Faces Matter: Microsoft introduced the picture password security feature with Windows 8, but the aging authentication method is now on its way out. Drawing a few lines around a personal photo was never considered a particularly secure authentication method anyway, which is why Microsoft is now recommending biometrics as an alternative.
A recent Windows update focused on "quality improvements" and security has removed an authentication feature that quite a few users still rely on. Released on July 14, 2026, the KB5101650 update has quietly disabled support for picture password, an image-based sign-in method originally introduced in 2012 with Windows 8 as Microsoft sought to demonstrate the usefulness of touch-enabled devices.
The change affects both currently supported versions of Windows, meaning Windows 10 and Windows 11 users will no longer be able to enroll new picture passwords. Microsoft explained that after installing KB5101650, the picture password option will no longer be available to set up.
Existing picture passwords will continue to work as normal. However, once a user changes or removes their existing sign-in method, they will no longer be able to configure a new picture password. Microsoft highlights Windows Hello, PINs, and biometric authentication as more secure alternatives to picture passwords.

Redmond explains the removal of picture password support as a way to improve security on the Windows platform. The Windows 8-era feature was – and still is – essentially a limited implementation of the Draw a Secret password scheme, which replaces traditional alphanumeric passwords with a custom "picture" drawn on a grid.
Users could choose a personal photo or image and then set up a series of gestures (circles, straight lines, and taps) in a specific sequence and location on the selected image. Over time, picture passwords proved rather unsecure and prone to being "cracked," much like traditional passwords consisting of numbers and letters.
Microsoft has long tried to steer users away from weak authentication methods, both on Windows and in its other software products. The company now recommends passkeys above other authentication methods, although users cannot yet use a passkey to sign in to a local Windows account.
Besides removing picture passwords, the KB5101650 update includes a few other security-related changes. The package expands the pool of machines eligible to receive the new Secure Boot certificates, updates the cURL tool to version 8.21.0, and adds support for SHA-2 certificate thumbprints to the Remote Desktop Protocol.