Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Your Help Desk Is a Target — Protecting Support Workflows

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2019, written in 2026 with the benefit of hindsight.

The short version: In 2019, attackers got into Microsoft's consumer email support systems by compromising a single support agent's account. Help desks are trusted by design — which makes them a target.

Why your help desk is part of your security perimeter

Help desk staff reset passwords, change MFA settings and unlock accounts. Attackers either steal a support agent's credentials or call the help desk pretending to be an employee. Some of the most damaging attacks of recent years began this way.

The business impact

  • Account takeover at scale through one compromised support account.
  • Executive impersonation when callers convince agents to reset MFA.
  • Outsourced risk when support is handled by a third party.

Questions to ask your team

  • What can our help desk staff change, and for whom?
  • How does the help desk verify who a caller is before resetting MFA?
  • Do outsourced support providers have the same restrictions and monitoring?
  • Would we notice if one agent reset dozens of accounts in an hour?

What good looks like

Help desk roles limited to what they need, verification procedures that don't rely on easily found personal information, extra checks for executives and administrators, and monitoring of unusual support activity.

The decision

Ask to see the written identity verification procedure your help desk follows for MFA resets. If it relies on date of birth or employee ID, strengthen it.

outlook.com breach 2019 impactOutlook.com support account2019

More on this story