Passkey lures: Review cloud identities now

Microsoft Security Research reports active cloud-based intrusions in which passkey, MFA, or SSO themes are used as social-engineering pretexts. The point is not that passkeys are weak. Microsoft describes how a convincing passkey message can lead users into adversary-in-the-middle phishing or device-code authentication, after which compromised identities are used across Microsoft Graph, SharePoint, OneDrive, and Exchange. For small and midsized Microsoft 365 environments, this creates an immediate review point for Microsoft Entra ID, Defender XDR, and cloud data access.

What Microsoft reported on 9 September 2026

The Microsoft Security Blog describes an intrusion chain that Microsoft has observed since May 2026. It often starts with a call or message to an employee’s personal mobile number. The caller claims to be from IT support and says that a passkey, MFA, or single sign-on setting must be updated immediately to avoid disruption. The link then leads to infrastructure that imitates Microsoft sign-in or steers the user into a legitimate device-code flow for the attacker. In some cases, Microsoft also observed compromised accounts sending similar messages through Microsoft Teams.

After successful authentication, Microsoft observed unusual sign-ins, threat actor-added authentication methods, Microsoft Graph reconnaissance, SharePoint and OneDrive downloads, and email collection through REST APIs. Microsoft stresses that this recurring sequence matters more than individual domains or IP addresses because attacker infrastructure can change quickly.

Why this affects smaller organizations

The steps do not apply only to large enterprises. Organizations with 10 to 250 seats also have users with Microsoft 365 access, shared files, Teams communication, email attachments, and occasional helpdesk requests. If a compromised account receives an attacker-controlled authentication method, a short user mistake can turn into persistent cloud access.

  • A personal phone call can feel more credible than a broad phishing email.
  • Passkey and MFA language sounds like a legitimate security upgrade.
  • SharePoint, OneDrive, and Exchange hold business-critical data even in small teams.
  • Graph activity is easy to miss when it is not correlated with sign-ins and MFA changes.

Urgency: active campaign, not a migration deadline

Microsoft does not publish a future deadline for this issue. The concrete action is a timely review of identity and cloud-workload signals. The most relevant events are unusual sign-ins, device-code authentication, newly registered MFA devices, token issuance, broad Graph queries, and abnormal file or mailbox access. Organizations using Microsoft Defender can use Microsoft’s Advanced Hunting queries as a starting point.

The distinction is important: this is not an argument against passkeys. Microsoft Learn continues to describe passkeys in Entra ID as a phishing-resistant authentication method. The abuse is in the pretext and in fallback paths that are not phishing-resistant, such as captured sessions or device-code flows that a user approves for an attacker.

Which signals belong together

Microsoft recommends investigating identity and workload events as a connected sequence. A single IP address or domain match is not conclusive. The stronger pattern is an unusual sign-in followed by authentication-method enrollment, Graph reconnaissance, SharePoint or OneDrive searching, Exchange REST activity, and elevated download volume.

For Microsoft Entra ID, this means security information registration, MFA changes, and risk events must be connected to Exchange, SharePoint, and Graph access. Conditional Access can enforce phishing-resistant MFA, managed-device requirements, sign-in frequency for security information registration, and restrictions for device-code or authentication-transfer flows. These controls should cover administrators and users with broad access to shared files, mailboxes, or internal applications.

Concrete next steps for administrators

  • Review newly registered authentication methods for users with risky or unusual sign-ins.
  • Remove unauthorized MFA methods, revoke sessions, and reset credentials for confirmed compromises.
  • Correlate Graph requests for roles, applications, service principals, files, and mailboxes.
  • Check SharePoint, OneDrive, and Exchange REST activity for volume, source, and user-agent anomalies.
  • Tighten Conditional Access for security information, managed devices, and phishing-resistant MFA.
  • Allow device-code flows and application consent only where a documented business need exists.

For a Microsoft Security Assessment, this becomes a clear test case: does the environment expose the compromised identity during MFA persistence and Graph reconnaissance, or only after data access and download activity?

Official Microsoft sources

If you want to know whether Entra ID, Defender XDR, and Microsoft 365 make this attack chain visible in your environment, we can review your security configuration in a focused assessment – get in touch.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment