The Service Desk: A Critical New Front in Identity Security
While Multi-Factor Authentication (MFA) has significantly bolstered account security, attackers are increasingly bypassing these defenses by targeting the account recovery processes managed by service desks. This shift transforms the service desk from a mere support function into a crucial component of an organization's identity security boundary, demanding robust verification protocols.

For years, security teams have focused on making account takeovers harder. **Multi-Factor Authentication (MFA)**, conditional access, and device trust have added crucial layers of protection to traditional password-only authentication.
However, these strengthened controls have inadvertently pushed attackers to seek alternative routes. A growing trend involves targeting the processes surrounding authentication mechanisms, particularly account recovery. Why steal a user's second factor when you can convince someone with the authority to replace it for you?
This makes the service desk more than just a support function; it becomes an integral part of an organization's identity security boundary.
## MFA Has Raised the Cost of Account Takeover
Even if an attacker obtains a user's credentials, MFA ensures a second authentication factor still stands between them and the account. Many organizations are further strengthening this barrier by moving away from weaker factors like SMS toward authenticator apps, **FIDO** security keys, and passkeys.
Phishing-resistant authentication makes credential theft considerably harder to leverage, while conditional access and device trust add further checks based on factors such as device, location, and login context.
This doesn't mean MFA has failed. In many cases, the opposite is true: MFA is effective enough that attackers are incentivized to find ways around it rather than attack it directly. This can involve stealing session tokens, abusing existing authenticated sessions, or targeting authentication processes that operate outside the normal login flow. One of the most important of these processes is account recovery.
Every robust authentication system needs a solution for a common problem: what happens when a legitimate employee loses access? At this point, the security of the account may depend less on the MFA technology protecting it and more on the process used to reset it.
## When the Recovery Path Becomes the Attack Path
Employees frequently replace phones, lose security keys, change numbers, damage devices, or simply forget credentials. When self-service recovery isn't an option, the service desk typically becomes the route to regaining account access.
Depending on the organization and the user's privileges, an agent might be able to reset a password or MFA, remove an existing authentication method, issue temporary credentials, approve the registration of a new authenticator, or otherwise restore access.
While these are necessary support functions, from a security perspective, they are also sensitive identity-management actions. This makes the verification step before the reset critically important. If a user normally requires multiple authentication factors to access an account but only needs to answer a few questions to replace those factors, the recovery process can become a significantly weaker path to the same identity.
This is increasingly being viewed as an identity assurance problem rather than a conventional help desk issue. **Microsoft**, for example, now describes account recovery in **Entra ID** as a βhigh-assuranceβ process, contrasting traditional question-based help desk recovery with stronger identity verification designed to re-establish trust before access is restored.
## Recent Attacks Highlight the Risk
The tactics employed by the hacking collective **Scattered Spider** clearly exemplify the challenges faced by service desks. A joint advisory from **CISA**, the **FBI**, and international partners detailed how the group has impersonated employees to persuade IT and help desk staff to reset passwords and transfer MFA to attacker-controlled devices.
The advisory also noted that attackers may spend several calls learning about an organizationβs password-reset process before attempting the takeover. The 2025 attack on **Marks & Spencer** illustrates how damaging sophisticated impersonation can be. Scattered Spider impersonated an employee to trick a third-party contractor into resetting their password, gaining initial access. From there, the group compromised more accounts and ultimately deployed ransomware across the retailerβs network.
**M&S** chairman Archie Norman told Parliament that the incident was expected to reduce profit by approximately Β£300 million before recoveries, underscoring how a successful identity-focused social engineering attack can escalate into a major business incident.
## Make Identity Verification Part of the Service Desk Workflow
Closing this security gap requires the service desk to move beyond questions like βDoes this person sound legitimate?β or βCan they answer our verification questions?β toward a stronger standard: Can this person securely prove they are the employee associated with the account?
This is where **Specops Secure Service Desk** comes into play. It mandates identity verification as a required step in sensitive service desk workflows, reducing reliance on easily guessed or phished information and human judgment that social engineers can manipulate.
Specops Secure Service Desk can leverage existing identity data in **Active Directory** or Entra ID and integrate with authentication services such as **Duo**, **Okta**, **PingID**, and **Symantec VIP**. With support for over 15 MFA factors, service desks can verify different types of users without introducing a separate enrollment process.
Crucially, verification is positioned directly before high-risk actions. Agents can only reset passwords, unlock accounts, and require a password change at the next logon after the caller has been successfully verified. Verification events can also be exported to **SIEM** and analytics platforms to support audit and **SOC** workflows.
## Secure Your Service Desk with Specops
Strong authentication is only effective if the processes used to reset or recover it are equally secure. Treating service desk verification as an integral part of the identity security process helps mitigate the risk of social engineering without hindering legitimate support operations.
Specops assists organizations in implementing stronger identity verification for high-risk service desk actions such as password resets and account unlocks.