Microsoft says it has observed cloud intrusions since May in which attackers use passkey, multifactor-authentication or single-sign-on setup as social-engineering bait. The security lesson is not that passkeys failed. It is that authentication systems remain vulnerable at the points where people enroll credentials, recover accounts and authorize new sessions.
In Microsoft’s investigations, attackers have used adversary-in-the-middle and device-code flows to obtain valid access, then registered authentication methods or used the session to enumerate cloud applications and collect data from Microsoft Graph, SharePoint, OneDrive and Exchange.
That shifts the control problem. Phishing-resistant credentials make it harder to steal a reusable password or intercept an ordinary MFA code. They do not stop a user from approving a malicious flow or a compromised session from registering a new authentication method if the surrounding policy allows it.
Microsoft’s recommended controls concentrate on security-info registration, conditional access, managed devices, device-code restrictions and cloud-session investigation. Help-desk verification also becomes more valuable because recovery and enrollment are natural targets once primary authentication gets harder to phish.
This is why the transition away from SMS and voice authentication should not be measured only by passkey adoption. Organisations also need to know who can add a new method, from which device and network, how long sessions persist and whether unusual Graph or content-access patterns trigger investigation.
Better authenticators reduce one attack surface and increase the value of policy, telemetry and recovery controls around them. Enterprises that buy passkeys as a substitute for identity governance will remove the weakest credential while leaving the attacker’s next-best workflow open.
