
For years, security teams have been making account takeovers more difficult. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust added additional checks before users could reach sensitive systems.
However, these controls give attackers a reason to look for another route. Some attacks that are becoming more common are targeting the processes around authentication mechanisms, specifically account recovery. After all, why steal the user’s second factor if you can convince someone with the rights to manage it to replace it for you?
This makes the service desk more than just a support function. This makes it part of the organization’s identity security boundary.
MFA has increased the cost of acquiring an account
Even if an attacker captures the user’s credentials, MFA means that a second factor of authentication still stands between them and the account.
Further strengthening this barrier is the fact that many organizations are moving away from weaker factors such as SMS and towards authentication applications, FIDO security keys and passwords. Phishing-resistant authentication can make credential theft significantly more difficult to turn into account access, while conditional access and device trust add additional checks based on factors such as device, location, and login context.
None of this is to say that the MFA failed. In many cases, the opposite is true: MFA works well enough that attackers have an incentive to find ways around it instead of attacking it directly.
This could mean stealing session tokens, abusing existing authenticated sessions, or targeting authentication processes that are outside of the normal login flow. And one of the most important processes is account recovery.
Any strong authentication system still needs an answer to a routine problem: what happens when a legitimate official loses access to it? At this point, the account’s security may depend less on the MFA technology that protects it and more on the process used to reset it.
Verizon’s data breach investigation report found that stolen credentials were involved in 44.7 percent of breaches.
Effortlessly protect Active Directory with compliant password policies, blocking 4+ billion compromised passwords, increasing security and reducing maintenance hassles!
When the path of recovery becomes the path of attack
Employees switch phones, lose security keys, change numbers, damage devices and forget credentials. Sometimes the authenticator simply becomes unavailable.
When self-service recovery is no longer possible, the service desk usually becomes the route back to the account.
Depending on the user’s organization and privileges, the agent may be able to reset a password or MFA, remove an existing authentication method, issue temporary credentials, approve registration of a new authenticator, or otherwise restore access.
While these are necessary maintenance features, from a security perspective, they are also sensitive identity management actions. This makes the pre-reset verification step critical. If a user normally has to answer multiple authentication factors to access an account, but only needs to answer a few questions to replace those factors, the recovery process can become the weaker path to the same identity.
This is increasingly being treated as an identity assurance issue rather than a conventional help desk issue. Microsoft, for example, now describes Entra ID account recovery as a “high security” process and is pitting traditional question-based help desk recovery against stronger identity verification designed to restore trust before access is restored.
The principle is simple: the process used to replace an authentication method must provide confidence that the person requesting the change is the person who owns the account. If it doesn’t, the recovery path can quickly become an attack path.
Recent attacks highlight the risk
The tactics used by the hacking collective Scattered spider are a clear example of the challenge facing service desks. A joint consultation from CISA, the FBI and international partners say the group impersonated employees to convince IT staff and help desk staff to reset passwords and transfer MFA to devices controlled by an attacker.
The same advisory notes that attackers may spend several conversations learning about an organization’s password reset process before trying to take over.
The Attack in 2025 Marks and Spencer shows how damaging sophisticated mimicry can be. Scattered Spider impersonates an employee to trick a third-party contractor into resetting their password to gain access. From there, the group compromised more accounts and eventually deployed ransomware on the merchant’s network.
M&S chairman Archie Norman told parliament the incident was expected to reduce profits by around £300m before recovery, highlighting how a successful identity-focused social engineering attack could turn into a major business incident.
Make identity verification part of the Service Desk workflow
Bridging this gap means moving the service desk away from questions like “Does this person sound legit?” or “Can they answer our verification questions?” and to a stronger one: can this person prove for sure that he is the employee associated with the account?
Here’s where Specops Secure Service Desk it fits. This makes identity verification a mandatory part of sensitive service desk workflows, helping to reduce reliance on easily guessed or phishable information and judgment that a social engineer may be able to manipulate.
Specops Secure Service Desk can use existing identities in Active Directory or Entra ID and integrate with authentication services such as Duo, Okta, PingID and Symantec VIP. With support for more than 15 MFA factors, service desks can verify different types of users without introducing a separate enrollment process.
Most importantly, the check is right in front of the high-risk actions. Agents can reset passwords, unlock accounts, and require a password change at the next login only after the caller has successfully authenticated. Inspection events can also be exported to SIEM and analytics platforms to support auditing and SOC workflows.
Secure your service desk with Specops
Strong authentication only works if the process used to reset or restore is equally secure. Treating service desk verification as part of the identity security process helps reduce the risk of social engineering without making legitimate support more difficult.
Specops helps organizations put stronger identity verification in front of high-risk service desk actions like password resets and account unlocks.
Contact Specops today to see how you can improve identity verification and secure your service desk
Sponsored and written by Specops software.