Microsoft 365 accounts are increasingly targeted not just for passwords, but for the authentication process itself. Attackers are employing passkey-themed social engineering tactics to trick users into compromising their cloud identities, as first reported by Channel Insider.Microsoft has observed campaigns since May 2026 where threat actors impersonate IT support to guide employees through updating security features like passkeys or multi-factor authentication. These attacks utilize methods such as adversary-in-the-middle phishing and device code authentication to intercept credentials, steal session tokens, or authorize attacker-controlled sessions. Once access is gained, attackers can move laterally within Microsoft 365 services like Exchange Online, SharePoint, and OneDrive for reconnaissance and data collection.This trend highlights a broader identity security challenge, where even advanced authentication methods can be bypassed through social engineering. The attacks can originate on unmanaged personal devices, complicating endpoint security monitoring. Microsoft recommends investigating suspicious sign-ins and unusual authentication activity, and blocking device code flows where not explicitly needed. For managed service providers (MSPs) and channel partners, this underscores the need to secure the entire chain of trust around user accounts, beyond just implementing stronger authentication methods.Source: Channel Insider