Microsoft Entra passkey vishing campaign
- Attackers used voice-phishing calls on July 8 to trick Microsoft 365 users into enrolling new Microsoft Entra passkeys, according to BleepingComputer. (bleepingcomputer.com) - Microsoft says passkeys are phishing-resistant, but users can still be prompted to register one through campaigns or policy, creating an opening for social engineering. (learn.microsoft.com) - Microsoft’s deployment guides say Security Administrators manage passkey campaigns and Temporary Access Pass can be used for registration workflows. (learn.microsoft.com)
BleepingComputer reported on July 8 that a threat actor has been calling employees at organizations in multiple sectors and posing as internal security staff to get Microsoft 365 users to enroll a new Microsoft Entra passkey. The tactic does not break passkey cryptography. It targets the enrollment step, where a user can still be persuaded to approve a new credential under false pretenses. (bleepingcomputer.com) Microsoft’s own documentation says users can be prompted to register a passkey through an adoption campaign or because an administrator requires it through policy. (learn.microsoft.com) Microsoft describes passkeys in Entra as phishing-resistant because they use origin-bound public-key cryptography and local user interaction. But the company’s guidance also shows that registration is an administrative workflow with roles, policies and rollout campaigns behind it. (learn.microsoft.com) That makes the support process around enrollment as important as the technology itself. ### How are the callers getting users to create a credential they should not create? BleepingComputer said the caller’s pitch is a fake security request: the victim is told to enroll a new Entra passkey as part of an urgent internal action. The report said the campaign has targeted organizations across several sectors and uses voice contact rather than a conventional email phish. (bleepingcomputer.com) Microsoft’s registration documentation shows that adding a synced passkey can be a normal browser-based flow on Windows, iOS or Android. In practice, that means a user who believes the caller is legitimate may see a real enrollment screen and complete a real registration, even though the request itself is fraudulent. (learn.microsoft.com) ### Why does a passkey attack start at the help desk instead of the login page? Microsoft’s Entra guidance says passkey rollouts are governed through authentication methods policy, Conditional Access settings and campaign management by administrators. BleepingComputer reported that the social-engineering effort is aimed at the people and processes that can authorize or normalize identity changes, including service-desk interactions. (bleepingcomputer.com) Microsoft also says users may see a passkey prompt when a registration campaign is enabled or when policy requires phishing-resistant authentication. That means a phone call that references a real tenant change, a real rollout or a real prompt can sound credible unless the organization has a separate verification step. (learn.microsoft.com) ### What does Microsoft’s own guidance say about controlling this workflow? Microsoft says Security Administrators are required to manage passkey campaigns in the Conditional Access Optimization Agent. The company also says organizations should use a persona-based deployment, group users for rollout, and plan the operational steps before enforcing phishing-resistant credentials broadly. (learn.microsoft.com) A separate Microsoft policy guide for administrators says Temporary Access Pass can be used to register passwordless authentication methods, but warns that requiring phishing-resistant MFA before registration is complete can lock an organization out of its tenant. That warning underscores that registration is a privileged change path, not a routine click-through. (learn.microsoft.com) ### If passkeys are phishing-resistant, what exactly is being compromised here? Microsoft says passkeys are designed to stop remote phishing of the credential itself. The weakness in this case is not replaying or stealing the passkey after enrollment; it is persuading a user to create a new approved sign-in method for the wrong party or under the wrong pretext. (learn.microsoft.com) BleepingComputer has reported other recent Entra-focused vishing activity, including attacks using device code flows. Taken together, those reports show attackers continuing to target Microsoft identity workflows that rely on user approval during a legitimate Microsoft process. (learn.microsoft.com) ### What should readers watch for next inside their own tenant? Microsoft’s current documentation says users can encounter passkey registration through adoption campaigns, explicit policy requirements and supported registration flows across desktop and mobile platforms. Organizations reviewing this campaign will likely start with those settings, the roles allowed to manage them, and the scripts their support teams use when a caller or ticket requests a new authentication method. (learn.microsoft.com) The next concrete checkpoint is in Microsoft’s Entra admin guidance: passkey campaigns are reviewed in the Conditional Access Optimization Agent, and registration methods are controlled in Authentication methods policy pages. Those are the named controls administrators would use to verify whether any unexpected enrollment activity has been introduced. (bleepingcomputer.com) (learn.microsoft.com 1) (learn.microsoft.com 2)