Overview: Entra Passkey Enrollment Vishing Campaign
A new and concerning Phishing campaign leveraging voice-based social engineering, known as vishing, is actively targeting Microsoft 365 users across various sectors. The objective of this campaign is to trick users into enrolling a malicious Entra passkey, thereby granting attackers unauthorized and persistent access to their Microsoft 365 accounts. This method poses a significant threat as it can bypass traditional multi-factor authentication (MFA) mechanisms, leading to potential account takeover and subsequent access to sensitive organizational data.
According to BleepingComputer, this sophisticated attack focuses on exploiting user trust and a legitimate security feature – passkey enrollment – for malicious ends. Security professionals must understand the nuances of this TTP to effectively protect their organizations.
The Vishing Tactic: How Attackers Exploit Trust
Attackers initiate the campaign by contacting targets via phone, often impersonating internal IT support, security personnel, or even external service providers. The vishing call typically involves a fabricated security alert, such as unusual activity detected on the user’s account, a pending security update, or a request to verify account details. The impersonator then instructs the user to navigate to a seemingly legitimate Microsoft-branded page or follow specific prompts to “secure” their account. This is where the passkey enrollment comes into play.
The attacker guides the user through the process of enrolling a new passkey, ostensibly to enhance their account security. However, this passkey is generated by the attacker and enrolled on their device, or is generated by the user on their device but the enrollment process is intercepted or initiated maliciously by the attacker. Once enrolled, the attacker’s device effectively becomes a trusted authentication method for the victim’s Microsoft 365 account, enabling seamless access without requiring further traditional MFA prompts. This is a critical bypass, as passkeys are designed to be a more secure alternative to passwords and many forms of MFA, making their malicious enrollment particularly impactful.
Deep Dive into the Attack Chain
The attack typically unfolds in several steps:
- Initial Contact: A vishing call is made to a targeted employee, using caller ID spoofing to appear legitimate.
- Social Engineering: The attacker establishes rapport and creates a sense of urgency or fear, convincing the victim their account is at risk.
- Malicious Instruction: The victim is instructed to visit a specific URL or open a security notification that initiates the passkey enrollment process within Entra ID (formerly Azure Active Directory).
- Passkey Enrollment: The victim is coerced into approving a passkey enrollment request. Crucially, this passkey is under the attacker’s control or is being enrolled for the attacker’s device.
- Account Takeover: With the malicious passkey successfully enrolled, the attacker gains persistent access to the victim’s Microsoft 365 environment, including email, SharePoint, Teams, and other integrated services.
This campaign leverages the inherent trust users place in official communications and the complexity of modern authentication systems. The ability to bypass strong MFA through this method highlights a critical gap in security awareness and process enforcement.
Mitigating Entra Passkey Vishing Threats
Protecting against this advanced form of Phishing requires a multi-faceted approach, focusing on technology, policy, and, most importantly, user education. Organizations must prioritize strategies to prevent Microsoft 365 account takeover via vishing and enhance their detection capabilities.
Proactive Defense Strategies
- User Training and Awareness: Conduct regular, robust security awareness training focused specifically on vishing and social engineering tactics. Emphasize that IT/security teams will never ask for credentials over the phone or guide users through direct security enrollment processes during an unsolicited call. Train users on how to detect Entra passkey enrollment vishing by identifying suspicious call requests, verifying identities, and understanding proper security procedures.
- Implement FIDO2 Hardware Keys: For critical accounts, enforce the use of FIDO2-compliant hardware security keys (e.g., YubiKey, Titan Security Key). These provide robust phishing resistance as they require physical interaction and are bound to specific domains, making malicious passkey enrollment by an attacker significantly harder.
- Conditional Access Policies: Utilize Microsoft Entra ID Conditional Access policies to restrict passkey enrollment to specific trusted networks, compliant devices, or administrators with elevated privileges. This reduces the attack surface for unauthorized enrollment.
- Review Authentication Methods: Regularly audit registered authentication methods for all users in Entra ID. Look for newly registered passkeys, especially for high-privilege accounts, and verify their legitimacy.
- “Verified ID” / Internal Verification: Establish clear internal procedures for employees to verify the identity of anyone claiming to be from IT or security, such as requiring a callback to a known internal number or using an internal chat system for verification.
Incident Response and User Education
- Clear Reporting Channels: Ensure employees know how to report suspicious vishing calls or requests immediately. A rapid response can contain potential breaches.
- Zero Trust Principles: Apply Zero Trust principles across your identity and access management strategy, assuming breach and verifying every access attempt.
- SOC Monitoring: Enhance SIEM and EDR monitoring for suspicious authentication events, such as new authentication method registrations from unusual IP addresses or locations, and rapid changes in user permissions.
By combining technical controls with comprehensive employee training, organizations can significantly reduce their exposure to this evolving vishing threat and secure their Microsoft 365 environments.