Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. Mollema describes the behavior as a consequence of how Windows Hello for Business works and says it was left as-is. The disclosure does not identify the exact Windows builds or Windows Hello for Business deployment models tested. The new work removes that requirement by treating the Windows Hello for Business key as a FIDO2 passkey through WebAuthn. For detection, he recommended hunting for Windows Hello for Business sign-ins with an empty device ID.