Microsoft is warning about active attacks that use fake passkey, MFA and single sign-on support requests to take over Microsoft 365 accounts. The approach often starts with a phone call or text from someone pretending to be IT support, then leads the victim into a convincing Microsoft-style sign-in or device-code flow.
The important point is that passkeys themselves are not being broken. Microsoft says the passkey theme is being used as a social-engineering pretext to steal sessions, register attacker-controlled authentication methods and reach data in SharePoint, OneDrive and Exchange Online.
For UK SMEs, the practical response is to warn staff, verify unexpected IT requests through a known support channel and review Microsoft Entra controls around authentication registration, device code and risky sign-ins.
What has Microsoft found?
Microsoft Security Research says it is tracking active cloud intrusions in which identity-focused social engineering is followed by persistence and data collection across Microsoft 365. Microsoft published the research on 9 September 2026 and says the activity has been observed since May.
The attack sequence can include unusual sign-ins, the registration of new authentication methods, Microsoft Graph reconnaissance, SharePoint and OneDrive downloads and access to Exchange Online email content.
Microsoft describes the activity in its passkey-themed social-engineering research. It says the recurring sequence is more useful to defenders than relying on any single domain or IP address because attacker infrastructure changes quickly.
How does the passkey phishing scam work?
The scam often begins with someone claiming to be from the organisation's IT helpdesk and saying that a passkey, MFA or SSO setting needs urgent attention. The user may receive the contact on a personal phone number and be sent a link by SMS to a site that closely resembles a Microsoft sign-in page.
In some incidents, already-compromised Microsoft 365 accounts have also been used to send similar messages through Microsoft Teams. That makes the request more convincing because it appears to come from a trusted colleague inside the organisation.
Microsoft says “passkey enrollment is often not the actor’s true objective.” Instead, the passkey language helps persuade the user to complete an adversary-in-the-middle sign-in or a device-code authentication flow that gives the attacker access.
This is closely related to the technique explained in our guide to adversary-in-the-middle attacks.
Does this mean passkeys are unsafe?
No. The Microsoft warning does not show attackers breaking FIDO2 passkeys or defeating their underlying cryptography. In fact, Microsoft continues to recommend phishing-resistant MFA such as FIDO2 passkeys and Windows Hello for Business.
The attack works around the security technology by manipulating the person. A fake technician may tell the user that a passkey needs to be enrolled, repaired or synchronised, but then guide them through a different authentication process that grants the attacker a valid session.
That distinction matters because businesses should not respond by abandoning passkeys. Our guide to what passkeys are and whether businesses should use them explains why they remain a stronger option than passwords and weaker MFA methods when properly deployed.
How can device-code phishing bypass normal MFA?
Device-code phishing tricks a user into approving a sign-in that was initiated by the attacker. The victim may be sent to a legitimate Microsoft authentication page and asked to enter a code. Because the Microsoft page itself is genuine, the process can feel trustworthy even though the code belongs to an attacker-controlled session.
Once the user completes the authentication, the attacker's client receives the resulting token and can access whatever resources that identity is allowed to use.
Microsoft's current Entra guidance says device code flow should be allowed only where it is genuinely required and recommends blocking device code flow wherever possible. Businesses should review existing use before enforcing a block so legitimate Teams Rooms, devices or legacy workflows are not disrupted.
What can attackers do after they get into Microsoft 365?
Microsoft has observed attackers turning a temporary sign-in into persistent access, then searching Microsoft 365 for useful data. One of the first actions can be registering a new phone number, Authenticator app or other MFA method under the attacker's control.
Microsoft then observed Microsoft Graph queries used to discover applications, permissions and content. SharePoint and OneDrive were used to locate and download files, while some intrusions extended into Exchange Online email and attachments.
The collection can be deliberately slow. Microsoft says some activity continued for hours or days and often stayed below 1,000 files or emails in any one-hour period. That makes it important to look at the sequence of identity changes and data access rather than expecting one spectacular alert.
What warning signs should staff look for?
An unexpected request to change or re-register MFA should always be verified independently, even if the caller knows the employee's name, job title or company details.
- A phone call or text claiming that a passkey, MFA or SSO setting must be fixed immediately.
- A technician contacting a personal mobile number when that is not part of the normal support process.
- A link sent by SMS or Teams asking the user to sign in or enter a device code.
- A web address containing the company name but sitting underneath an unfamiliar domain.
- A request to approve an MFA prompt the user did not initiate.
- A request to add a new Authenticator app, phone number or security method during an unsolicited support call.
- A warning that email or Microsoft 365 access will stop unless the user acts immediately.
The same principle applies to the fake IT support requests we recently covered in Microsoft Teams: the communication channel is not proof of identity.
Microsoft 365 guidance
Check the settings attackers try to exploit
Passkey-themed scams often succeed by abusing authentication registration, device-code flows or weak administrator controls rather than breaking passkeys themselves.
