Fake passkey helpdesk calls are being used in social engineering campaigns targeting Microsoft 365 users. In these scams, an attacker may pretend to be an IT helpdesk representative and claim that the victim needs to update a passkey, multifactor authentication (MFA), or single sign-on (SSO) settings.
Microsoft Security reported in September 2026 that it had observed attacks in which passkey-themed phone calls and messages were used to direct victims toward phishing and device-code authentication flows.
The goal is not necessarily to break the passkey itself. Instead, the attacker may try to persuade the user to take an action that helps them gain access to a Microsoft 365 account.
What Is a Fake Passkey Helpdesk Call?
A fake passkey helpdesk call is a type of social engineering scam in which someone impersonates IT support.
The caller may claim that:
- Your Microsoft 365 account requires a security update.
- Your passkey needs to be registered again.
- Your MFA settings need to be changed.
- Someone is attempting to access your account.
- Your Microsoft 365 account could be disrupted.
- You need to complete an identity verification process.
The scammer may then provide instructions or send a link that appears to be related to Microsoft 365.
How the Microsoft 365 Passkey Scam Works
1. The Scammer Pretends to Be IT Support
The victim receives a phone call or message from someone claiming to work for the organization’s IT department.
Microsoft says observed attacks have included phone-based impersonation and messages directing employees toward Microsoft-themed sign-in experiences.
2. The Caller Creates a Sense of Urgency
The caller may say that the user’s Microsoft 365 account, passkey, MFA, or SSO needs immediate attention.
Creating urgency is a common feature of phishing and social engineering. Microsoft advises users to slow down when a message or caller demands immediate action.
3. The Victim Is Sent a Link
The attacker may send a website that looks similar to a legitimate Microsoft sign-in page.
Microsoft has reported that passkey-themed attacks can use phishing pages and device-code authentication as part of the attack chain.
4. The Attacker Attempts to Obtain Access
Depending on the technique, the victim may be persuaded to enter information, complete an authentication step, or authorize a device.
This can potentially give the attacker access to the victim’s cloud identity and Microsoft 365 resources.
Why Are Passkeys Being Used in These Scams?
Passkeys are designed to strengthen account security and provide protection against many forms of traditional phishing.
However, scammers can still target the person using the technology.
Instead of trying to steal the passkey itself, an attacker may attempt to convince the user to:
- Visit a fraudulent website
- Approve an unexpected authentication request
- Enter a device code
- Change account security settings
- Register an unauthorized authentication method
This makes security awareness an important part of Microsoft 365 account protection.
Warning Signs of a Fake Microsoft Support Call
Be cautious when an unexpected caller claims to be Microsoft or your organization’s IT department and asks you to:
- Provide a password
- Provide an MFA or verification code
- Approve an unfamiliar sign-in
- Register a new passkey
- Visit an unfamiliar website
- Install remote-access software
- Change security settings
- Act immediately without verifying the request
Microsoft also advises users to be cautious about suspicious links, unexpected messages, and requests that create unnecessary urgency.
How to Protect Your Microsoft 365 Account
Verify Unexpected Support Calls
If someone contacts you unexpectedly about your Microsoft 365 account, do not rely on the contact information provided by the caller.
End the conversation and contact your organization’s IT department using a trusted phone number, internal directory, or established support channel.
Don’t Share Authentication Codes
Never give an unsolicited caller your password or authentication code.
Also avoid approving an authentication request that you did not initiate.
Be Careful With Sign-In Links
If someone sends you a Microsoft 365 sign-in link unexpectedly, avoid clicking it.
Instead, open your normal browser or established Microsoft 365 access point yourself.
Microsoft recommends independently navigating to an organization’s legitimate website rather than using suspicious links supplied in messages.
Enable Strong Authentication
Organizations should use appropriate MFA and phishing-resistant authentication methods where available.
Microsoft also recommends security controls designed to protect identities and reduce phishing-related account compromise.
What If You Already Responded to the Scam?
If you provided information, followed the caller’s instructions, or approved an unexpected authentication request, don’t ignore the incident.
For a work or school Microsoft 365 account:
- Contact your IT or security team immediately.
- Explain what information or authentication action you completed.
- Ask the administrator to review recent account activity.
- Review authentication methods and devices associated with the account.
- Change compromised credentials where appropriate.
- Report the suspicious message or phishing attempt.
Microsoft recommends investigating compromised accounts and reviewing authentication activity when phishing has resulted in account access.
How to Report Microsoft 365 Phishing
Microsoft provides reporting options for suspicious Outlook and Teams messages.
For Outlook, Microsoft recommends using the Report > Report phishing option when a suspicious message is selected. Teams users can also report suspicious messages through the available reporting options.
You can read Microsoft’s full guidance here:
Protect yourself from phishing — Microsoft Support
For Microsoft 365 administrators, Microsoft’s guidance on anti-phishing protection is also useful:
Tune anti-phishing protection — Microsoft Learn
Fake Passkey Helpdesk Scam: Key Safety Tips
Remember these simple precautions:
- Don’t trust unexpected support calls automatically.
- Don’t share passwords or authentication codes.
- Don’t approve sign-ins you didn’t initiate.
- Don’t follow unfamiliar links from callers or messages.
- Verify IT requests through a trusted channel.
- Report suspicious activity quickly.
Final Verdict
Fake passkey helpdesk calls are a form of social engineering that can target Microsoft 365 users. The scam relies on impersonation and convincing users to perform authentication-related actions rather than necessarily compromising the passkey itself.
Passkeys and strong authentication can improve account security, but users should still be cautious when an unexpected caller asks them to change security settings, visit a website, or approve an authentication request.
When in doubt, stop the interaction and verify the request through a trusted channel.
Frequently Asked Questions
What is a fake passkey helpdesk scam?
It is a social engineering scam in which an attacker impersonates IT support and claims that a Microsoft 365 passkey or authentication setting requires an update.
Can a fake Microsoft support call compromise my account?
A caller cannot normally access an account simply by calling. However, social engineering can persuade victims to provide information or authorize authentication activity that may contribute to account compromise.
Should I give my Microsoft verification code to IT support?
Do not give authentication codes to an unsolicited caller. Verify the identity of the support representative through your organization’s established support process.
How can I recognize a Microsoft 365 phishing scam?
Watch for unexpected calls or messages, urgent security claims, unfamiliar links, requests for authentication codes, and instructions to approve sign-ins you did not initiate.
What should I do after a suspicious Microsoft 365 call?
Stop following the caller’s instructions and contact your organization’s IT or security team through a trusted channel. If you entered credentials or approved authentication activity, report that immediately.
Are passkeys safe?
Passkeys are designed to provide strong, phishing-resistant authentication. However, social engineering can still target users around the authentication process, which is why users should verify unexpected security requests.
