Blog, Cloud Security Blog, Identity and Access Management Blog, LOGON Blog
When Passkeys Become the Bait: A New Wave of Voice Phishing Targeting Microsoft 365
LOGON BLOG
When Passkeys Become the Bait:
A New Wave of Voice Phishing Targeting Microsoft 365

Author: Sandy Chu, LOGON Software Asia
Your users have passkeys. Your Conditional Access policies are in place. Your MFA coverage looks solid on paper.
So why are attackers still walking out with valid Microsoft 365 sessions?
Because they stopped attacking your technology. They started attacking your people—and the processes around them.
Since May 2026, Microsoft Security Research has tracked a wave of attacks that bypass passkeys entirely. No cryptography was broken. No private keys were extracted. Instead, attackers call your employees, impersonate IT support, and create enough urgency that the victim willingly completes an authentication action—one that authorizes the attacker, not themselves.


What Happens After the Attacker Gets In
In one case Microsoft examined, the attacker signed in from an unmanaged device. Within minutes, the session was accessing My Apps, My Profile, Microsoft Approval Management, and My Sign-Ins. From there: SharePoint Online, Outlook on the web, and internal business applications.
The session stayed active for about an hour while the attacker mapped what was available.
And if your Entra ID is your central SSO platform? The blast radius extends well beyond one inbox. Depending on the user’s permissions, attackers may reach Salesforce, Google Workspace, Dropbox, Slack, SAP, Adobe, Zendesk, Atlassian, and your internally developed applications.
Persistence: The Part That Ruins Your Weekend
Attackers don’t just grab and go. They register their own authentication methods—phone numbers, authenticator apps, software tokens—so they can come back later.
This means a password reset alone won’t remove their access. Neither will killing a single browser session. You need to review the entire identity: registered authentication methods, active sessions, refresh tokens, OAuth grants, mailbox rules, device registrations, and enterprise application permissions.
Miss one, and the attacker still has a way back in.
Low-and-Slow Data Theft
Attackers aren’t always smash-and-grab. Microsoft observed collection continuing for hours or days, generally accessing fewer than 1,000 files or emails per hour.
Why? Because it blends in. Volume-based detection rules won’t catch it. Your normal business traffic looks similar.
But over time, that’s a lot of documents and emails—especially if the compromised user has access to shared repositories or departmental mailboxes.

Why this matters to Enterprises in Asia
1. Hybrid IT creates blind spots
Many enterprises in Asia run on-prem Active Directory alongside Microsoft 365 or Entra ID. Different authentication flows, different teams, different views. Help desk staff often can’t tell whether a “passkey registration request” is legitimate.
2. Multilingual social engineering is more convincing
Attackers can conduct voice phishing in local languages, mimicking local IT support teams. When the message comes through Microsoft Teams from what looks like an internal account, it’s even harder to question.
3. BYOD is the norm
Your employees handle corporate authentication on personal phones outside MDM control. Phishing links sent there bypass your email gateways and endpoint protection entirely.
What LOGON Brings to the Table
At LOGON Software Asia, we help organizations close the process gaps that social engineering exploits—without slowing down your passwordless journey.
We approach this problem across four pillars.
1. Identity and Access Management Architecture
Built for complex Asian enterprise environments. Covers Windows logon (including offline), RDP and privileged sessions, VPN access, on-prem AD and multi-forest environments, hybrid cloud directories, and legacy systems that can’t be modernized.
What this means for you: Identity security controls extend beyond the cloud login page to every identity use case across your network.
2. AI-driven Social Engineering Simulation
Our solutions let you test your frontline against the exact techniques in this blog—not just email phishing, but AI-generated voice calls (vishing), SMS phishing (smishing), and deepfake-enabled scenarios.
What this means for you: An employee who has already received a convincing fake IT call—and learned to verify it through a trusted channel—is far less likely to fall for the real thing.
3. Self-Service Password Reset
Most users can help themselves when they’re locked out—if you give them the tools. Our self-service password reset capabilities handle password reset, account unlocks, and Temporary Access Pass issuance for Active Directory, cloud identity providers, and application-level systems like SAP, Oracle, and IBM.
What this means for you: Fewer calls to the help desk. Organizations typically see an 85% or greater reduction in password reset calls after deploying self-service.
4. Verified Help Desk Assistance
Authentication proves a device. It doesn’t prove a person. Our solution offers verified help desk assistance that makes the verification decision inside the ticket your agent is already working in—using contextual signals and configurable soft tokens. The agent facilitates, but never overrides the outcome. That produces a defensible, auditable result instead of a judgment call.
What this means for you: An attacker who can convince your support agent to reset MFA has bypassed every technical control you’ve deployed. Verified workflows ensure high-risk changes require proof of identity—not just a convincing phone manner.
5. Cloud Workload Protection (CWPP)
Real-time monitoring of cloud workloads with machine learning-based threat detection. When an account accesses SharePoint or OneDrive at abnormal times or from abnormal locations, the system triggers alerts or blocks automatically—rather than waiting for an obvious download spike.
What this means for you: You catch low-and-slow data collection that volume-based rules miss.
6. Cloud Security Posture Management (CSPM)
Many organizations are exposed because Entra ID’s default settings are too permissive. Our CSPM capabilities assess configuration deviations across IaaS, SaaS, and PaaS—identifying missing Conditional Access policies, over-granted OAuth permissions, and providing remediation guidance.
What this means for you: You find and fix the configuration gaps attackers exploit before they find them.
The Bottom Line
Enterprise authentication is now an attack surface that extends far beyond the login page.
Passkeys remove one of the most phishable secrets—the password. But attackers have shifted their focus to enrolment workflows, fallback mechanisms, user trust, access tokens, and the cloud applications behind a successful sign-in. They’re targeting your help desk, your employees’ personal phones, and the processes you built to make passwordless authentication work.
The organizations that come out ahead will be the ones that secure the entire identity lifecycle—not just the login moment—and prepare their people for the calls, messages, and conversations designed to work around it.
LOGON Software Asia helps organizations across the region strengthen Microsoft 365 identity security and reduce human risk—whether you’re just beginning your passwordless journey or looking to harden an existing deployment.
Ready to secure your identity perimeter?
Contact LOGON Software Asia today. Let’s talk about where your gaps are—and how to close them.


