Microsoft calls identity "the primary control plane for defense." If you sell to enterprises, your sign-in page is part of that control plane. Here's what the 2026 report means for how you authenticate users, and agents.
On October 1, Microsoft published its 2026 Digital Defense Report, covering threat activity from July 2025 through June 2026. Much of the coverage focused on AI: attackers using it to write phishing, find vulnerabilities and run intrusions faster. But the report's clearest message is older and plainer. Microsoft calls identity "the primary control plane for defense," and warns that "the rise of AI should not steal security teams' focus away from identity."
That matters for anyone building a B2B product. Your customers' security teams protect their own identity provider, but every app their employees sign in to is part of the same perimeter. When an attacker holds a valid password for your product, your sign-in flow is the control that decides what happens next.
The identity numbers that matter #
Read together, these numbers describe one pattern. Attackers go after credentials, sign in with them, and then collect more. Here are four lessons for how you build sign-in.
1. A valid password proves less than it used to #
The report puts it directly: "A valid credential can turn malicious activity into something that resembles legitimate use." If one in five observed intrusions starts with a valid account, a correct password tells you very little about who is typing it.
Your sign-in flow needs signals beyond the credential. Is this a device the user has signed in from before? Could they plausibly be in this location, given where they signed in an hour ago? Has this account been dormant for months? None of these signals is proof on its own, but each one is a reason to ask for more before you issue a session.
2. One-time codes don't stop modern phishing #
Kits like Tycoon2FA sit between the user and the real sign-in page. BleepingComputer describes how the kit "proxies the MFA flow directly to Microsoft or Google" and "captures session cookies." The user types their code, the attacker relays it, and the attacker walks away with a signed-in session.
Microsoft's disruption cut Tycoon2FA activity by 95%, but the technique doesn't depend on one kit. That's why the report points to "phishing-resistant multifactor authentication (MFA) and passkeys." A passkey is bound to the domain where it was registered, so a user can't hand it to a look-alike page, however convincing.
3. AI makes fake people convincing #
According to Help Net Security's summary of the report, fraudsters used to give themselves away with a forged ID that looked off, writing that read like a second language, an accent in an interview and barely any online footprint. "AI fixes all four simultaneously." The report also says North Korea's remote IT worker scheme now uses AI for persona development.
For a product with self-serve sign-up, this shows up as accounts that look real but aren't: free-trial farms, repeat sign-ups and bot-created users. The fix isn't more careful human review. It's checking the device and network behind each sign-up, which is much harder to fake than a name or a profile photo. We covered this in more depth in Why rate limits can't stop distillation attacks.
4. Attacks now run at machine speed #
In a test against an emulated enterprise with no defenders, Help Net Security reports that frontier models "took control of the whole domain, including the main server and all user accounts, through a 32-step attack chain." That was a lab. On October 1, the Dutch Institute for Vulnerability Disclosure (DIVD) disclosed what it describes as an agentic AI attack on its own systems on September 21. DIVD said "after every action it decided the next step itself," and noted the agent made mistakes like "polluting its own MITM attack with password spraying."
Automated attacks are fast, but they are also noisy and repetitive. That's a detection opportunity, if your detection is automatic too. A quarterly access review won't catch something that happens in seconds.
What each finding means for your sign-in flow #
Make a stolen password worth less #
WorkOS Radar adds these checks to AuthKit sign-in. It uses device fingerprinting and sign-in signals to detect bots, brute force attempts, impossible travel, unrecognized devices and stale accounts that suddenly become active. Its bot detection can tell AI agents apart from other automated traffic like search engine crawlers. For sign-up, Radar limits repeat sign-ups from the same email and blocks or challenges disposable and known fraudulent email domains.
For each detection, you choose what happens: block the attempt even with a valid password, challenge the user with a one-time code, or notify the user and their admin. You can also allow or deny specific IP ranges, countries, devices or users. With hosted AuthKit, Radar works once you turn it on in the WorkOS Dashboard. If you use the User Management APIs with your own UI, follow the Radar integration guide. Radar decides whether an attempt deserves trust. The factor you then ask for decides whether a phishing kit can get through. AuthKit supports passkeys, and treats a passkey as both factors because it requires user verification, such as a fingerprint or PIN. You can also prompt existing password users to enroll a passkey the next time they sign in.
For agents, the report's advice is that the same controls "need to extend to their identities, permissions, data, and tools." AuthKit's Agent Registration gives each agent its own short-lived, scoped credentials, tied to the user who delegated to it, so an agent never needs a user's password at all.
A checklist for your sign-in flow #
- Sign-in checks device, location and account dormancy, not just the password.
- You can block or challenge risky attempts automatically, without a human in the loop.
- Users can sign in with passkeys, and you prompt password users to enroll one.
- Sign-up detects bots, repeat sign-ups and disposable email domains.
- Users and admins are notified when an unrecognized device or a dormant account signs in.
- Agents authenticate with their own scoped credentials, never a user's password.
The report spends many pages on AI, but its advice for defenders is familiar: strengthen identity and limit privilege. AI doesn't change what a strong sign-in looks like. It changes how quickly a weak one gets found.