Fake Entra Passkey Registration: A New Microsoft 365 Takeover Vector via Vishing

Colleagues, I would like to draw your attention to an important cybersecurity case.
Attackers are using phone calls and spoofed Microsoft Entra pages to persuade users to register a new passkey.
The scenario looks convincing: the victim is guided through a fake sign-in flow, their password and MFA code are captured, and the attacker then completes passkey registration under their own account.
The danger lies in abusing trust in passkeys, a technology many consider more secure.
Why this matters: even protective mechanisms can be turned against users if they do not verify the request and its context.
Are you already reviewing your sign-in verification procedures and employee training? #cybersecurity #phishing #Microsoft365 #Passkey

