IT First Responder home
IT First Responder home

Fake Passkey Setup Scams: What Microsoft 365 Users Need to Know

An urgent “IT support” request can turn a security upgrade into an account takeover. Learn how the scam works, why genuine passkeys remain secure and which controls to check.

Isometric Illustration Of A Fake Support Caller Using A Phishing Hook While A Microsoft 365 User Pauses Beside An Intact Passkey Shield.

The hook

A security upgrade. Or an account takeover?

“Your account needs a passkey update.” A helpful-sounding caller, an urgent deadline and a familiar sign-in screen can make the wrong request feel routine.

Microsoft’s September 2026 investigation describes fake support calls and messages using passkey setup as a cover for phishing or device-code abuse. Attackers then added authentication methods and explored cloud data.

The trap is the request, not a broken passkey. Genuine passkeys remain phishing-resistant. Not all MFA methods offer the same protection.

A Staff Member Pauses To Verify An Unexpected Support Request
The wider risk · From our insights library
A$56,600

Average self-reported cybercrime cost per small-business report.

Australia, FY2024-25 · ASD
58%

Of incidents observed by Coalition involved email compromise or funds-transfer fraud.

Global policyholders, 2025 · Coalition
84,700+

Cybercrime reports made to Australian law enforcement through ReportCyber.

Australia, FY2024-25 · ASD

These are broader cybercrime and insurance figures, not passkey-scam rates. Explore the full facts library.

Behind the sign-in

A real Microsoft page can still be part of the trick

Device-code authentication is a legitimate way to sign in on devices with limited input. But entering a code supplied by an attacker can authorise their session, even on a genuine Microsoft page.

In the reported intrusions, attackers used Microsoft Graph to discover information and collect SharePoint, OneDrive and sometimes Exchange data. The observed paths varied; not every victim went through an identical sequence.

For staff: stop the unexpected conversation and contact IT through your established support number. Do not use the number or link supplied by the caller.

Isometric Identity Monitoring Across Cloud Accounts And Business Information
Make the safe path the easy path

Three controls worth checking with your IT team

1. Close unused sign-in routes

Allow device-code authentication only where the business actually needs it.

What should IT check?

Review sign-in logs, test Conditional Access in report-only mode and document legitimate exceptions. Authentication-transfer flows need their own review.

Microsoft’s flow controls

2. Protect enrolment too

Review who can register a new authentication method, from which devices and under what conditions.

What should IT check?

Use Conditional Access for security-information registration. Plan safe onboarding, lost-device recovery and emergency access. Require phishing-resistant authentication for sensitive and privileged access where supported.

Microsoft’s registration guidance

3. Connect the warning signs

Review unusual sign-ins alongside newly added methods and abnormal cloud downloads.

What should IT check?

Check available logging, licensing and response ownership. A single API call or download is not proof of an attack; the sequence and user context matter.

Microsoft’s investigation

Sources & further reading

Microsoft Security Research: passkey-themed social engineering, 9 September 2026

Microsoft: authentication strengths · Authentication flows · Security-information registration

For a practical next step, explore identity and access security and security awareness training. General information; controls depend on your environment and Microsoft licensing.

Make your Microsoft 365 sign-ins harder to exploit

Explore ITFR’s cloud security services for identities, email, collaboration and ongoing oversight.

Explore Microsoft 365 security

Useful IT ideas, straight to your inbox

Get the monthly ITFR Insights newsletter. Unsubscribe any time.

Choose interests (optional)
What interests you?

Privacy policy