Microsoft is moving to passkeys, and small Texas businesses need to prepare employees for changing sign-in procedures. However, a convincing request to “update your security” deserves verification before anyone follows instructions.
On September 9, 2026, Microsoft reported attacks using fake passkey, MFA, and single-sign-on updates as bait. Impersonators contacted employees as supposed IT staff, including through calls and texts. Microsoft observed activity dating back to May. Therefore, these attacks predate September’s rollout. Microsoft’s investigation
For business owners, the practical question is straightforward: Does your team know what a legitimate security update looks like?

What is changing with Microsoft passkeys?
Microsoft announced a phased Entra ID change beginning September 1, 2026. As the rollout reaches organizations, users enabled for SMS or voice authentication become eligible for passkeys. After completing multifactor authentication, those users receive a prompt to register one.
This concerns organizational sign-in through Microsoft Entra ID. It does not mean every Microsoft account instantly switched to passwordless access on September 1. Microsoft’s rollout announcement
Consequently, owners should ask their IT provider which employees face changes and how the business will introduce them.
For a five-computer office, that conversation can be brief. Nevertheless, it should happen before staff encounter unfamiliar prompts during a busy workday.
Are attackers breaking passkeys?
The reported attacks use passkey enrollment as a pretext for other authentication flows. They do not demonstrate broken passkey cryptography.
A passkey replaces a shared password with cryptographic authentication. Its connection to the intended service helps resist fake sign-in websites. That makes passkeys a valuable improvement over reusable passwords. FIDO Alliance
However, a security feature’s name can still appear in a dishonest message. Employees need to understand both the new tool and the process for introducing it.
Think about your own office. If someone called claiming to handle a Microsoft upgrade, who would verify that claim?
If the answer is unclear, write down the procedure before rollout day.
How does a fake passkey request compromise an account?
Microsoft describes two routes. In adversary-in-the-middle phishing, attackers intercept credentials and authenticated sessions. With device-code phishing, victims enter a supplied code on Microsoft’s genuine authentication page, authorizing an attacker-controlled client.
Investigators also observed added authentication methods and access to SharePoint, OneDrive, and Exchange data. Therefore, the concern extends beyond a stolen password. Microsoft’s technical report
For employee training, avoid turning that explanation into a vocabulary test. Instead, teach one question: “Did I initiate this request through our approved process?”
A professional-looking page cannot answer that question. Neither can a caller who sounds confident or knows the company’s name.
Why does this matter to a small Texas business?
Consider an illustrative San Antonio office with six employees. Its administrator handles scheduling, invoices, and customer correspondence.
Now imagine that employee receives an unexpected call about a mandatory security change. Meanwhile, customers are waiting and the phone keeps ringing.
Without clear instructions, the employee must judge the request under pressure. With a documented process, the response becomes much easier: stop and contact the known IT provider.
For STS, this is the central lesson: introducing stronger authentication should include teaching employees what normal looks like.
Owners do not need a lengthy policy manual to start. They need a clear contact, an agreed procedure, and permission for employees to pause.
What should employees do with unexpected setup requests?
Adopt this office rule:
Never enroll, reset, or update MFA or passkeys because of an unexpected call, text, or Teams message. Verify through your company’s known IT channel first.
Then make the rule usable:
- Save the approved contact. Give employees a known IT number or support address before they need it.
- Verify independently. End the unexpected conversation and start a separate request through that saved contact.
- Explain the request. Tell IT what the caller wanted, including any code entry or account approval.
- Pause under pressure. Allow staff to delay an alleged security deadline while they verify it.
- Report without embarrassment. Ask employees to speak up even if they already clicked or approved something.
Most importantly, managers should follow the same procedure. A policy loses credibility when the owner expects exceptions.
How can owners prepare for a safer rollout?
Start with a short planning conversation involving your office manager and IT provider.
First, identify the affected accounts. Include part-time employees and anyone who handles business accounts from a phone.
Next, agree on the rollout schedule. Tell employees who will provide instructions, where those instructions will appear, and whom to contact.
Then demonstrate the approved process using your actual business setup. Show staff where to begin and when to stop for help.
Also, ask employees to repeat the verification steps in their own words. “Any questions?” is less useful than “What would you do if someone texted you a setup code?”
Finally, document how employees should request help after losing a device or encountering a failed sign-in. Recovery should follow an agreed process too.
Keep the instructions short enough to use during an ordinary workday. A one-page checklist beside the office contact list is a practical starting point.
FAQ
No. Passkeys provide phishing-resistant authentication. Introduce them with clear enrollment instructions, employee education, and an approved support process. FIDO Alliance
No single control covers every situation. Microsoft’s report describes session interception and device-code authorization abuse. Businesses should discuss phishing-resistant authentication and permitted sign-in flows with IT. Microsoft’s investigation
Contact the known IT provider immediately. Microsoft recommends revoking compromised sessions, resetting credentials, and removing unauthorized authentication methods. A password change alone does not complete that response. Microsoft’s response guidance
Tell them where legitimate setup instructions come from and how to verify unexpected requests. Then make sure everyone can find the approved IT contact.
Make your next security change easier to trust
SofTouch Systems helps Texas businesses connect practical security tools with clear everyday procedures.
Request a free 15-minute IT security check. We can discuss your Microsoft 365 sign-in procedures, employee questions, and next steps for safer authentication.
Discover more from SofTouch Systems
Subscribe to get the latest posts sent to your email.
