Microsoft warns attackers are using passkey and MFA update requests to phish employees, hijack sessions, and access Microsoft 365 data.
Attackers persuade employees to accept a remote-control request during screen sharing or to open Quick Assist and provide its access code.