CIO Brief: Your Help Desk Is a Target — Protecting Support Workflows
Retrospective: this article looks back at events from April 2019, written in 2026 with the benefit of hindsight.
The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are trusted by design — which makes them a target.
Why your help desk is part of your security perimeter
Help desk staff reset passwords, change MFA settings and unlock accounts. Attackers either steal a support agent's credentials or call the help desk pretending to be an employee. Some of the most damaging attacks of recent years began this way.
The business impact
- Account takeover at scale through one compromised support account.
- Executive impersonation when callers convince agents to reset MFA.
- Outsourced risk when support is handled by a third party.
Questions to ask your team
- What can our help desk staff change, and for whom?
- How does the help desk verify who a caller is before resetting MFA?
- Do outsourced support providers have the same restrictions and monitoring?
- Would we notice if one agent reset dozens of accounts in an hour?
What good looks like
Help desk roles limited to what they need, verification procedures that don't rely on easily found personal information, extra checks for executives and administrators, and monitoring of unusual support activity.
The decision
Ask to see the written identity verification procedure your help desk follows for MFA resets. If it relies on date of birth or employee ID, strengthen it.
- Outlook.com Support Agent Account Compromised (Apr 2019): The Help Desk Attack Surface Incident Teardowns
- How to Secure Help Desk and Support Roles in Microsoft 365 How-To & Hardening
- Detecting Help Desk Account Compromise: Defender XDR and Sentinel Hunting Queries Detection & Response