Include:
Tech
Cybersecurity
Business Strategy
Channel Insights
Stay Connected
Acer America
Acer America Corp. is a computer manufacturer of business and consumer PCs, notebooks, ultrabooks, projectors, servers, and storage products.

Location

333 West San Carlos Street
San Jose, California 95110
United States

WWW: acer.com

ChannelPro Network Awards

hello 2
hello 3

New Products & Platforms

September 21, 2026 |

Attackers aren’t breaking Microsoft passkeys. They’re going around them.

Attackers are using passkey social engineering to hijack Microsoft 365 identities, exposing a security gap that stronger authentication alone cannot close.

Passkeys promise to make stolen passwords far less useful to attackers. Cybercriminals have found another option: convince the user to let them in. According to Channel Insider, Microsoft has tracked passkey phishing campaigns since at least May 2026 in which attackers impersonate IT support and guide employees through what appears to be a legitimate security update. Instead, victims can end up handing attackers access to their Microsoft 365 identities.

That creates a troubling question for MSPs: What happens when stronger authentication works exactly as designed but the user authorizes the attacker anyway?

Attackers are turning security itself into the lure

Microsoft said attackers have contacted employees with instructions to update or configure security features such as passkeys, multifactor authentication and single sign-on.

The campaigns use several techniques. In adversary-in-the-middle attacks, threat actors can intercept credentials and session tokens. Attackers can also abuse device code authentication to persuade a user to authorize a session that the attacker controls. Once inside, they can reach Microsoft Graph, Exchange Online, SharePoint and OneDrive to conduct reconnaissance, collect data and maintain access.

The attacks do not show that criminals have cracked passkeys. They show something potentially more frustrating for defenders: Attackers may not need to defeat the authentication technology if they can manipulate the process around it.

The endpoint may never see the attack coming

The problem becomes even harder when the attack begins outside the corporate environment. Microsoft found that some social engineering activity can start on an employee’s unmanaged personal mobile device before the attacker moves into Microsoft cloud services. That can leave MSPs with little or no endpoint telemetry from the beginning of the attack.

A customer laptop may never download malware. An antivirus alert may never fire. Yet an attacker can still end up operating inside the customer’s Microsoft 365 environment with a legitimate session.

That shifts more of the defensive burden toward identity and cloud activity.

The head fake: Stronger authentication does not eliminate phishing

Passkeys and phishing-resistant authentication remain important defenses. But stronger authentication changes the attacker’s tactics rather than eliminating the attacker.

Instead of asking, “Can I steal this password?” criminals can ask a different question: Can I convince this employee that I’m their IT administrator? That makes the surrounding chain of trust just as important as the authentication method itself.

MSPs should watch for suspicious sign-ins, unexpected registration of new authentication methods, unusual device code activity and abnormal behavior across Microsoft 365 services. Microsoft also recommends blocking device code and authentication-transfer flows unless the organization has a specific business need for them.

MSPs need to protect more than the login

For MSPs, the larger lesson goes beyond passkey phishing campaigns. Many customers may assume that deploying MFA or passwordless authentication largely solves their phishing problem. It does not.

Attackers can target the identities, permissions, sessions and workflows surrounding those controls — particularly when an employee believes the request comes from a trusted administrator.

That puts MSPs in a critical position because they often manage the authentication policies, Microsoft 365 configurations, identity monitoring and employee guidance that determine whether these attacks succeed.

Providers should evaluate whether customers need device code authentication at all, monitor changes to authentication methods, investigate unusual cloud activity following suspicious sign-ins and teach users to independently verify unexpected requests involving account security.

The security question is no longer simply whether an attacker can steal a password. It is whether the attacker can convince a trusted user to open the door for them.

Source: Channel Insider

Related New Products & Platforms

Free MSP Resources

Editor’s Choice


Explore ChannelPro

Events

Reach Our Audience