VMTech
Discuss a project

Fake Entra Passkey Registration: A New Microsoft 365 Takeover Vector via Vishing

Fake Entra Passkey Registration: A New Microsoft 365 Takeover Vector via Vishing

Colleagues, I would like to draw your attention to an important cybersecurity case.

Attackers are using phone calls and spoofed Microsoft Entra pages to persuade users to register a new passkey.

The scenario looks convincing: the victim is guided through a fake sign-in flow, their password and MFA code are captured, and the attacker then completes passkey registration under their own account.

The danger lies in abusing trust in passkeys, a technology many consider more secure.

Why this matters: even protective mechanisms can be turned against users if they do not verify the request and its context.

Are you already reviewing your sign-in verification procedures and employee training? #cybersecurity #phishing #Microsoft365 #Passkey

Open analytics
On the site 5 views
min read 1 10.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Fake Entra Passkey Registration: A New Microsoft 365 Takeover Vector via Vishing

Open the post on Instagram ↗