Microsoft Passkey Attacks Target Enrollment and Recovery

By
CTOL Staff Reporter
1 min read

Microsoft says it has observed cloud intrusions since May in which attackers use passkey, multifactor-authentication or single-sign-on setup as social-engineering bait. The security lesson is not that passkeys failed. It is that authentication systems remain vulnerable at the points where people enroll credentials, recover accounts and authorize new sessions.

In Microsoft’s investigations, attackers have used adversary-in-the-middle and device-code flows to obtain valid access, then registered authentication methods or used the session to enumerate cloud applications and collect data from Microsoft Graph, SharePoint, OneDrive and Exchange.

That shifts the control problem. Phishing-resistant credentials make it harder to steal a reusable password or intercept an ordinary MFA code. They do not stop a user from approving a malicious flow or a compromised session from registering a new authentication method if the surrounding policy allows it.

Microsoft’s recommended controls concentrate on security-info registration, conditional access, managed devices, device-code restrictions and cloud-session investigation. Help-desk verification also becomes more valuable because recovery and enrollment are natural targets once primary authentication gets harder to phish.

This is why the transition away from SMS and voice authentication should not be measured only by passkey adoption. Organisations also need to know who can add a new method, from which device and network, how long sessions persist and whether unusual Graph or content-access patterns trigger investigation.

Better authenticators reduce one attack surface and increase the value of policy, telemetry and recovery controls around them. Enterprises that buy passkeys as a substitute for identity governance will remove the weakest credential while leaving the attacker’s next-best workflow open.

Sources

You May Also Like

This article is submitted by our user under the News Submission Rules and Guidelines. The cover photo is computer generated art for illustrative purposes only; not indicative of factual content. If you believe this article infringes upon copyright rights, please do not hesitate to report it by sending an email to us. Your vigilance and cooperation are invaluable in helping us maintain a respectful and legally compliant community.

Subscribe to our Newsletter

Get the latest in enterprise business and tech with exclusive peeks at our new offerings

We use cookies on our website to enable certain functions, to provide more relevant information to you and to optimize your experience on our website. Further information can be found in our Privacy Policy and our Terms of Service . Mandatory information can be found in the legal notice