Passkey lures can expose SharePoint and OneDrive data

Microsoft has described active cloud intrusions that start with passkey, multifactor authentication, or single sign-on lures. After compromising an identity, attackers can add an authentication method, map the tenant through Microsoft Graph, and collect SharePoint, OneDrive, and Exchange content using the access already available to that user.
A successful sign-in is not the whole incident. The report shows how a single compromised identity can become a route into collaboration data: new authentication methods make access persistent, Graph requests reveal the tenant, and ordinary-looking file activity can become a collection pattern. For SharePoint and Teams admins, the useful response is to connect the signals rather than chase a single suspicious URL. An unusual sign-in followed by new authentication methods, broad Graph reconnaissance, or high-volume SharePoint and OneDrive access deserves one joined investigation.
Analysis
Test the handoff between identity and collaboration monitoring this week. Confirm who can investigate a risky sign-in, remove an unauthorised authentication method, revoke sessions, and check the same identity’s Graph, SharePoint, OneDrive, and Exchange activity.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Passkey lures can expose SharePoint and OneDrive data", Collab365 Spaces.