Microsoft Is Moving to Passkeys. Attackers Are Already Exploiting the Confusion

Phishing hook holding an envelope beside an STS-branded laptop and passkey shield. Text: “Passkeys are secure. Fake requests aren’t.”

Microsoft is moving to passkeys, and small Texas businesses need to prepare employees for changing sign-in procedures. However, a convincing request to “update your security” deserves verification before anyone follows instructions.

On September 9, 2026, Microsoft reported attacks using fake passkey, MFA, and single-sign-on updates as bait. Impersonators contacted employees as supposed IT staff, including through calls and texts. Microsoft observed activity dating back to May. Therefore, these attacks predate September’s rollout. Microsoft’s investigation

For business owners, the practical question is straightforward: Does your team know what a legitimate security update looks like?

Phishing hook holding an envelope beside an STS-branded laptop and passkey shield. Text: “Passkeys are secure. Fake requests aren’t.”
Microsoft is moving to passkeys. Verify unexpected setup requests through your trusted IT contact before approving changes.

Microsoft announced a phased Entra ID change beginning September 1, 2026. As the rollout reaches organizations, users enabled for SMS or voice authentication become eligible for passkeys. After completing multifactor authentication, those users receive a prompt to register one.

This concerns organizational sign-in through Microsoft Entra ID. It does not mean every Microsoft account instantly switched to passwordless access on September 1. Microsoft’s rollout announcement

Consequently, owners should ask their IT provider which employees face changes and how the business will introduce them.

For a five-computer office, that conversation can be brief. Nevertheless, it should happen before staff encounter unfamiliar prompts during a busy workday.


The reported attacks use passkey enrollment as a pretext for other authentication flows. They do not demonstrate broken passkey cryptography.

A passkey replaces a shared password with cryptographic authentication. Its connection to the intended service helps resist fake sign-in websites. That makes passkeys a valuable improvement over reusable passwords. FIDO Alliance

However, a security feature’s name can still appear in a dishonest message. Employees need to understand both the new tool and the process for introducing it.

Think about your own office. If someone called claiming to handle a Microsoft upgrade, who would verify that claim?

If the answer is unclear, write down the procedure before rollout day.


Microsoft describes two routes. In adversary-in-the-middle phishing, attackers intercept credentials and authenticated sessions. With device-code phishing, victims enter a supplied code on Microsoft’s genuine authentication page, authorizing an attacker-controlled client.

Investigators also observed added authentication methods and access to SharePoint, OneDrive, and Exchange data. Therefore, the concern extends beyond a stolen password. Microsoft’s technical report

For employee training, avoid turning that explanation into a vocabulary test. Instead, teach one question: “Did I initiate this request through our approved process?”

A professional-looking page cannot answer that question. Neither can a caller who sounds confident or knows the company’s name.


Consider an illustrative San Antonio office with six employees. Its administrator handles scheduling, invoices, and customer correspondence.

Now imagine that employee receives an unexpected call about a mandatory security change. Meanwhile, customers are waiting and the phone keeps ringing.

Without clear instructions, the employee must judge the request under pressure. With a documented process, the response becomes much easier: stop and contact the known IT provider.

For STS, this is the central lesson: introducing stronger authentication should include teaching employees what normal looks like.

Owners do not need a lengthy policy manual to start. They need a clear contact, an agreed procedure, and permission for employees to pause.


Adopt this office rule:

Never enroll, reset, or update MFA or passkeys because of an unexpected call, text, or Teams message. Verify through your company’s known IT channel first.

Then make the rule usable:

  • Save the approved contact. Give employees a known IT number or support address before they need it.
  • Verify independently. End the unexpected conversation and start a separate request through that saved contact.
  • Explain the request. Tell IT what the caller wanted, including any code entry or account approval.
  • Pause under pressure. Allow staff to delay an alleged security deadline while they verify it.
  • Report without embarrassment. Ask employees to speak up even if they already clicked or approved something.

Most importantly, managers should follow the same procedure. A policy loses credibility when the owner expects exceptions.


Start with a short planning conversation involving your office manager and IT provider.

First, identify the affected accounts. Include part-time employees and anyone who handles business accounts from a phone.

Next, agree on the rollout schedule. Tell employees who will provide instructions, where those instructions will appear, and whom to contact.

Then demonstrate the approved process using your actual business setup. Show staff where to begin and when to stop for help.

Also, ask employees to repeat the verification steps in their own words. “Any questions?” is less useful than “What would you do if someone texted you a setup code?”

Finally, document how employees should request help after losing a device or encountering a failed sign-in. Recovery should follow an agreed process too.

Keep the instructions short enough to use during an ordinary workday. A one-page checklist beside the office contact list is a practical starting point.


Should our business avoid passkeys?

No. Passkeys provide phishing-resistant authentication. Introduce them with clear enrollment instructions, employee education, and an approved support process. FIDO Alliance

Is ordinary MFA enough by itself?

No single control covers every situation. Microsoft’s report describes session interception and device-code authorization abuse. Businesses should discuss phishing-resistant authentication and permitted sign-in flows with IT. Microsoft’s investigation

What if an employee already followed suspicious instructions?

Contact the known IT provider immediately. Microsoft recommends revoking compromised sessions, resetting credentials, and removing unauthorized authentication methods. A password change alone does not complete that response. Microsoft’s response guidance

What should we tell employees today?

Tell them where legitimate setup instructions come from and how to verify unexpected requests. Then make sure everyone can find the approved IT contact.


SofTouch Systems helps Texas businesses connect practical security tools with clear everyday procedures.

Request a free 15-minute IT security check. We can discuss your Microsoft 365 sign-in procedures, employee questions, and next steps for safer authentication.

SofTouch Systems Simplifying technology, maximizing results

Home » Managed IT Services » Microsoft Is Moving to Passkeys. Attackers Are Already Exploiting the Confusion


Discover more from SofTouch Systems

Subscribe to get the latest posts sent to your email.

What do y'all think?

Discover more from SofTouch Systems

Subscribe now to keep reading and get access to the full archive.

Continue reading