Microsoft is introducing an age assurance API that shares a band rather than a birth date. Apps can distinguish under 10, 10-12, 13-15, 16-17 and adult users.

Quick answer

APIPurpose
GetUserAgeRangeAsyncRetrieve the band.
GetAgeVerificationStatusAsyncRead verification status.
CheckAgeStatusAsyncCheck or launch the flow.

Collect less

Adapting content rarely requires an exact birthday. A band is enough and reduces breach impact. Windows reuses assurance instead of every developer building a form. Signal quality still depends on the Microsoft account.

Handle every state

Developers need paths for missing signals, refusal and pending verification. They should neither block every unknown user nor reconstruct a date. Obligations vary by country, so legal review remains necessary.

An understandable experience

Microsoft says these controls are available in markets including France. Families need to know why verification is requested and how to correct a misclassified account. Repeating checks in every app would defeat the shared mechanism.

Not automatic compliance

The API does not decide consent or retention. Each service must document use, limit logs and provide an appeal path. Used well it reduces collection; used poorly it becomes another opaque barrier.