Identity attacks are creating new security gaps for MSP clients as employees increasingly work across email, browsers, SaaS applications, cloud platforms and AI tools. Recent Microsoft attacks used passkey-themed social engineering, device code phishing and adversary-in-the-middle techniques to compromise cloud identities, while Microsoft’s 2025 Digital Defense Report found that 97% of identity attacks were password spray attacks.The attack surface is expanding beyond authentication as well. Verizon reported that unauthorized “shadow AI” use had tripled to 45% and mobile social engineering attacks were 40% more successful than traditional email phishing, while LayerX found that 99% of enterprise users have at least one browser extension installed and AI extensions were three times more likely to have access to browser cookies. For MSPs, these trends increase the need to connect identity security with endpoint, email, browser, SaaS and cloud protections.
IAM Technologies, AI benefits/risks
Browsers, AI and stolen sessions are creating new MSP security gaps
(Adobe Stock)
You can skip this ad in 5 seconds