Microsoft Warns of Passkey Phishing Attacks: Hackers Are Hijacking Microsoft 365 Accounts

Microsoft warns attackers are using passkey-themed phishing to compromise Microsoft 365 accounts, creating new identity risks for MSPs and customers.

Written By
Matt Gonzales
Matt Gonzales
Sep 15, 2026
3 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Passwords are not the only keys attackers want to Microsoft 365 accounts. They are increasingly targeting the authentication process itself.

Microsoft warned Sept. 9 that attackers are using passkey-themed social engineering to trick users and compromise cloud identities. The campaigns can ultimately give attackers access to Microsoft 365 services including Exchange Online, SharePoint, OneDrive, and Microsoft Graph by manipulating authentication flows, stealing session tokens, or using previously compromised credentials.

For MSPs and partners managing Microsoft environments, the attacks expose a tricky weakness: even stronger authentication methods can be undermined when an employee is convinced that the attacker is legitimate IT support.

Attackers turn passkey security into a phishing lure

In its Sept. 9 threat analysis, Microsoft said it has observed the activity since at least May 2026.

Attackers impersonate IT support and contact employees with instructions to supposedly update or configure security features such as passkeys, multifactor authentication, or single sign-on. Rather than relying on a single attack method, Microsoft observed campaigns employing techniques such as adversary-in-the-middle phishing and device code authentication.

In adversary-in-the-middle attacks, threat actors can intercept credentials and session tokens. Microsoft also observed attackers abusing device-code authentication, which can trick a user into authorizing an attacker-controlled session.

Once access is obtained, attackers can move deeper into the victim’s Microsoft cloud environment. Microsoft observed activity involving Microsoft Graph, Exchange Online, SharePoint, and OneDrive for purposes including reconnaissance, data collection, and maintaining access.

That shift fits a broader identity-security problem already facing MSPs. Earlier this year, Guardz research highlighted AI-driven phishing and identity attacks as growing risks for managed service providers and their customers.

The new campaign also shows why simply moving organizations away from passwords does not eliminate phishing. Microsoft continues to recommend phishing-resistant authentication, including passkeys, but attackers can adapt their approach and target the people and authentication workflows that surround those protections.

Advertisement

Microsoft 365 security moves beyond the endpoint

One complication for defenders is that parts of these attacks can happen outside a traditional corporate endpoint.

Microsoft said some social-engineering activity can begin on unmanaged personal mobile devices before attackers move into cloud services. That can leave security teams with limited endpoint telemetry and place greater emphasis on identity and cloud activity when investigating an incident.

For MSPs, that means Microsoft 365 monitoring increasingly needs to extend beyond malware alerts on customer laptops.

Channel vendors are already moving in that direction. In September, inforcer introduced Microsoft 365 threat detection and response designed for MSPs, drawing telemetry from services including Entra ID, Exchange, SharePoint, Teams, Defender, and Purview.

Microsoft recommends that organizations investigate suspicious sign-ins, unexpected registrations of authentication methods, unusual device code activity, and abnormal activity across Microsoft 365 services. It also recommends blocking device-code and authentication-transfer flows unless organizations have an explicit business need for them.

The attack pattern also reflects another emerging problem for partners: attackers are increasingly targeting credentials and permissions associated with cloud and AI services. Channel Insider recently reported that attackers are targeting cloud credentials through AI-agent environments, showing that privileged access, rather than malware, can become the gateway into sensitive systems.

What this means for MSPs and channel partners

For channel partners, the larger lesson is that deploying stronger authentication is only one piece of Microsoft 365 security.

Customers may assume passkeys and MFA largely solve the phishing problem. Microsoft’s findings show attackers can instead target the people and workflows surrounding those protections, particularly when a request appears to come from a trusted IT administrator. Importantly, Microsoft’s findings do not mean passkeys themselves have been broken.

That puts MSPs in a particularly important position. Partners often control authentication policies, Microsoft 365 configurations, identity monitoring, and employee security guidance across multiple customers.

MSPs should consider whether customers actually need device code authentication, monitor for unexpected changes in authentication methods, investigate unusual Microsoft 365 activity after suspicious sign-ins, and ensure users know that unexpected requests to reconfigure authentication should be independently verified.

Advertisement

For partners, this is ultimately a reminder that identity security is becoming less about protecting a single password and more about protecting the entire chain of trust around a user’s account. As attackers adapt to passkeys, MFA, cloud services, and increasingly complex authentication systems, helping customers secure that chain could become one of the channel’s most important security jobs.

Also read: For more on protecting customer identities after authentication, see how ThreatDown is expanding identity threat detection and response for MSPs.

Matt Gonzales

Matt Gonzales is a technology journalist, editor, and content strategist with more than a decade of experience covering emerging technologies, enterprise IT, cybersecurity, artificial intelligence, and workplace innovation. As Managing Editor for eWeek and TechRepublic, he leads editorial strategy and newsroom operations while helping business and IT leaders navigate an evolving technology landscape. Throughout his career, Matt has held leadership roles overseeing content development, editorial planning, and newsroom operations across digital publications and enterprise media organizations. Before joining TechnologyAdvice, he served as an editor at SHRM, where he covered workplace trends and emerging technologies, and as Lead Writer and Editor for Marine Corps Systems Command, where he reported on defense technologies, innovation initiatives, and government technology programs. Matt's expertise spans cybersecurity, enterprise technology, AI, B2B software, technical writing, and digital publishing. He has reported on major technology developments, including the rapid evolution of generative AI, helping readers understand both the opportunities and risks associated with emerging technologies. His work combines deep research, editorial rigor, and practical business insights to make complex technical topics accessible to a broad audience. An award-winning journalist, Matt has earned recognition for excellence in reporting and editorial leadership. He holds a Bachelor of Science in Communication with a concentration in Journalism from East Carolina University and continues to focus on delivering trusted analysis and actionable insights for technology, cybersecurity, and business professionals.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.