UPDATE Attackers can exploit flaws in Microsoft's passkey systems in ways surprisingly similar to old password attacks. But that doesn't mean it's time to give up on passkeys. Passkeys have received much attention in recent years. They're considered phishing-resistant, and their use of private keys means they are largely unaffected by data breaches when identity information and credentials are stolen. They also require zero memorization compared to traditional passwords because users embed authentication directly into the device by enabling biometrics or PINs. Even so, widespread adoption has been gradual. That may change. Microsoft has announced that starting Sept. 1, passkeys will become the default authentication method for Microsoft Entra ID sign-in, the tech giant's cloud-based identity and access management service. With passkeys steadily becoming the norm, Michael Grafnetter, principal security researcher at SpecterOps, decided to dig deeper into the security and risks of the passwordless alternative. That research, which will be presented next month at Black Hat USA conference in Las Vegas, uncovered three nearly exploitable zero-day vulnerabilities in Windows 11 and Microsoft Entra ID. Two of the vulnerabilities formed a replay chain that could eventually allow attackers to impersonate privileged cloud identities while bypassing phishing-resistant multifactor authentication (MFA). Grafnetter calls the chain "Pass-the-Passkey" because it mirrors similar Windows hackin...
Flaws in Passkey Implementation Show Old Attacks Still Work
Dark Reading
·Arielle Waldman
·Published Jul 22, 2026
·Updated
Affected Software
2 affected components
Microsoft Windows 11=Windows 11
Microsoft Microsoft Entra ID=Microsoft Entra ID
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses vulnerabilities in Microsoft's passkey systems that allow attackers to exploit them using techniques reminiscent of traditional password attacks.
2
What security vulnerabilities are highlighted in the article?
The article highlights flaws in Microsoft's passkey implementation that could be exploited similarly to older password-related attacks.
3
Which Microsoft products are affected by these security flaws?
The affected products mentioned in the article are Microsoft Windows 11 and Microsoft Entra ID.
4
Are passkeys still considered secure despite these vulnerabilities?
Yes, the article suggests that while the vulnerabilities exist, it is not a reason to abandon passkeys as they are still considered phishing-resistant.
5
What do the findings imply about the effectiveness of passkeys?
The findings imply that despite passkeys being more secure than passwords, they still have exploitable weaknesses that attackers can leverage.