Cybercriminals are impersonating IT support staff and using passkey-themed social engineering to compromise Microsoft 365 accounts, according to a threat analysis Microsoft published Sept. 9. The company has tracked the activity since at least May 2026. The campaigns can ultimately grant attackers entry to Microsoft 365 services including Exchange Online, SharePoint, OneDrive, and Microsoft Graph by manipulating authentication flows, stealing session tokens, or exploiting previously compromised credentials. For managed service providers and partners overseeing Microsoft environments, the attacks reveal a challenging vulnerability: even more robust authentication methods can be weakened when an employee believes the attacker is legitimate IT support.

Threat actors contact employees with instructions to purportedly update or configure security features such as passkeys, multifactor authentication, or single sign-on, Microsoft reported. Rather than depending on a single attack method, the company observed campaigns using techniques including adversary-in-the-middle phishing and device code authentication. In adversary-in-the-middle attacks, attackers can capture credentials and session tokens. Microsoft also saw attackers misusing device-code authentication, which can fool a user into authorizing an attacker-controlled session. Once access is secured, attackers can navigate deeper into the victim's Microsoft cloud environment. Microsoft observed activity involving Microsoft Graph, Exchange Online, SharePoint, and OneDrive for purposes including reconnaissance, data collection, and maintaining access.

According to the threat analysis, portions of these attacks can occur outside a traditional corporate endpoint. Microsoft said some social-engineering activity can begin on unmanaged personal mobile devices before attackers shift into cloud services. That can leave security teams with limited endpoint telemetry and place greater weight on identity and cloud activity when investigating an incident. The company continues to recommend phishing-resistant authentication, including passkeys, but attackers can adapt their approach and target the people and authentication workflows that surround those protections. Microsoft's findings do not mean passkeys themselves have been broken.

The shift reflects a broader identity-security challenge already confronting MSPs. The new campaign shows why simply transitioning organizations away from passwords doesn't eliminate phishing. For MSPs, that means Microsoft 365 monitoring increasingly needs to extend beyond malware alerts on customer laptops. Some parts of these attacks happen outside traditional endpoints, leaving security teams with less visibility and forcing them to rely more heavily on identity and cloud activity logs. Microsoft recommends that organizations investigate suspicious sign-ins, unexpected registrations of authentication methods, unusual device code activity, and abnormal activity across Microsoft 365 services. It also recommends blocking device-code and authentication-transfer flows unless organizations have an explicit business need for them.

For channel partners, the larger lesson is that deploying stronger authentication is only one piece of Microsoft 365 security. Customers may assume passkeys and MFA largely solve the phishing problem, but Microsoft's findings show attackers can instead target the people and workflows surrounding those protections, particularly when a request appears to come from a trusted IT administrator. That puts MSPs in a particularly important position, since partners often control authentication policies, Microsoft 365 configurations, identity monitoring, and employee security guidance across multiple customers. MSPs should consider whether customers actually need device code authentication, monitor for unexpected changes in authentication methods, investigate unusual Microsoft 365 activity after suspicious sign-ins, and ensure users know that unexpected requests to reconfigure authentication should be independently verified. For partners, this is ultimately a reminder that identity security is becoming less about protecting a single password and more about protecting the entire chain of trust around a user's account. The real battle isn't just technical controls but user discernment, and the MSPs who grasp that duality will separate themselves from those still treating authentication as a purely technological fix. As cloud permissions become the new perimeter, partners may find their most valuable security offering isn't another layer of defense but the human judgment to question an urgent request.