96333°N 74.90556°W / 4.96333; -74.90556TypeLaharsCauseVolcanic eruptionDeaths23,000+Non-fatal injuries5,000 (approximate)Missing3,300Property damage$1 billion The Armero tragedy (Spanish: Tragedia de Armero [tɾaˈxeðja ðe aɾˈmeɾo]) occurred following the e...

 

Questa voce sull'argomento calciatori spagnoli è solo un abbozzo. Contribuisci a migliorarla secondo le convenzioni di Wikipedia. Segui i suggerimenti del progetto di riferimento. Israel Bascón Nazionalità  Spagna Altezza 172 cm Calcio Ruolo Centrocampista Termine carriera 2016 Carriera Giovanili 2002-2004 Betis Squadre di club1 2004-2009 Betis B87 (8)2005-2011 Betis38 (1)2006-2007→  Mérida17 (0)2011-2013 Xerez44 (3)2013→  GAS Veria0 (0)2013-20...

Alonzo Mourning Alonzo Mourning ai Miami Heat nel 2007 Nazionalità  Stati Uniti Altezza 208 cm Peso 109 kg Pallacanestro Ruolo Centro Termine carriera 2009 Hall of fame Naismith Hall of Fame (2014)FIBA Hall of Fame (2019) Carriera Giovanili Indian River High School1988-1992 Georgetown Hoyas Squadre di club 1992-1995 Charlotte Hornets215 (4.569)1995-2003 Miami Heat407 (8.045)2003-2004 N.J. Nets30 (283)2004-2005 Toronto Raptors0 (0)2005-2008 Miami ...

 

Liga Bank MandiriMusim2004JuaraPersebaya Surabaya (gelar LI kedua) (gelar divisi teratas keenam)Liga ChampionsPersebaya SurabayaPSM MakassarPencetak golterbanyak Ilham Jaya Kesuma (Persita Tangerang) (22 gol)Rata-ratajumlah penonton40,000← 2003 2005 → Divisi Utama Liga Indonesia 2004 adalah musim kesepuluh Liga Indonesia. Terdapat 18 tim yang ikut berlaga. Pada musim 2004 Persebaya Surabaya berhasil merengkuh gelar juara. Liga ini dimulai dari tanggal 4 Januari 2004 sampai 23 Desember 200...

 

Cet article est une ébauche concernant un homme politique. Vous pouvez partager vos connaissances en l’améliorant (comment ?) selon les recommandations des projets correspondants. Pour les articles homonymes, voir Ali ben Yusuf. Ali ibn Jusufas ZakarijaBiographieDécès 1458Activité Homme politiquemodifier - modifier le code - modifier Wikidata `Alî ben Yûsuf[1] succéda à son oncle[2] Abû Zakarîyâ Yahyâ comme vizir et régent watasside du sultan mérinide Abû Muhammad `Abd...

Space in Paris Rosiers–Joseph Migneret Garden The Rosiers–Joseph Migneret Garden is a green space located in the 4th arrondissement of Paris. Location The garden is located between the rue des Francs-Bourgeois and the rue des Rosiers in the heart of the historic quarter of Le Marais. It can be accessed either by the courtyard of the hôtel de Coulanges at 35-37, rue des Francs-Bourgeois, or by number 10, rue des Rosiers. The garden entrance at 35-37 rue des Franc-Bourgeois, Hôtel de Coul...

 

Северный морской котик Самец Научная классификация Домен:ЭукариотыЦарство:ЖивотныеПодцарство:ЭуметазоиБез ранга:Двусторонне-симметричныеБез ранга:ВторичноротыеТип:ХордовыеПодтип:ПозвоночныеИнфратип:ЧелюстноротыеНадкласс:ЧетвероногиеКлада:АмниотыКлада:Синапси...

 

土库曼斯坦总统土库曼斯坦国徽土库曼斯坦总统旗現任谢尔达尔·别尔德穆哈梅多夫自2022年3月19日官邸阿什哈巴德总统府(Oguzkhan Presidential Palace)機關所在地阿什哈巴德任命者直接选举任期7年,可连选连任首任萨帕尔穆拉特·尼亚佐夫设立1991年10月27日 土库曼斯坦土库曼斯坦政府与政治 国家政府 土库曼斯坦宪法 国旗 国徽 国歌 立法機關(英语:National Council of Turkmenistan) ...

Questa voce o sezione sull'argomento diritto internazionale non cita le fonti necessarie o quelle presenti sono insufficienti. Puoi migliorare questa voce aggiungendo citazioni da fonti attendibili secondo le linee guida sull'uso delle fonti. Monete di Jersey con l'iscrizione Bailiwick of Jersey, baliato di Jersey Un baliato o baliaggio (bailliages nell'espressione originale in lingua francese) è l'area di giurisdizione di un balivo (bailli); il siniscalcato (sénéchaussée) invece è...

