For years, security teams have been making account takeover harder. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems.
However, these controls give attackers a reason to look for another route. Some attacks that are becoming increasingly common target the processes around authentication mechanisms, in particular account recovery. After all, why steal a user’s second factor if you can convince someone with the rights to manage it to replace it for you?
That makes the service desk more than a support function. It makes it part of the organization’s identity security boundary.
MFA Has Raised the Cost of Account Takeover
Even if an attacker captures a user’s credentials, MFA means a second authentication factor still stands between them and the account.
Further strengthening that barrier is the fact that many organizations are moving away from weaker factors such as SMS and toward authenticator apps, FIDO security keys and passkeys. Phishing-resistant authentication can make credential theft considerably harder to turn into account access, while conditional access and device trust add further checks based on factors such as the device, location and context of a login.
None of this means that MFA has failed. In many cases, the opposite is true: MFA works well enough that attackers have an incentive to find ways around it rather than attack it head-on.
That can mean stealing session tokens, abusing existing authenticated sessions or targeting authentication processes that sit outside the normal login flow. And one of the most important processes is account recovery.
Every strong authentication system still needs an answer to a routine problem: what happens when a legitimate employee loses access to it? At that point, the security of the account may depend less on the MFA technology protecting it and more on the process used to reset it.
Secure your Active Directory passwords with Specops Password Policy
Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.
Effortlessly secure Active Directory with compliant password policies, blocking 4+ billion compromised passwords, boosting security, and slashing support hassles!
When the Recovery Path Becomes the Attack Path
Employees replace phones, lose security keys, change numbers, damage devices, and forget credentials. Sometimes an authenticator simply becomes unavailable.
When self-service recovery is no longer possible, the service desk typically becomes the route back into the account.
Depending on the organization and the user’s privileges, an agent may be able to reset a password or MFA, remove an existing authentication method, issue temporary credentials, approve registration of a new authenticator, or otherwise restore access.
While these are necessary support functions, from a security perspective, they are also sensitive identity-management actions. That makes the verification step before the reset critical. If a user normally must satisfy multiple authentication factors to access an account but only has to answer a handful of questions to replace those factors, the recovery process can become the weaker path to the same identity.
This is increasingly being treated as an identity assurance problem rather than a conventional help desk problem. Microsoft, for example, now describes account recovery in Entra ID as a “high-assurance” process and contrasts traditional question-based help desk recovery with stronger identity verification designed to re-establish trust before access is restored.
The principle is simple: the process used to replace an authentication method should provide confidence that the person requesting the change is the person who owns the account. If it doesn’t, the recovery path can quickly become the attack path.
Recent Attacks Highlight the Risk
The tactics employed by hacking collective Scattered Spider are a clear example of the challenge service desks face. A joint advisory from CISA, the FBI and international partners say the group has posed as employees to persuade IT and help desk staff to reset passwords and transfer MFA to attacker-controlled devices.
The same advisory notes that attackers may spend several calls learning about an organization’s password-reset process before attempting the takeover.
The 2025 attack on Marks & Spencer shows how damaging sophisticated impersonation can be. Scattered Spider impersonated an employee to trick a third-party contractor into resetting their password to gain access. From there, the group compromised more accounts and eventually deployed ransomware across the retailer’s network.
M&S chairman Archie Norman told Parliament that the incident was expected to reduce profit by around £300 million before recoveries, underlining how a successful identity-focused social engineering attack can become a major business incident.
Make Identity Verification Part of the Service Desk Workflow
Closing this gap means moving the service desk away from questions such as “Does this person sound legitimate?” or “Can they answer our verification questions?” and toward a stronger one: Can this person securely prove they are the employee associated with the account?
That is where Specops Secure Service Desk fits. It makes identity verification a required part of sensitive service desk workflows, helping reduce reliance on easily guessed or phished information and judgement that a social engineer may be able to manipulate.
Specops Secure Service Desk can use existing identity data in Active Directory or Entra ID and integrate with authentication services such as Duo, Okta, PingID and Symantec VIP. With support for more than 15 MFA factors, service desks can verify different types of users without introducing a separate enrollment process.
Crucially, verification sits directly in front of high-risk actions. Agents can reset passwords, unlock accounts and require a password change at the next logon only after the caller has been successfully verified. Verification events can also be exported to SIEM and analytics platforms to support audit and SOC workflows.
Secure Your Service Desk with Specops
Strong authentication only works if the process used to reset or recover it is just as secure. Treating service desk verification as part of the identity security process helps reduce the risk of social engineering without making legitimate support harder.
Specops helps organizations put stronger identity verification in front of high-risk service desk actions such as password resets and account unlocks.
Contact Specops today to see how you can strengthen identity verification and secure your service desk
Sponsored and written by Specops Software.
Comments have been disabled for this article.