Concerned about your Microsoft 365 security or configuration? Talk to KES about your current setup and the areas you would like help with. We will discuss your requirements and recommend an appropriate next step.
Prefer a quick starting point? Complete the free Microsoft 365 Security Assessment →
What should Microsoft 365 administrators do now?
Administrators should combine user awareness with identity controls that make the attack harder to complete and easier to detect. Microsoft recommends several practical measures.
- Give staff a verified support route. Users should know exactly how genuine IT support contacts them and how to check an unexpected call or message.
- Use phishing-resistant MFA. Microsoft recommends FIDO2/passkeys and Windows Hello for Business through Conditional Access where appropriate.
- Review device-code use. Check Entra sign-in logs and block device code flow unless a documented business requirement exists.
- Protect security-info registration. Use Conditional Access to make the registration of new authentication methods harder from risky or unmanaged contexts.
- Use managed-device requirements where practical. Microsoft recommends requiring managed, compliant devices for Exchange, SharePoint and Graph-privileged applications.
- Watch for new authentication methods. Investigate unexpected phone numbers, Authenticator registrations and other security-method changes after risky sign-ins.
- Monitor unusual cloud access. Correlate SharePoint, OneDrive, Exchange and Graph activity with identity events rather than treating them separately.
A KES Microsoft 365 Security Assessment can help identify gaps in MFA, Conditional Access, device management, sharing and account monitoring.
What should you do if someone has already followed the instructions?
Treat the account as potentially compromised and contact your IT provider immediately. Do not assume that changing the password alone is enough, because Microsoft has observed attackers registering their own authentication methods and retaining active sessions.
Microsoft's containment guidance includes revoking active sessions and refresh tokens, resetting credentials, removing unauthorised authentication methods, checking for attacker-created mailbox rules and requiring secure re-registration of MFA.
The investigation should also review sign-in history, Microsoft Graph activity and unusual access to SharePoint, OneDrive and Exchange. If data may have been accessed or downloaded, the incident may require wider technical, legal or regulatory assessment.
Our step-by-step cyberattack response guide covers the immediate actions businesses should take when compromise is suspected.
Why does this matter particularly now?
Businesses are being encouraged to move towards stronger authentication at the same time attackers are learning to imitate that migration process. A request to “set up your new passkey” can therefore sound plausible to staff who know that Microsoft is changing how organisations authenticate.
KES has already covered Microsoft's move away from weaker SMS and voice authentication in our guide to Microsoft ending SMS MFA. The lesson from this new campaign is not to delay stronger authentication; it is to make the rollout process clear enough that staff can distinguish a genuine change from an unsolicited request.
SMEs are especially vulnerable when IT support is remote, outsourced or shared across several sites because employees may not personally know every technician. A documented support process removes that ambiguity.
Quick answers
Are hackers stealing passkeys?
Microsoft's new warning is mainly about attackers using passkey language as a lure. The campaign relies on social engineering, AiTM phishing, device-code authentication and attacker-controlled MFA registration rather than breaking FIDO2 passkey cryptography.
Can a genuine Microsoft sign-in page still be part of a scam?
Yes. In device-code phishing, the victim can be sent to a legitimate Microsoft authentication page but asked to enter a code generated for the attacker's session.
Can MFA still be bypassed?
Some MFA methods can be defeated by AiTM phishing or abused through device-code flows. Microsoft recommends phishing-resistant methods such as passkeys and Windows Hello for Business, combined with Conditional Access.
What is the biggest warning sign?
An unsolicited request to change authentication settings is a strong reason to stop and verify the request through your organisation's known IT support route.
Should businesses stop rolling out passkeys?
No. Microsoft continues to recommend phishing-resistant authentication. Businesses should secure the enrolment and support process around it rather than reverting to weaker methods.
The important point
Passkeys are becoming familiar enough that attackers can now use them as part of a believable helpdesk story. The threat is not a broken passkey standard; it is a convincing human interaction that leads the victim into a different sign-in flow.
Make sure staff know how genuine IT support will contact them, review device-code and authentication-registration controls in Microsoft Entra, and investigate unexpected authentication changes quickly. If something does not feel right, stop the process and contact KES or your normal IT provider through a known route.
Microsoft sources
- Microsoft Security Research: Passkey-themed social engineering leads to identity and cloud compromise — published 9 September 2026.
- Microsoft Learn: Authentication flows as a condition in Conditional Access — guidance on restricting device code and authentication transfer flows.
- Microsoft Learn: Microsoft-managed Conditional Access policies — includes Microsoft's managed policy for blocking device code flow.
Threat techniques and Microsoft 365 controls continue to change. Review Microsoft's live guidance and your own tenant requirements before enforcing Conditional Access changes.