Passwords are not the only keys attackers want to Microsoft 365 accounts. They are increasingly targeting the authentication process itself.
Microsoft warned Sept. 9 that attackers are using passkey-themed social engineering to trick users and compromise cloud identities. The campaigns can ultimately give attackers access to Microsoft 365 services including Exchange Online, SharePoint, OneDrive, and Microsoft Graph by manipulating authentication flows, stealing session tokens, or using previously compromised credentials.
For MSPs and partners managing Microsoft environments, the attacks expose a tricky weakness: even stronger authentication methods can be undermined when an employee is convinced that the attacker is legitimate IT support.
Attackers turn passkey security into a phishing lure
In its Sept. 9 threat analysis, Microsoft said it has observed the activity since at least May 2026.
Attackers impersonate IT support and contact employees with instructions to supposedly update or configure security features such as passkeys, multifactor authentication, or single sign-on. Rather than relying on a single attack method, Microsoft observed campaigns employing techniques such as adversary-in-the-middle phishing and device code authentication.
In adversary-in-the-middle attacks, threat actors can intercept credentials and session tokens. Microsoft also observed attackers abusing device-code authentication, which can trick a user into authorizing an attacker-controlled session.
Once access is obtained, attackers can move deeper into the victim’s Microsoft cloud environment. Microsoft observed activity involving Microsoft Graph, Exchange Online, SharePoint, and OneDrive for purposes including reconnaissance, data collection, and maintaining access.
That shift fits a broader identity-security problem already facing MSPs. Earlier this year, Guardz research highlighted AI-driven phishing and identity attacks as growing risks for managed service providers and their customers.
The new campaign also shows why simply moving organizations away from passwords does not eliminate phishing. Microsoft continues to recommend phishing-resistant authentication, including passkeys, but attackers can adapt their approach and target the people and authentication workflows that surround those protections.
Microsoft 365 security moves beyond the endpoint
One complication for defenders is that parts of these attacks can happen outside a traditional corporate endpoint.
Microsoft said some social-engineering activity can begin on unmanaged personal mobile devices before attackers move into cloud services. That can leave security teams with limited endpoint telemetry and place greater emphasis on identity and cloud activity when investigating an incident.
For MSPs, that means Microsoft 365 monitoring increasingly needs to extend beyond malware alerts on customer laptops.
Channel vendors are already moving in that direction. In September, inforcer introduced Microsoft 365 threat detection and response designed for MSPs, drawing telemetry from services including Entra ID, Exchange, SharePoint, Teams, Defender, and Purview.
Microsoft recommends that organizations investigate suspicious sign-ins, unexpected registrations of authentication methods, unusual device code activity, and abnormal activity across Microsoft 365 services. It also recommends blocking device-code and authentication-transfer flows unless organizations have an explicit business need for them.
The attack pattern also reflects another emerging problem for partners: attackers are increasingly targeting credentials and permissions associated with cloud and AI services. Channel Insider recently reported that attackers are targeting cloud credentials through AI-agent environments, showing that privileged access, rather than malware, can become the gateway into sensitive systems.
What this means for MSPs and channel partners
For channel partners, the larger lesson is that deploying stronger authentication is only one piece of Microsoft 365 security.
Customers may assume passkeys and MFA largely solve the phishing problem. Microsoft’s findings show attackers can instead target the people and workflows surrounding those protections, particularly when a request appears to come from a trusted IT administrator. Importantly, Microsoft’s findings do not mean passkeys themselves have been broken.
That puts MSPs in a particularly important position. Partners often control authentication policies, Microsoft 365 configurations, identity monitoring, and employee security guidance across multiple customers.
MSPs should consider whether customers actually need device code authentication, monitor for unexpected changes in authentication methods, investigate unusual Microsoft 365 activity after suspicious sign-ins, and ensure users know that unexpected requests to reconfigure authentication should be independently verified.
For partners, this is ultimately a reminder that identity security is becoming less about protecting a single password and more about protecting the entire chain of trust around a user’s account. As attackers adapt to passkeys, MFA, cloud services, and increasingly complex authentication systems, helping customers secure that chain could become one of the channel’s most important security jobs.
Also read: For more on protecting customer identities after authentication, see how ThreatDown is expanding identity threat detection and response for MSPs.





