Microsoft warns that malicious actors are exploiting passkey and multi-factor authentication update requests to launch sophisticated phishing campaigns against enterprise employees, hijack active user sessions, and compromise sensitive Microsoft 365 data.
The emerging attack vector leverages deceptive prompts disguised as routine security compliance and passkey registration updates. By tricking users into interacting with fraudulent device code verification flows, threat actors bypass traditional perimeter security controls and establish persistent access to cloud environments without triggering standard credential alerts.
Security researchers note that while passkeys and modern multi-factor authentication protocols significantly raise the barrier against conventional credential harvesting, cybercriminals are shifting their focus toward social engineering the human element during the enrollment phase. Attackers initiate fake device code authentication sequences, compelling targets to authorize unauthorized sessions under the guise of mandatory corporate security upgrades.
Enterprise IT and security teams are urged to audit their identity and access management configurations immediately. Organizations must reinforce employee awareness training regarding unsolicited security notifications and monitor Azure Active Directory logs for anomalous device code binding requests and suspicious token generation patterns.
“While modern authentication mechanisms like passkeys remain fundamentally robust against automated credential stuffing, threat actors are aggressively adapting their tactics to exploit user trust during security configuration workflows,” stated enterprise cybersecurity analysts tracking the campaign.
Microsoft continues to investigate the scope of these targeted phishing operations and recommends implementing stringent conditional access policies, restricting device code flow usage where unnecessary, and enforcing phishing-resistant authentication methods across all enterprise tenants.