Security teams have spent years making account takeovers more difficult. Multi-factor authentication (MFA) adds an essential layer of protection beyond passwords, while conditional access and device trust introduce additional checks before users can access sensitive systems.
However, stronger authentication controls can also encourage attackers to target alternative entry points. Instead of stealing a user’s second factor, cybercriminals may try to manipulate the people and processes responsible for managing authentication—particularly account recovery and password reset procedures.
This makes the service desk more than a support function. It is also a critical part of your organization’s identity security perimeter.
MFA raises the cost of account takeover
Even if an attacker obtains a user’s password, MFA creates another barrier between the attacker and the account.
Many organizations are also replacing weaker authentication methods, such as SMS, with authenticator apps, FIDO security keys, and passkeys. Phishing-resistant authentication, conditional access, and device trust can add further checks based on the device, location, and login context.
These controls do not mean MFA has failed. In many cases, the opposite is true. MFA is effective enough that attackers have an incentive to bypass it rather than attack it directly.
Attackers may steal session tokens, abuse already authenticated sessions, or target authentication processes outside the standard login flow. One of the most important of these processes is account recovery.
Every strong authentication system must address practical questions: What happens when an authorized employee loses access? How can a user replace a lost security key or enroll a new authenticator? In these situations, account security may depend more on the recovery process than on the MFA technology protecting the account.
Verizon’s Data Breach Investigations Report found that 44.7% of breaches involved stolen credentials.
Protect Active Directory with compliant password policies, block more than 4 billion leaked passwords, strengthen security, and reduce password-related support requests.
When account recovery becomes an attack path
Employees lose phones, replace devices, change phone numbers, damage security keys, or forget their credentials. Authentication services can also become temporarily unavailable.
When self-service account recovery is not possible, the service desk is typically the route back into the account.
Depending on the organization’s procedures and the user’s permissions, a service desk agent may be able to reset a password, remove existing MFA methods, issue temporary credentials, approve a new authenticator enrollment, unlock an account, or otherwise restore access.
These are necessary support functions, but they are also sensitive identity management actions. That is why strong identity verification should take place before a password reset or MFA change.
If a user must satisfy multiple authentication factors to access an account but only answer a few basic questions to replace those factors, the recovery process may provide a weaker route to the same identity.
Account recovery is increasingly viewed as an identity security issue rather than a traditional help desk concern. Microsoft, for example, describes account recovery with Entra ID as a high-assurance process. This approach contrasts question-based help desk recovery with stronger identity verification designed to re-establish trust before access is restored.
The principle is straightforward: before an authentication method is replaced, the organization must have confidence that the person requesting the change is the legitimate account owner. Otherwise, the recovery process can quickly become an attack path.
Recent attacks show the risks of service desk impersonation
The tactics used by the hacking group Scattered Spider demonstrate the risks facing service desks. In a joint advisory, CISA, the FBI, and international partners reported that the group impersonated employees and persuaded IT and help desk staff to reset passwords and transfer MFA enrollment to attacker-controlled devices.
The advisory also notes that attackers may make several calls to learn how an organization’s password reset and identity verification procedures work before attempting an account takeover.
The 2025 attack against Marks & Spencer demonstrates how damaging sophisticated impersonation can become. Scattered Spider reportedly gained access by impersonating employees and convincing third-party contractors to reset passwords. The attackers then compromised additional accounts and eventually deployed ransomware across the retailer’s network.
Marks & Spencer chairman Archie Norman told Parliament that the incident was expected to reduce profits by approximately £300 million before recovery. The impact highlights how identity-focused social engineering can develop into a major business disruption.
Make identity verification part of your service desk workflow
Reducing this risk requires service desks to move beyond questions such as, “Does this person sound legitimate?” or, “Can the caller answer the verification questions?” The more important question is: Can the person securely prove that they are the employee associated with the account?
That is where Specops Secure Service Desk can help. The solution makes identity verification a required step in sensitive service desk workflows, reducing reliance on easily guessed or phished information and limiting the influence of social engineering.
Specops Secure Service Desk can use existing identity data in Active Directory or Entra ID and integrate with authentication services including Duo, Okta, PingID, and Symantec VIP. Support for more than 15 MFA factors allows service desks to verify different types of users without requiring a separate registration process.
Verification takes place immediately before high-risk actions. After the caller successfully authenticates, an agent can reset the password, unlock the account, and require a password change at the next logon. Verification events can also be exported to SIEM and analytics platforms to support security operations, auditing, and compliance workflows.
Protect your service desk with Specops
Strong authentication is only effective when the password reset and account recovery processes are protected by equally strong controls. Treating service desk identity verification as part of your overall identity security strategy can reduce the risk of social engineering while preserving a reliable support experience for legitimate users.
Specops helps organizations verify user identities before high-risk service desk actions, including password resets, account unlocks, and MFA changes.
Contact Specops today to learn how to strengthen identity verification and protect your service desk.
Sponsored and written by Specops Software.
Source: www.bleepingcomputer.com


