Skip to content
Some content is members-only. Sign in to access.

Microsoft's Identity Moat Faces Mounting Security Overhang

Persistent identity threats versus Foundry governance may reshape valuation and positioning

By KAPUALabs

One must consider what the system promised before one can judge how it failed. The principle dictates that security reside in the key, not in the obscurity of the mechanism. We must apply Kerckhoffs's lens to Microsoft's identity fabric, and what the material establishes from the outset is unsettling: adversaries defeat authentication without breaking its cryptography 18, turning trust in passkeys, MFA and single sign-on into the lure itself 3,5.

The cryptographic analogy would be a cipher whose algorithm is sound but whose transcript can be read, replayed and redirected. Compromise of one Microsoft 365 session can expose email and files and provide access to other applications connected through single sign-on 34, creating persistent cloud access 2. That is why this is not a series of isolated phishing incidents. In our reading, it is a systemic exposure of the conversation between user, identity provider and application.

How the conversation is hijacked

The most corroborated vector in the material — carried by multiple independent sources where most claims stand alone — is passkey- and SSO-themed social engineering to compromise corporate Microsoft accounts 1,5. Activity exploiting the popularity of passkeys and single sign-on as themes has been observed since May 2026 4, which gives the later September disclosures their currency: the pretext is recent, active and still evolving.

Attackers talk about passkeys but usually do not actually try to enter a passkey, using them instead as a pretext to persuade victims to log in to a fake page or enter a password on an official page 3,32. Impersonation uses urgency requiring targets to immediately update passkey, MFA or SSO settings to avoid losing access 4, with company names placed as subdomains to mimic portals 4. The observed domains including secure-passkey[.]com 4 and setupmypasskey[.]com 4 show the method plainly. A system that depends on secrecy of implementation is inherently fragile; here it depends instead on the user correctly parsing semantics under pressure, and the language of authentication is deliberately misspoken.

The relay and the abused flow

Two complementary technical paths dominate, and they should be understood together rather than as alternatives.

The first is adversary-in-the-middle phishing sites resembling legitimate Microsoft login pages that capture credentials and session tokens despite MFA 3,4,37. The mechanism then intercepts and replays passwords and session cookies to hijack accounts after MFA 34,35, involving a reverse proxy positioned between browser and genuine login page 20. While Microsoft claims MFA as a boundary, the reality demonstrates session theft after the ceremony completes. Active attempts to weaken phishing-resistant FIDO2/WebAuthn to steer users to weaker methods 36 confirm the intent: downgrade the dialogue until it can be overheard.

The second path abuses legitimate flows rather than copying them. Victims entering a device code into a legitimate Microsoft page issues a token to an attacker-controlled OAuth app bypassing further MFA 3, turning the device authorization flow intended for printers and smart TVs against users 12,13. This includes GhostCode hijacking MFA in just 78 seconds via deceptive device-code flow 14. This violates the fundamental axiom that authentication must bind identity, channel and intent; here the channel is genuine, the intent is counterfeit, and the proof succeeds anyway.

Initial access, in both paths, is overwhelmingly human. Microsoft warns scammers impersonate corporate IT support to gain Microsoft 365 access 16,32. That human opening is what makes the elegant relay possible.

What happens after login

The recurring sequence is identity compromise, persistence through MFA enrollment, reconnaissance of Graph categories, content discovery and collection or exfiltration 31. Persistence uses attacker-controlled MFA 17,31, followed by systematic exfiltration from SharePoint, OneDrive and Exchange 4,31,32.

The material stresses hijacking of valid authenticated sessions to access email, SharePoint, Teams and SSO apps 35. At scale, BigBear 2.0 is described as bypassing MFA to steal sessions at 258 organizations 19,21,22,24,26,36. In cryptanalytic terms, once the transcript is stolen, the attacker no longer needs to break the cipher at all.

