Call or Text - 
Orlando & Central Florida:
407-554-5534
Naples & Southwest Florida:
239-653-0252
cybernetic_logo_white
Schedule a Free Consultation

Fake IT Support Is Calling About Passkeys: How to Protect Your Microsoft 365 Account

09/16/2026
2149445127(1)

A caller says they are from IT. They know your company’s name, sound professional, and warn that your Microsoft 365 passkey or multifactor authentication must be updated immediately.

It feels like routine technical support. That is exactly why the scam works.

Microsoft recently reported an active campaign in which attackers use passkey, single sign-on, and multifactor authentication updates as a pretext. The objective is not necessarily to steal a passkey. Instead, the attacker persuades an employee to complete a sign-in process that gives the criminal access to the employee’s cloud account.

For a small business, one successful conversation can expose email, OneDrive files, SharePoint documents, customer information, and internal communications.

What Does the Scam Look Like?

The attack often begins with an unsolicited phone call, text message, email, or Microsoft Teams message. The person claims to represent the company’s IT department or technology provider.

They may say:

  • Your passkey must be registered or synchronized.
  • Your Microsoft 365 account will stop working.
  • Your multifactor authentication needs an urgent reset.
  • A new single sign-on system is being activated.
  • You must enter a code to prevent your account from being disabled.

The employee may then receive a link to a convincing sign-in page. In some cases, the attacker asks the employee to enter a device code on a genuine Microsoft webpage. Although the page itself is real, entering the code can authorize the attacker’s session.

That distinction matters: seeing a familiar Microsoft page does not automatically mean the request is legitimate.

Why Passkeys Are Not the Problem

Passkeys remain a strong sign-in method. They are designed to resist ordinary password phishing and are generally safer than reusable passwords or text-message codes.

The danger is the surrounding conversation.

Criminals are taking advantage of the fact that many employees are still learning what passkeys are. A technical-sounding caller can turn that uncertainty into urgency and persuade someone to follow an unauthorized enrollment or approval process.

Microsoft’s report also notes that some attackers add their own authentication method after gaining access. This can help them return even after the employee changes a password.

What Could Happen After One Account Is Compromised?

A Microsoft 365 account can contain far more than email. Depending on the employee’s access, a criminal may be able to:

  • Read email and search attachments.
  • Download files from OneDrive or SharePoint.
  • Review internal contacts and organizational information.
  • Create hidden inbox rules that redirect or conceal messages.
  • Impersonate the employee in future payment or account-change requests.
  • Use a trusted Teams or email account to target other employees.
  • Add an unauthorized authentication method for continued access.

Microsoft observed compromised identities being used to examine cloud resources and collect business data over time. This means an incident may not produce an immediate, obvious warning.

A Simple Rule Employees Can Follow

Employees should never complete an unexpected authentication change while communicating with the person who initiated the request.

Instead:

  1. End the call or conversation.
  2. Do not open the supplied link or enter a device code.
  3. Contact the company’s known IT provider using a saved telephone number, support portal, or established email address.
  4. Ask whether the request is legitimate.
  5. Report the caller’s number, message, link, and approximate time of contact.

Even if the message appears to come from a coworker’s Teams or email account, verify unusual authentication requests through a separate channel. A trusted account may already have been compromised.

Steps Business Owners Should Take

Establish a Verified Support Process

Employees should know exactly how real IT requests will arrive and how to confirm them. Provide one official support number or portal and include the procedure in new-employee onboarding.

Explain Device-Code Requests

A device code can authorize access without revealing a password. Employees should never enter a code that was supplied by an unsolicited caller or message.

Review Authentication Methods

An administrator or managed IT provider should periodically check which phones, authenticator apps, passkeys, and security keys are registered to important accounts. An unfamiliar method should be investigated promptly.

Strengthen Microsoft 365 Access Controls

Microsoft recommends phishing-resistant sign-in methods such as properly deployed passkeys, FIDO2 security keys, and Windows Hello for Business. Organizations can also restrict authentication registration, block unnecessary device-code flows, and require managed devices for sensitive services.

