Act
active
Passkey-themed social engineering enables M365 identity and cloud compromise
- Engineer — Plan: No exploitation-pressure signals, but the MFA persistence and Microsoft Graph abuse techniques described warrant auditing Entra ID registered authentication methods for unexpected passkey enrollments and reviewing conditional access policies governing Graph API access this quarter.
- SOC/IR — Act: The article documents TTPs mappable to ATT&CK — MFA persistence registration and Microsoft Graph reconnaissance — against a near-universal enterprise target (M365); implement or tune detections for anomalous Graph API enumeration calls and unexpected MFA method additions, and hunt for such activity since early September 2026.
- Leader — Plan: Passkey rollout communications are now a social engineering attack surface; if your organization is mid-deployment, review user-facing passkey enrollment messaging for impersonation risk and include this TTP in the next security-awareness training update.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.