 

 本表是動態列表,或許永遠不會完結。歡迎您參考可靠來源來查漏補缺。 潛伏於中華民國國軍中的中共間諜列表收錄根據公開資料來源,曾潛伏於中華民國國軍、被中國共產黨聲稱或承認,或者遭中華民國政府調查審判,為中華人民共和國和中國人民解放軍進行間諜行為的人物。以下列表以現今可查知時間為準,正確的間諜活動或洩漏機密時間可能早於或晚於以下所歸�...

 

Nort-sur-Erdre Le bâtiment voyageurs côté cour. Localisation Pays France Commune Nort-sur-Erdre Adresse boulevard de la Gare 44390 Nort-sur-Erdre Coordonnées géographiques 47° 26′ 31″ nord, 1° 30′ 12″ ouest Gestion et exploitation Propriétaire SNCF Exploitant SNCF Code UIC 87481598 Site Internet La gare de Nort-sur-Erdre, sur le site officiel de SNCF Gares & Connexions Services TER Pays de la Loire Caractéristiques Ligne(s) Nantes-Orléans �...

Indian royal title This article is about the title of the Maratha head of state. For the Telugu film, see Chatrapathi (2005 film). This article may need to be rewritten to comply with Wikipedia's quality standards. You can help. The talk page may contain suggestions. (May 2024) Chatrapati of the MarathasMarāṭhyānche ChatrapatīFederalSealFirst to reignShivaji I6 June 1674 – 3 April 1680 DetailsStyleHis MajestyFirst monarchShivaji ILast monarchPratap SinghFormation...

 

Public university in Harderwijk, Dutch Republic (now the Netherlands) from 1648-1811 This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: University of Harderwijk – news · newspapers · books · scholar · JSTOR (January 2021) (Learn how and when to remove this message) Harderwijk, tower: het Linnaeustorentje The Un...

 

Ethiopian politician (born 1981) This article has multiple issues. Please help improve it or discuss these issues on the talk page. (Learn how and when to remove these template messages) This biography of a living person needs additional citations for verification. Please help by adding reliable sources. Contentious material about living persons that is unsourced or poorly sourced must be removed immediately from the article and its talk page, especially if potentially libelous.Find sources:&...

This article needs additional citations for verification. Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed.Find sources: LGBT rights in North Korea – news · newspapers · books · scholar · JSTOR (October 2016) (Learn how and when to remove this message) LGBT rights in North KoreaNorth KoreaStatusNever criminalisedMilitaryCelibacy required during initial 10 years of service (for a...

 

Fictional character from the Fox series Glee For the judge, see J. Blaine Anderson. Fictional character Blaine AndersonGlee characterDarren Criss as Blaine Anderson in GleeFirst appearanceNever Been Kissed (2010)Last appearanceDreams Come True (2015)Created byRyan MurphyBrad FalchukIan BrennanPortrayed byDarren CrissIn-universe informationOccupation Student Glee club director Actor FamilyPam Anderson (mother)Cooper Anderson (brother)Unnamed daughterSpouseKurt HummelSignificant otherDave Karof...

 

City in West Yorkshire, England This article is about the local government district. For the settlement, see Wakefield. For other cities called Wakefield, see Wakefield (disambiguation). City and Metropolitan borough in EnglandCity of WakefieldCity and Metropolitan boroughWakefieldFrom left to rightTop: Sandal Castle in Sandal and Knottingley Town HallUpper: Castleford Civic Centre and Pontefract Old Town HallBottom: Ossett Town Hall and Wakefield Old Town Hall Coat of arms of Wakefield Metro...

Legislative branch of the state government of Alabama Alabama LegislatureTypeTypeBicameral HousesSenate House of RepresentativesTerm limitsNoneHistoryNew session startedMarch 7, 2023LeadershipPresident of the Senate (Lieutenant Governor)Will Ainsworth (R) since January 14, 2019 President pro tempore of the SenateGreg Reed (R) since February 2, 2021 Senate Majority LeaderSteve Livingston (R) since October 30, 2023 Senate Minority LeaderBobby Singleton (D) since January 8, 2019 ...

 

This article is about the city in Japan. For the prefecture with the same name where this city is located, see Kagoshima Prefecture. For other uses, see Kagoshima (disambiguation). Core city in Kyushu, JapanKagoshima 鹿児島市Core cityKagoshima CityFrom top, left to right: Senga-en Garden, Saigō Takamori statue, Kagoshima Aquarium, Ohara Festival, Tenmonkan, Hirakawa Zoological Park FlagSealNickname: City of IshinLocation of Kagoshima in Kagoshima PrefectureKagoshima Show map of...