Windows 11 will now warn you when you copy and paste your system password

Windows 11 on a laptop
(Image credit: Unsplash)

Microsoft is launching a new anti-phishing measure which will issue a warning to users when they paste their system credentials into documents and websites.

The new feature, available now in preview is part of the Windows 11 Enhanced Phishing Protection, which was released with Windows 11 version 22H2, and is meant to protect your Windows and Active Directory passwords from falling into the wrong hands.

Malware and phishing campaigns can be used to acquire an organization's log in details and deal all sorts of damage, from stealing sensitive data to sell on the dark web, to gaining insights into business partners and spread their attack further.

Enhanced Phishing Protection

Initially, the Enhanced Phishing Protection only warned users when they manually typed their password into a document or website, but since many use password managers to store their credentials, they are able to copy and paste them instead.

However, with the Windows Insider Preview Build 23506, copying and pasting your Windows password is now detected. In the build's release notes, Microsoft says that, "We are trying out a change starting with this build where users... will see a UI warning on unsafe password copy and paste, just as they currently see when they type in their password."

To enable the feature, users of the preview build need to navigate to Windows Security under App & browser control > Reputation-based protection > Phishing protection and enable all checkboxes.

When you then copy and paste your Windows password into a website, a dialog box will appear warning you of the dangers of password reuse, and recommend that you change your local Windows account password with link to take you straight to the settings to do this. Or, you can choose to dismiss the warning.

BleepingComputer notes, however, that the feature does not appear to work when the password is pasted into certain third-party applications, such as Notepad2 and Notepad++, which may be commonly used to insert credentials. 

The warning also does not work if you are using the company's passwordless login feature, Windows Hello, where biometrics or a PIN are used to grant you access instead. A password must be used to login to Windows so that it is stored in the system memory and therefore referenced against pasted text. 

TOPICS
Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft authentication system spoofed via phishing attack
Microsoft Teams
Microsoft Teams is finally introducing a spam and phishing alert - here’s what you need to know
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Acer Aspire 14 AI laptop display showing the Windows 11 login screen
Shock, horror – I’m not going to argue with Microsoft’s latest bit of nagging in Windows 11, as this pop-up is justified
Hacker Typing
This devious two-step phishing campaign uses Microsoft tools to bypass email security
Phone scammer
Microsoft thinks it could stop this dangerous scam forever
Latest in Pro
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
AI quantization
What is AI quantization?
US flags
US government IT contracts set to be centralized in new Trump order
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Latest in News
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
Ncuti Gatwa as The Fifteenth Doctor in Doctor Who
Disney+ drops new trailer for Doctor Who season 2 that promises an epic adventure across time and space
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired