Fake Passkey Prompts in Microsoft 365: How to Tell a Real Setup From a Phishing Trap

Reviewed by IT Cares technicians · Updated October 1, 2026

Laptop showing a sign-in window with a fingerprint and key icon beside a phone with a warning shield, illustrating a fake passkey prompt in Microsoft 365
A passkey is meant to stop phishing. Attackers now imitate the passkey setup itself to get in.

Quick fix (if you clicked or approved something)

  1. Do not click anything else in the message. Open a new browser tab and type mysignins.microsoft.com/security-info yourself.
  2. Look at every sign-in method listed. Delete any passkey, phone number, app or device you do not recognize, then change your password from the real Microsoft page.
  3. Sign out of all sessions, tell your IT administrator or IT provider, and read the recovery steps in What to do if you clicked, typed or approved.

What is happening: attackers are borrowing the passkey

Security researchers and the technology press reported in 2026 that criminals are using the idea of a passkey as bait: a fake "set up your passkey" message that pushes Microsoft 365 users to hand over access. The attacker does not break the passkey. The attacker persuades a person to start, approve or complete a step that looks like a security upgrade but gives the attacker a way in.

On September 9, 2026, the Microsoft Security Blog published a post titled "Passkey-themed social engineering leads to identity and cloud compromise", described on the blog listing as covering passkey-themed social engineering used to compromise identities and enable broader cloud attacks. In the weeks before and after, trade and general outlets (The Hacker News, Help Net Security, International Business Times and others) ran stories about fake passkey prompts aimed at Microsoft 365 users. We could read the Microsoft listing, but not the full text of that post, so this guide does not quote its internal findings. Everything below that goes beyond the headline is either taken from Microsoft's own documentation pages we did read, or is practical advice from our technicians, and we say which is which.

What this guide is, and is not

This is a practical check-list for non-experts and small-business owners. It is not an incident report on any one campaign, and we are not aware of, and do not claim, a current outage or breach at Microsoft. The reported problem is people being tricked, not passkeys failing.

Why a "security upgrade" message works so well

People have been told for years to use stronger sign-in methods. A message that says "your organization now requires a passkey" sounds like a helpful reminder from IT, not a threat. The attacker borrows three trusted ideas at once: the Microsoft name, the word "security", and a deadline. A rushed employee who has never seen a real passkey screen has nothing to compare it with, so the fake gets the benefit of the doubt.

That last point is the real lesson. If your staff have never been shown what a genuine enrollment looks like, any pretty page can pass as one. This guide gives you the comparison, plus the policy and training script to make it routine. For the basics of what a passkey is, our passkeys explained guide for business covers the foundation, and this article builds on it.

Real versus fake at a glance

The fastest test is to ask who started the process: if you did, from a page or app you opened yourself after signing in, it is probably genuine, and if a message started it for you, treat it as fake until proven otherwise. The table below compares the two experiences side by side.

QuestionGenuine passkey enrollmentSuspicious or fake prompt
Who started it?You, by opening Security info or the Authenticator app, or by following your IT team's announced rolloutAn email, text, QR code, chat message or pop-up that appeared on its own
Where does it live?Microsoft's own sign-in and security info pages, or the Authenticator appA look-alike address, a shortened link, a document viewer or a "secure message" page
Did you sign in first?Yes. Microsoft documents that you must complete multifactor authentication before registering a passkeyIt asks for your password and a code on the same page, then moves on to "set up your passkey"
What is the tone?Calm, optional wording, no threatsUrgent, with a deadline, a lock-out warning or a reference to HR or payroll
What does it ask you to approve?Creating a passkey with your own device lock: fingerprint, face or PINA code you must read out, a sign-in you did not start, or adding a "helper" device
What shows in Security info afterwards?One new passkey you recognizeAn unknown passkey, phone number, device or app you never added
Can you verify it another way?Yes, by calling IT or checking the admin announcementThe message discourages calling anyone ("do this now")

Keep this table in mind as you read the next sections. The twelve detailed tells later in the article are an expanded version of it. If you only have a minute, the first row alone catches most attacks.

How a real Microsoft passkey setup works

Per Microsoft's documentation, you create a passkey either inside the Microsoft Authenticator app or from the Security info page after signing in with multifactor authentication, and a work account setup follows the policies your organization has chosen. Knowing the true path is your best defense, because every fake has to deviate from it somewhere.

We read Microsoft Learn's page on registering passkeys in Authenticator (last updated July 2026) and its page on enabling passkeys in Microsoft Entra ID (last updated June 2026). Here is what they say, in plain terms.

Path 1: inside the Authenticator app

Microsoft calls this the recommended way to set up a passkey in Authenticator. You install the app from your phone's official store, add a work or school account, sign in, tap Create a passkey, and complete multifactor authentication. If needed, you set up a screen lock and turn on Authenticator as your passkey provider in the phone's own settings (on iPhone, under AutoFill and passwords; on Android, under passwords and accounts). Microsoft lists minimum versions: iOS 17 or later, and Android 14 or later.

Path 2: from the Security info page

You open a browser, sign in with multifactor authentication to the Security info page (the address Microsoft gives is mysignins.microsoft.com/security-info, also reachable through aka.ms/mysecurityinfo), choose + Add sign-in method, and pick Passkey in Microsoft Authenticator. The page then sends you to the Authenticator app to finish. When done, you return to the browser, and the new passkey appears in the list.

Path 3: a different device or a security key

Microsoft also documents a WebAuthn route for people who cannot sign in to the app, which can involve a nearby device and Bluetooth for cross-device registration. The page notes that this route does not work if the administrator has turned on attestation. A physical security key is another supported option, and our comparison of a YubiKey versus an authenticator app explains when it fits.

What you will never be asked to do in a genuine setup

Nothing on those pages tells you to read a code from your phone aloud to someone, to scan a QR code from an email, to install a remote-control tool, or to send a screenshot of your recovery details. Microsoft's own steps are all things you do on your own devices. If a "setup" asks for any of those extras, it is outside the documented process.

A typical attack flow, step by step

The details of any single campaign vary, but social engineering attacks aimed at account sign-in generally follow the same four-stage chain: lure, capture, persist, expand. The stages below describe the general pattern, not a play-by-play from one Microsoft report, because we could only read that report's headline.

  1. The lure. A message arrives that mentions passkeys or a "new security requirement". It might be an email that looks like it came from IT or HR, a text, a chat message, a shared-document notice or a pop-up on a web page. The text pushes a deadline.
  2. The capture. You click and land on a page designed to look like a Microsoft sign-in. It may ask for your email, password and a code. Some versions try to relay your entries to the real Microsoft site live, so your genuine code works for the attacker too. This is why a six-digit code is not phishing-proof.
  3. The persistence. Once inside, an attacker who wants to stay in will try to add something that survives a password change, such as another sign-in method, a registered device, or a mailbox rule. A "passkey enrollment" is attractive here because registering the attacker's own authenticator would make your account sign in for them in the future.
  4. The expansion. With a trusted foothold, the attacker reads email, requests payments from your contacts, searches files, and looks for access to cloud apps. Microsoft's headline for the September post mentions "identity and cloud compromise", which is this stage.

The defender's job is to break the chain at the earliest point. Stage one is free for you to refuse: you do not have to respond. Stages three and four are where your administrator's settings matter, which we cover in the hardening section. Our guide to business email compromise shows what the expansion stage looks like in the real world for a small company.

Why passkey-themed bait is smart for the attacker

Most staff are still unfamiliar with passkeys, and they have heard that passkeys are "the safe thing". That makes them less alert to a request that says "do this to be safer". It also creates a cover story for a surprise sign-in prompt: "that must be the passkey thing IT mentioned". Phishing is a human problem, and this bait works on the human soft spot of trusting good news about security. For more on how modern lures are written, see our guide on AI-generated phishing emails, which explains why spelling mistakes are no longer a reliable tell.

Illustration contrasting a genuine passkey key and padlock with a fake login card hanging on a fishing hook

12 tells of a fake passkey prompt versus a real enrollment

No single tell is proof, but two or more together mean stop: close the page and open Microsoft's real Security info page yourself. These twelve checks are IT Cares' practical heuristics based on how phishing generally works and on Microsoft's documented setup steps. They are not an official Microsoft list.

Tell 1: You did not ask for it

Real: you decided to add a passkey, or your IT team told you a rollout is coming and you recognize the message. Fake: a "required" setup appears out of nowhere. If you are unsure whether IT announced it, ask them by phone or in person, not by replying to the message.

Tell 2: It arrives through a side door

Real: you reach the setup through the Authenticator app or the Security info page. Fake: you reach it through an email link, text link, QR code, calendar invite, shared-file notice or chat. Any side door is a reason to go in through the front door instead.

Tell 3: The web address is not Microsoft's

Real: the address bar shows a Microsoft sign-in or account address (for example mysignins.microsoft.com for Security info, or a Microsoft sign-in page that your IT team has shown you). Fake: a long address, an extra word before or after "microsoft", a shortened link, or a document-sharing site. Zoom in on the part right before the first single slash, because that is the part that decides who owns the page. On a phone, press and hold a link to preview its address before opening it.

Tell 4: It asks for your password and codes together

Real: Microsoft asks you to prove it is you by signing in, then adds the passkey. Fake: a single page asking for your password, then a code, then a "verification" number. If a page asks you to type or read out a code in order to "activate" a passkey, back out.

Tell 5: Urgency and consequences

Real: calm, optional language. Fake: "within 24 hours", "account will be locked", "payroll will be delayed". Pressure is the attacker's main tool because it stops you from checking. Our guide on spear phishing explains why targeted lures lean on your job's deadlines.

Tell 6: A QR code replaces the link

Real: the documented cross-device flow uses a nearby device and Bluetooth, started by you on a Microsoft page. Fake: a QR code in an email, PDF or printed notice that says "scan to activate your passkey". QR codes hide the destination, which is why attackers like them, and we explain the trick in our quishing guide.

Tell 7: The sender or channel does not match

Real: an announcement from your known IT contact through the usual channel. Fake: a free mail address, a name that matches your boss but an address that does not, or a text from an unknown number. In a small office, an unfamiliar "IT helpdesk" that nobody hired is a red flag. For the SMS variant, see what is smishing.

Tell 8: It wants you to approve a sign-in you did not start

Real: when you start setup, one prompt on your own phone matches your action. Fake: a push notification that arrives while you are doing nothing, often repeated several times. Never approve a prompt you did not trigger, even if the pop-up says it is "part of passkey activation". Deny it and change your password.

Tell 9: It asks you to install something

Real: Microsoft documents installing the Authenticator app from an official app store. Fake: a download of a "security module", a browser extension, or a remote-access program. Installing the real app is fine, but only from the store listing you found yourself, not from a link in a message.

Tell 10: It asks for a recovery detail or a screenshot

Real: nothing in the documented steps asks you to send a recovery code, backup code or screenshot to anyone. Fake: "send us the code on your screen so we can finish." Those details let the attacker take over recovery. Our guide on a lost authenticator app shows how legitimate recovery is supposed to work.

Tell 11: You find an unfamiliar method afterward

Real: after setup, the Security info list shows one new passkey that you created, usually named after your device. Fake: an extra passkey, phone number or app that you never added. Check the list within minutes of any enrollment, and again if you ever suspect a trick. Microsoft's Entra page notes that details of a registered passkey can include its AAGUID, the identifier for the type of authenticator, so IT can tell whether it matches your phone or an unknown provider.

Tell 12: It discourages a second opinion

Real: it survives a phone call to IT. Fake: it warns you not to tell anyone, says IT is "unavailable", or sends follow-up messages when you pause. A process that cannot withstand five minutes of checking is not a security process.

Ten-second check before you touch any passkey prompt

  • I started this myself, from the app or from a page I typed in.
  • The address belongs to Microsoft, and I did not arrive through a link, QR code or pop-up.
  • I am not being rushed, threatened, or told to keep it secret.
  • It does not ask me to read out a code, send a screenshot, or install something.
  • If I am unsure, I will close it and ask IT before doing anything else.

What to do if you clicked, typed or approved something

Act in this order: stop using the suspicious page, change your password from a clean device, remove unknown sign-in methods, sign out everywhere, and tell your administrator, ideally within the hour. Speed matters more than perfection, because an attacker with a live session can add persistence quickly. The steps below are standard account-recovery practice from IT Cares technicians, matched to the Security info path Microsoft documents.

Case A: You only clicked the link or opened the page

If you landed on the page, saw it looked odd and closed it without typing anything, the risk is low. Close the tab, clear the notification if it was a pop-up, and tell IT so that others can be warned. Do not click again "to check". Run your security software if the page started a download, and do not open the file.

Case B: You typed your password or a code

  1. Use a different tab or device. Open a new tab and type mysignins.microsoft.com/security-info yourself. If you can, use your phone rather than the same computer.
  2. Change your password now. Pick a long, unique passphrase that you have never used elsewhere. If you reused the old password on any other site, change it there as well. A password manager makes this far easier, see our password manager guide.
  3. Review sign-in methods. In Security info, delete anything you do not recognize: an extra passkey, phone number, authenticator app or email address. Keep only the ones you added.
  4. Sign out everywhere. Ask your administrator to revoke your sessions, or use the sign-out-everywhere option if your account page offers it. Changing a password alone may not end a session the attacker already has.
  5. Tell your administrator or IT provider. They can review sign-in logs for your account, look for unfamiliar locations or devices, and check for forwarding rules.

Case C: You approved a prompt or created a passkey

This is the serious case. Follow Case B, and in addition: remove any passkey you did not knowingly create on your own device. If you do not recognize the passkey provider listed, treat it as the attacker's. Microsoft's documentation says you can delete a passkey from the Authenticator app (Settings, then Delete passkey) and from Security info, and an administrator can delete a user's passkey from the user's Authentication methods in the Microsoft Entra admin center. Ask your admin to do it if you cannot sign in.

Check what the attacker may have touched

Whether you did Case B or C, go through these places once your account is secure:

When the attacker changed your recovery details

If you can no longer sign in because the password, email or phone was changed, do not guess repeatedly. Use Microsoft's account recovery from a trusted device, and ask your administrator to reset your authentication methods. The pattern of "recovery details quietly replaced" is common across platforms, and our walk-through of an Instagram account where the email and phone were changed shows the same logic you will use here: regain the email first, remove the intruder's methods, then secure everything else.

Incident checklist: first 60 minutes

  • I stopped interacting with the message or page and kept the original for IT.
  • I changed my password from the genuine Microsoft page on a clean device.
  • I deleted every passkey, phone and app in Security info that I did not add.
  • My sessions were revoked or I signed out of all devices.
  • I checked mailbox rules, forwarding, and connected apps.
  • My administrator or IT provider knows, and has checked sign-in logs.
  • I warned colleagues not to open the same message.
  • If money or data was involved, I contacted my bank and reported the fraud.

What your administrator should look at

For the IT person reading this: in the Microsoft Entra admin center, open the affected user and review their Authentication methods, then review sign-in and audit logs around the time of the click. Look for a newly registered method or an unfamiliar device or location, and for sign-ins that succeeded after an unusual prompt. Revoke sessions, reset the password, remove unknown methods, and review mailbox rules in Exchange. Exact log names, retention and available features depend on your licence, so we do not list a one-size-fits-all procedure here. If you want a second pair of eyes, our team can do a remote review.

Microsoft 365 admin hardening, as documented by Microsoft

Microsoft's Entra documentation lets administrators control who can register passkeys, which types and makes are allowed, and whether sensitive resources require a passkey, and these controls turn a fake enrollment from "easy" into "blocked or logged". Everything in this section comes from the Microsoft Learn page "How to enable passkeys (FIDO2) in Microsoft Entra ID" (updated June 2026) and the Authenticator registration page, both opened on October 2, 2026. Screens and names can change, so always check the live page and your licence.

1. Know that passkeys are available in every Entra edition

The page states that passkeys (FIDO2) are available in all Microsoft Entra ID editions, including Entra ID Free, with no extra licences needed. That means a small business on a basic plan can still manage passkeys. Some Conditional Access features, mentioned below, can depend on your licence, so confirm before you plan.

2. Use passkey profiles to separate groups

Passkey profiles let you apply different rules to different groups, for example administrators versus frontline staff. Per the page, a profile sets whether attestation is enforced, which passkey types are allowed (device-bound or synced), and which authenticators are allowed or blocked by their AAGUID. Up to three profiles, including the Default, are supported. The page warns that after you opt in to profiles, you cannot opt out. Microsoft's own example for high-privilege accounts is to give IT admins and executives a profile with device-bound passkeys only and attestation enforced.

3. Understand attestation and its limits

The documentation says that if attestation is not enforced, Entra cannot guarantee any attribute of a passkey, including whether it is synced or device-bound. It also says synced passkeys do not support attestation, and that enforcing attestation affects registration only: people who registered earlier without it are not blocked from signing in later. Practically, for the most sensitive accounts, device-bound passkeys with attestation give you the clearest picture of what is registered.

4. Restrict which authenticators are allowed

The key restriction setting lets you allow or block specific makes by AAGUID. The page cautions that if you remove an AAGUID you previously allowed, people who used it can no longer sign in with that method, and that AAGUID lists are a policy guide rather than a strict security control when attestation is off. Test on a pilot group first.

5. Control self-service registration

The page describes a global setting, Allow self-service set up. If it is set to No, users cannot register a passkey through Security info, even when passkeys are enabled. For a small company in the middle of a phishing wave, you may choose to centralize enrollment for a short time so that only IT-led sessions create passkeys. That is a business decision with a support cost, so weigh it.

6. Rely on the recent-MFA requirement

Microsoft states that users must have completed multifactor authentication within the past five minutes before they can register a passkey. This is a useful brake: a fake page that does not first obtain valid MFA cannot register a passkey in Microsoft's real flow. It is also a reason that fully stolen sessions are dangerous, because an attacker who relays your genuine MFA in real time can satisfy that condition. Layered controls matter.

7. Require passkeys for sensitive resources

The page explains that you can use Conditional Access authentication strength, either the built-in phishing-resistant strength or a custom one that allows only passkeys (FIDO2), so that sign-in to sensitive resources needs a passkey. It requires at least a Conditional Access Administrator role to create. Consider doing this first for administrators and finance staff.

8. Mind the Bluetooth and network requirements

For cross-device registration, the Authenticator page says both devices need internet access and Bluetooth, and that certain endpoints (for example cable.ua5v.com and cable.auth.com) must be reachable without interception. If your office blocks these, registration fails, and staff may be tempted to follow a "helpful" workaround from a fake message. Fix the legitimate path rather than leaving a gap.

9. Know how to delete an unknown passkey

The page says an administrator can delete a user's passkey in the Entra admin center by opening the user, choosing Authentication methods, and deleting the passkey entry. Practice it once before an incident.

Known issues Microsoft lists

The page notes that passkey registration is not supported for guest users, and that if a user's UPN changes, they need to delete the old passkey and add a new one in Security info. If your staff report odd enrollment errors, check these before assuming an attack.

Control (from Microsoft Learn)What it doesGood first targetWatch out for
Passkey profilesDifferent passkey rules per groupAdmins and executivesCannot opt out after enabling
Enforce attestationVerifies make and model at registrationHigh-privilege accountsSynced passkeys do not support it
Key restrictions (AAGUID)Allow or block specific authenticatorsPilot group firstRemoving an AAGUID locks out its users
Allow self-service set upControls registration via Security infoShort-term lockdownRaises helpdesk work
Authentication strengthRequires passkeys for chosen appsFinance and admin rolesNeeds Conditional Access licence and role

Passkeys for non-experts: what they are and why they are still worth using

A passkey is a sign-in credential that lives on your device and is unlocked with your fingerprint, face or screen PIN, so there is no password to type, steal or reuse. It is tied to the real website, which is why a copy-cat page cannot use it. The fake prompts in this article work around that protection by tricking you, not by breaking it.

How a passkey differs from a password and a text code

Synced or device-bound: which is for you

Microsoft's documentation describes two types. A device-bound passkey stays on one device, such as a security key or Microsoft Authenticator. A synced passkey is stored encrypted with a provider such as Apple Passwords or Google Password Manager so your other devices can use it. The page says to treat synced passkeys as phishing-resistant but with the same security posture as other unattested authenticators. For most home users and small teams, synced passkeys are the practical choice because losing a phone does not mean losing access. For administrators and finance, device-bound with attestation gives tighter control. Our passkey business guide goes through the trade-offs in more detail.

Step by step: add a passkey safely yourself

  1. Update your phone. Microsoft's page lists iOS 17 or later and Android 14 or later for passkeys in Authenticator.
  2. Open the app you already trust. Open Microsoft Authenticator from your phone's home screen, not from a link.
  3. Add or select your work or school account and tap Create a passkey, then finish the MFA step.
  4. Set a screen lock if asked and turn on Authenticator as a passkey provider in the phone's settings.
  5. Confirm in Security info. Type the Security info address yourself, sign in, and make sure the new passkey is listed once.
  6. Keep a backup method. Do not delete your other methods until your IT team tells you it is safe.

Common misunderstandings that scammers exploit

"Passkeys mean I never have to worry about phishing." They greatly reduce it, but the setup and recovery steps can still be attacked. "IT will text me a link to set it up." Only if your company announced it; verify first. "Biometrics are sent to Microsoft." Your fingerprint or face unlocks the key on your device; it is the device lock, not a file sent to a website. "If I lose my phone I lose everything." That is why synced passkeys, a second method and a documented recovery process matter. Our guide to a lost authenticator app covers recovery before you need it.

Keep your multifactor basics strong too

Passkeys are one layer. If you are still rolling out MFA across a company, start with our MFA guide for business owners, and make sure email, the usual target, is secure with the steps in our Microsoft 365 and Google Workspace email guide.

A one-page passkey and sign-in policy for a small business

A small business only needs about seven written rules to make fake passkey prompts far less effective, and the most important one is that nobody registers or approves a sign-in method unless they started it themselves. Copy the template below, adapt the names, and share it with every employee, including part-timers and contractors.

Sign-in security policy template (adapt to your company)

  1. Start it yourself. Add or change a sign-in method (passkey, phone, app, security key) only from the official app or by typing the Microsoft Security info address yourself.
  2. Announcements come from one place. IT announces any rollout by [phone call / staff meeting / intranet]. A message about passkeys that was not announced there is treated as suspicious.
  3. Never approve what you did not start. Deny any unexpected sign-in prompt, then tell IT.
  4. Never share codes or screenshots. No one at the company or at Microsoft will ask you to read out a code or send a recovery detail.
  5. Report fast, no blame. Report a clicked link or approved prompt immediately. Quick reporters are thanked, not blamed.
  6. Check your methods quarterly. Everyone reviews their Security info list every three months and removes anything unfamiliar.
  7. Offboarding. When someone leaves, IT removes their methods, sessions and devices the same day.

Rules for the person who manages IT

Whoever administers Microsoft 365 should add four duties to the policy: keep at least two accounts with admin rights and protect them with the strongest method you can manage; assign passkey rules by group as Microsoft's documentation describes; keep a written recovery procedure so that a locked-out employee is verified by a person, not by a message; and know who to call if an incident happens at 7 pm on a Friday. Our guide on business email compromise explains why the payment and invoice side of the company deserves the same attention.

Add a verification habit for money and access requests

Many account takeovers end in a request for money, gift cards, changed bank details or file access. Add a rule: any request that changes how money moves or who can access what is confirmed by a second channel, such as a phone call to a known number, regardless of who appears to have sent it.

A 15-minute staff training script

The most effective training is short, concrete and repeated: show the real screens, show a fake, and let people practise saying "I will check first". Use the script below in a team meeting, adjusting names and tools. It needs no technical background.

Minute 0 to 3: the story

Say: "Attackers are sending fake messages that say we need to set up a passkey. They know people want to be secure and they know we are busy. The message is designed to make us click before we think. Today we will learn how to spot it in ten seconds."

Minute 3 to 7: show the real thing

Open the Security info page live on a shared screen (typing the address, not clicking a link). Show the list of sign-in methods and where a passkey would appear. Open Authenticator and show where Create a passkey lives. Say: "A real setup happens here, because we opened it ourselves."

Minute 7 to 11: show three fakes

Show three mock messages (draw them on a slide, do not use a live phishing page): one with an urgent HR deadline, one with a QR code, one from a "helpdesk" you do not have. Ask the team to point at the tells from the twelve-tell list earlier. Our guides on what phishing is and quishing give additional examples to borrow.

Minute 11 to 14: practise the response

Teach one sentence staff can say without embarrassment: "I will check this with IT first." Have everyone say it aloud. Show how to report: forward the message as an attachment or screenshot to [IT contact], and then delete it. Remind them that if they clicked, they should report straight away, because speed limits the damage.

Minute 14 to 15: the three rules

Repeat the exercise every quarter with a new example. Lectures fade; repetition builds a habit. If you would like a trainer to run this session for your team, IT Cares can deliver it remotely.

Three realistic scenarios (illustrative)

These scenarios are invented illustrations to show how the checks work in practice, not real cases or real clients. Names and numbers are made up.

Scenario 1: The urgent email at 4:50 pm (illustrative)

A bookkeeper at a 9-person company gets an email that says everyone must set up a passkey by 5 pm or lose access to payroll. It has a button. She remembers the training, does not click, and instead types the Security info address into a new tab. Nothing is waiting for her there. She calls her IT provider, who confirms there is no rollout. Time spent: four minutes. Loss: none. The rule that saved her was Tell 1: she had not asked for it.

Scenario 2: The employee who entered a code (illustrative)

A sales rep clicks a link in a chat message, signs in on a page that looks right, and enters a code. A few minutes later he realizes the message did not come from a colleague. He follows Case B in this guide: new password from a clean phone, Security info review, an unknown phone number removed, sessions revoked by IT, and a mailbox-rules check that finds a forwarding rule. Total time to contain: about 50 minutes. Because he reported at once, no invoices were altered. Had he waited a day, the story could have ended differently.

Scenario 3: The unexpected passkey in the list (illustrative)

During a quarterly review, an office manager sees a passkey named after a device she has never owned. She deletes it, changes her password, tells IT, and learns from the sign-in logs that an unfamiliar location had signed in two weeks earlier. IT reviews mailbox rules, finds nothing, and tightens the policy so that new passkey registration needs an IT-led session for the next month. The quarterly review habit was the control that worked.

What it costs in CAD: do it yourself or get help

Most of this is free: reviewing sign-in methods, changing a password and running a training session cost only time, while a professional review is worth paying for when money, client data or admin accounts may be exposed. The figures below are rough planning numbers, not quotes.

TaskDIY costTimeWhen to pay for help
Review your own sign-in methodsFree10 minutesIf you find items you cannot explain
Password reset and session sign-outFree15 minutesIf you are locked out
Password manager for a teamPaid per user, varies by product1 to 2 hoursFor setup and migration
Physical security keys for adminsRoughly 30 to 80 CAD per key (market range, varies)30 minutes eachFor rollout and recovery planning
Policy and training sessionFree using the template above2 to 3 hours to prepareIf you want it delivered for you
Compromise review (logs, rules, apps)Not recommended without experience1 to 3 hoursUsually, yes

A single IT Cares Expert Consultation is 119.99$ CAD for 60 minutes, which is enough to review one account, clean up sign-in methods and write a short policy. Compare that to the cost of a fraudulent invoice, a day of lost work, or a privacy notification obligation after a breach, and the check is cheap.

Official resources

For authoritative steps, use Microsoft's own documentation and your national fraud-reporting body rather than blogs or messages.

When to call a professional

Call a professional if you approved a prompt, entered credentials into an unfamiliar page, found a sign-in method you did not add, or you manage an account that handles payments or client data. Those are the cases where hidden persistence, such as forwarding rules or extra devices, is most likely and most costly.

IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. We can review your sign-in methods, help recover an account, tighten Microsoft 365 settings and train your staff, remotely and while you watch. Call 1 (888) 711-9428 or book a session. A 60 minute Expert Consultation is 119.99$ CAD.

Still stuck? Get a technician on it now

Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.

Frequently asked questions

What is a fake passkey prompt?
A fake passkey prompt is a message, web page or pop-up that imitates the Microsoft process for adding a passkey to your account. Its real purpose is to trick you into signing in on a look-alike page, approving a sign-in, or registering the attacker's device as one of your sign-in methods. Reports in the security press during 2026 describe this passkey-themed social engineering as aimed at Microsoft 365 users.
Are passkeys themselves unsafe?
No. Passkeys are designed to resist phishing because the credential is tied to the real website and is not typed or sent like a password. The risk described in these reports is around the human steps surrounding passkeys, such as the enrollment and the recovery process, not the passkey cryptography. A passkey you created yourself on a page you opened yourself is still one of the strongest sign-in methods available.
How do I know if a passkey setup request is real?
A real request is one you started. Microsoft's documentation describes setting a passkey up by signing in to Authenticator directly, or by opening Security info and choosing Add sign-in method after you have signed in with multifactor authentication. If the request came from an email, text, QR code or pop-up you did not start, treat it as suspicious and open the official page yourself.
What should I do if I entered my password on a fake page?
Change your password right away from the genuine Microsoft sign-in page, then review your sign-in methods and sign out of all sessions. Tell your administrator so they can look at sign-in logs. Do this even if nothing looks wrong, because attackers often wait before using a stolen session.
What if I approved a prompt in Microsoft Authenticator?
Treat it as a compromised session. Reset your password, remove any sign-in method you do not recognize in Security info, and ask your administrator to revoke your active sessions. Then check your mailbox rules and forwarding settings, because a common follow-up step in account takeovers is hiding or forwarding mail.
Can my administrator see if someone registered a passkey on my account?
Administrators with the proper role can open a user's authentication methods in the Microsoft Entra admin center and see the registered methods, and Microsoft's documentation notes that the details of a registered passkey include its AAGUID, which identifies the type of authenticator. Sign-in and audit logs are the place to look for when a method was added. Exact log names depend on your licence, so ask your IT provider to check.
Is SMS still a safe way to get codes?
SMS codes are the weakest common second step because they can be intercepted or socially engineered. Press reports in September 2026 said Microsoft is retiring SMS authentication in Entra, but we did not confirm dates on a Microsoft page, so check your admin center message center for current timelines. Moving to Authenticator or passkeys is the better direction regardless.
Does this only affect Microsoft 365 business accounts?
The reports focus on Microsoft 365 and Entra work or school accounts, but the pattern applies to any account that offers passkeys, including Google, Apple and banking apps. The same rule works everywhere: start the setup yourself from the official site or app.
Should my small business turn passkeys off to be safe?
Not as a rule. Passkeys remain far more resistant to phishing than passwords and text codes. A better step is to control how and where staff can register them, require a recent sign-in before registration, and train people on the tells in this guide. Microsoft documents settings such as requiring recent multifactor authentication before passkey registration and restricting which authenticators are allowed.
What is the difference between a synced and a device-bound passkey?
Per Microsoft's Entra documentation, a device-bound passkey stays on one device such as a security key or Microsoft Authenticator, while a synced passkey is encrypted and synced through a provider such as Apple Passwords or Google Password Manager so other signed-in devices can use it. Microsoft notes synced passkeys do not support attestation. Businesses can choose which types to allow per group.
Who do I report a phishing attempt to?
Report it to your IT administrator first. In Canada you can also report fraud to the Canadian Anti-Fraud Centre, and if you lost money or data, tell your bank and consider a police report. Keep the original message, and do not forward it to colleagues as a live link.
Can IT Cares help me check an account I think was compromised?
Yes. IT Cares offers remote support for account recovery, sign-in review and staff awareness setup. You can call 1 (888) 711-9428 or book a session. A 60 minute Expert Consultation is 119.99$ CAD.

Sources and official references

Last verified: October 1, 2026

Need Help?