Microsoft's own observations codify the response: monitor unusual sign-ins, new MFA registrations, Graph reconnaissance and suspicious SharePoint, OneDrive or Exchange access 3. Recommendations center on phishing-resistant MFA 3,36,37. The Cassandra view warns MFA messaging alone does not equal phishing resistance without phishing-resistant implementation, managed devices and disabled device-code flow 3. That tension is information, not noise. It tells us the disagreement is about what counts as MFA, not whether MFA was present.

The control plane repeats the same axiom failure

The same failure of authentication and authorization reappears, in different dress, in Azure itself. The most material finding is the maximum-severity Azure AI Foundry issue with a CVSS score of 10.0, classified as maximum severity 7, involving missing authentication for a critical function in Azure AI Foundry 7. Discovery is among the better-corroborated recent points, with security researcher Rémy Marot credited with the discovery of CVE-2026-85889 27,29.

Complementary vectors reinforce the access-control theme. Azure Container Registry CVE-2026-69865 is a remotely exploitable pre-authentication elevation-of-privilege vulnerability involving authorization bypass, with a CVSS score of 10.0 28. Database services extend the pattern at near-maximum severity, described as an improper neutralization vulnerability in Azure Cosmos DB with a CVSS score of 9.6 29.

What mitigates the near-term interpretation is consistent reporting that exploitation had not materialized at disclosure. The company stated that none of the identified bugs are known to be exploited 9, and there was no evidence of active exploitation of the identified security flaws in the wild before remediation 27. Eighteen vulnerabilities were fixed server-side 28. Yet the risk framing is explicitly tail-risk rather than realized breach. The identified vulnerabilities represent cybersecurity threat, data-breach risk, technology disruption, operational risk, and potential regulatory-compliance and legal-liability risk 8. At minimum, this allows unauthenticated elevation; in worst-case scenarios, it enables full control-plane compromise. That bounding of possibilities is deliberate, because evidence gaps remain material. No CVSS score, severity rating, exploit details, affected versions, patch status, disclosure date, researcher credit, or remediation steps are provided in the supplied content for some items 10,11.

Governance: moat and single point of failure

Identity concentration is simultaneously Microsoft's deepest enterprise moat and its most consequential single point of failure. The compromise of one corporate Microsoft account exposes user resources and connected SSO applications including Salesforce, Google Workspace, Dropbox, Adobe, SAP, Slack, Zendesk, and Atlassian 3. The same Entra-centered estate that lowers friction therefore concentrates blast radius.

The more corroborated governance thread points to depth as differentiator. Security and IT-governance teams that trust Entra and Azure compliance tooling typically find onboarding friction lower in Microsoft Foundry than on platforms outside the Microsoft ecosystem 33, and at general availability, Agent 365 provides a unified foundation to discover, identify, and govern agents with core controls 6. But administrative assumptions must be tested. If applications or clients do not respect critical events, the longer Continuous Access Evaluation token lifetime increases risk 30. While centralization enables server-side repair, it also means a single bypass can imply broad compromise. That duality is the central strategic fact.

Fundamental lessons

The lineage is familiar to any student of ciphers. Past breaks came not from brute force but from misused nonces, confused transcripts and trusted intermediaries. Passkey lures, reverse proxies and device-code abuse are the same ancient themes in cloud dress.

For strategy, the material points to compounding trust and resilience costs rather than a single patch, sustaining a qualitative moat and operational trust risk for Microsoft 365 15. The path forward is not another message about MFA, but identity bound to phishing-resistant proofs, managed devices and least privilege by default.

More from KAPUALabs

See all
| Free

Microsoft's Capacity Bet: Bull Case for Azure Growth

By KAPUALabs
/
| Free

Microsoft Bull Case: Pricing Power Versus Breach Overhang

By KAPUALabs
/
| Free

Xbox Game Pass Monetization Reset: Cloud Caps and Pricing Tests

By KAPUALabs
/