Microsoft says attackers are using fake passkey, MFA and SSO prompts to compromise cloud identities, add their own authentication methods and access files and email.
A call from someone claiming to be your company's IT help desk can sound routine: your passkey, MFA or single sign-on setup needs an urgent update, or your access could be disrupted. The request may even arrive just as your organization is genuinely asking employees to register passkeys.
"Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs," Microsoft said in its September 9 research report.
The timing gives the lures an unusually credible cover. Microsoft began rolling out passkeys as the default authentication experience in Entra ID on September 1, automatically enabling the change for users who were still using SMS or voice authentication and prompting them to register a passkey during MFA sign-in.
The Passkey Isn't The Weakness"Despite the frequent use of passkey-themed lures, passkey enrollment is often not the actor's true objective. Instead, the passkey narrative serves as a convincing pretext to guide victims through adversary-in-the-middle (AiTM) phishing or device-code authentication flows," Microsoft Security Research said.
The initial contact can come through a call or message to a user's personal phone from someone claiming to be internal IT. "The attack often begins with a seemingly routine call or message on a user's personal phone number from someone claiming to be from the organization's IT helpdesk," Microsoft said.
Microsoft also observed attackers directing victims toward adversary-in-the-middle phishing pages or legitimate Microsoft device-code authentication flows. In the latter case, the victim enters a code on Microsoft's real authentication page but unknowingly authorizes an attacker-controlled client.
That means a genuine-looking Microsoft authentication page does not necessarily make the request safe. The question is how the user arrived there and who initiated the request.
What Happens After Access"Following account compromise, threat actors often register a new authentication method, mobile device, or software-based OTP to establish persistent access to the compromised identity," Microsoft said in its investigation guidance.
The next stage is reconnaissance. Attackers use Microsoft Graph to enumerate users, groups, permissions and applications, then move toward cloud content. Microsoft observed SharePoint and OneDrive access and email collection through REST APIs, with some activity showing the characteristics of automated collection.
This is why checking only for an unfamiliar sign-in can miss part of the problem. An attacker who has added an authentication method may retain access even after the original phishing event is no longer visible.
What To Check NowIf you receive an unexpected request to configure a passkey, MFA or SSO, don't complete it through the caller's link or instructions. Hang up and contact your organization's IT help desk through a number or channel you already trust.
If you may have already complied, check recent sign-ins and your registered authentication methods. Look specifically for an authenticator app, phone number or other MFA method that you did not add yourself. Microsoft recommends investigating unusual sign-ins alongside authentication-method enrollment, Microsoft Graph activity and abnormal SharePoint, OneDrive or Exchange access. For confirmed compromises, its guidance includes revoking active sessions and removing unauthorized authentication methods.
"Microsoft Entra ID is making passkeys the default sign-in experience," Microsoft said, with the rollout beginning September 1, 2026 for users enabled for SMS or voice authentication. A passkey prompt by itself is not evidence that an account has been compromised. Microsoft is legitimately rolling out passkeys across Entra ID, so users may encounter real registration prompts.