Passkeys have emerged as an important step toward stronger, phishing-resistant authentication. But new security research shows that even advanced authentication technology can introduce risks when weaknesses exist elsewhere in the process.
Researchers at SpecterOps identified more than 20 “Pass-the-Passkey” attack techniques involving Windows 11, Microsoft Entra ID, browsers, password managers, and enterprise authentication workflows. The techniques demonstrate how attackers could potentially undermine passkey protections without stealing the private cryptographic keys themselves.
For MSPs managing Microsoft environments and protecting client identities, the findings provide several important insights.
1. Strong Authentication Still Depends on Secure Implementation
Passkeys make traditional credential theft and phishing significantly more difficult. However, the research demonstrates that attackers may not need to defeat the underlying cryptography.
Weaknesses in how authentication information is logged, validated, and processed can create other avenues for attack.
For MSPs, that reinforces why stronger authentication should remain one part of a broader identity security strategy.
MSP Action: Evaluate passkeys alongside endpoint protection, authentication policies, access controls, monitoring, and secure identity configurations rather than treating them as a standalone solution.
2. Windows 11 Patching Remains Critical
One key finding involved Windows 11 logging complete WebAuthn assertion responses during passkey authentication. Those logs could contain information that an attacker with sufficient endpoint access could potentially harvest and replay.
Microsoft addressed the vulnerability, tracked as CVE-2026-34348, in its July 14, 2026 security release. Updated Windows 11 systems now truncate signature fields within logged assertions to prevent the replay technique.
MSP Action: Verify that managed Windows 11 endpoints have received the appropriate July 2026 or later security updates and include CVE-2026-34348 in patch compliance reviews.
3. Identity Security Extends Beyond the Endpoint
Researchers also identified server-side weaknesses involving Microsoft Entra ID, including issues related to challenge reuse, session binding, and authenticator signature counters.
Combined with authentication assertions obtained from compromised systems, these weaknesses could potentially enable attackers to impersonate users while satisfying phishing-resistant MFA requirements.
The lesson for MSPs is that authentication security must be evaluated across the complete identity environment.
MSP Action: Review endpoints, Entra ID configurations, cloud applications, authentication policies, privileged accounts, and monitoring systems for potential gaps throughout the identity chain.
4. Privileged Accounts Require Additional Protection
The potential consequences become more significant when privileged administrators are targeted.
Researchers demonstrated how authentication material associated with privileged identities could potentially be used to access Microsoft cloud accounts. One recommended mitigation is hardware-backed passkey attestation for high-privilege Entra ID accounts.
That’s particularly relevant for MSPs whose technicians may hold administrative access across multiple customer environments.
MSP Action: Separate administrative and everyday accounts, minimize unnecessary privileges, strengthen privileged workstation security, and consider hardware-backed authentication for high-risk administrative identities.
5. Authentication Monitoring Needs to Evolve
Pass-the-Passkey techniques extend beyond replay attacks. Researchers also demonstrated how malware could abuse legitimate WebAuthn APIs to generate convincing authentication requests.
Techniques include repeated credential prompts, application identity spoofing, passkey requests tunneled through Remote Desktop sessions, and malicious interfaces layered over legitimate Windows credential windows.
That means MSPs may increasingly need visibility into how and where authentication requests originate, not simply whether authentication succeeds.
MSP Action: Monitor for unusual WebAuthn activity, unexpected applications invoking authentication APIs, suspicious Remote Desktop behavior, repeated credential prompts, and anomalous privileged authentication.
The Bigger Lesson for MSPs
The Pass-the-Passkey research doesn’t mean organizations should abandon passkeys. They remain fundamentally stronger than password-based authentication, particularly when device-bound hardware authentication is used.
Instead, the findings reinforce a broader cybersecurity principle: strong authentication still requires strong implementation.
MSPs can help clients benefit from modern authentication while ensuring the endpoints, identity platforms, privileged accounts, policies, and monitoring surrounding it remain equally well protected.