These settings should be planned and tested by someone familiar with Microsoft 365 administration. Changing access policies without preparation can lock legitimate employees out of their accounts.

Watch for Unusual Activity

Warning signs can include unexpected authentication registrations, unfamiliar sign-ins, newly created mailbox rules, unusual file downloads, and access from unmanaged devices.

What to Do If an Employee Followed the Instructions

Contact your IT or cybersecurity provider immediately. Do not wait for suspicious email activity to appear.

A qualified administrator may need to revoke active sessions, reset credentials, remove unauthorized authentication methods, examine mailbox rules, and review activity across Exchange, OneDrive, SharePoint, and Microsoft 365.

Changing the password alone may not terminate an already authorized session or remove an authentication method added by the attacker.

Make Verification Easier Than Compliance

Employees are more likely to resist social engineering when they have a quick, familiar way to verify requests. The goal is not to make staff afraid of every technology change. It is to make stopping and checking a normal part of the process.

Cybernetic Networks can help Orlando-area businesses establish a verified IT support process, review Microsoft 365 authentication settings, monitor suspicious account activity, and guide employees through passkey adoption safely. A short review today can prevent an urgent-looking support call from becoming a much larger business disruption.

Source Links

Quotes from our Customers

Posted on Google Google
Lori Hall Patel profile picture
Lori Hall Patel
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Fantastic service!
Posted on Google Google
Yaritza Quintero Luis profile picture
Yaritza Quintero Luis
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cybernetic Networks Inc. provides excellent tech support for the office. Himala is always responsive, knowledgeable, and quick to resolve any issues I run into. I truly appreciate his reliability and professionalism—highly recommended!
Posted on Google Google
Carlos Villoch profile picture
Carlos Villoch
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
From the very first call to Cybernetic, the team was responsive, knowledgeable, and genuinely committed to solving my issues. Their proactive approach and genuine care are what really stood out above any other IT Support Businesses. If you’re looking for IT support that’s dependable, friendly, and truly invested in keeping your technology running smoothly, this is the team you want. I can’t recommend them highly enough.
Posted on Google Google
KIMBERLY profile picture
KIMBERLY
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I would highly recommend Cybernetic Networks Inc. to anyone looking for reliable and trustworthy tech support.
Posted on Google Google
Tom moore profile picture
Tom moore
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Himala and his team at Cybernetic Networks have been amazing. We have been a customer of Cybernetic Networks for well over 14 years now, both personally and professionally. Himala and his team are professional, reachable and on the cutting edge of technology. We have enjoyed doing business with Cybernetic Networks for many years and still rely on their knowledge, skills and technology every day.
Posted on Google Google
Daniel Fusco profile picture
Daniel Fusco
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Himala and his Cybernetic team have never let me down! For over 10 years now they have been fixing my technical issues, set up all my new networks and computers and have safeguarded me from any hackers or malware. You can trust this company to navigate you as your company grows and to keep you on track with the latest in security and safety.
Posted on Google Google
Beth Wolff profile picture
Beth Wolff
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Cybernetic Networks has been advising and supporting all our IT issues and purchases for the last 18 years. They are very responsive and extremely knowledgeable- always providing us with timely services.
Posted on Google Google
Brian Wolff profile picture
Brian Wolff
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I am a solo practicing neurologist and have had all my IT needs covered through Cybernetic Networks since 2007. They are the best! All of their tech support staff is extremely knowledgeable and efficient. Just as importantly, they are quickly responsive whenever we need their assistance. I couldn’t be happier with their service and give them my highest recommendation!
Posted on Google Google
Patti Muzzonigro profile picture
Patti Muzzonigro
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
I couldn't be happier with Cybernetics - they are experts, always respond quickly , and solves any issues I have.
Posted on Google Google
sue myhelic profile picture
sue myhelic
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
It is not often you find small business companies that are not only rewarding to work with, but also have integrity, truth and skill. I have worked with this company for over 20 years, and the service is outstanding. I can easily recommend that if you need an IT company, this is the one to get. Full STOP! Look no further, you will be happy that you did. Sue Myhelic, Gulf Breeze Real Estate, Naples, Florida.