How to Harden Help Desk Identity Verification and Password Resets
Retrospective: this article looks back at events from September 2023, written in 2026 with the benefit of hindsight.
The help desk is now a primary target for social engineering. Here is how to harden identity verification and password/MFA resets.
Step 1: Classify requests by risk
- Standard users, password reset: medium risk.
- MFA method reset or new device registration: high risk.
- Privileged users, executives, IT staff: very high risk.
Step 2: Replace knowledge-based verification
Employee ID, date of birth, manager name and last four digits of Social Security numbers are easy to find or buy. Use stronger methods:
- Push a verification to an existing registered method (for example, Microsoft Authenticator Verified ID or a callback to a phone number already on file — not one provided by the caller).
- Video verification comparing the caller to an ID photo.
- Manager confirmation through a separate channel.
- In-person verification for privileged accounts.
- Microsoft Entra Verified ID with face check for high-assurance identity proofing.
Step 3: Use Temporary Access Pass
Instead of resetting passwords and MFA methods directly, issue a Temporary Access Pass (time-limited, single-use) after verification, so the user registers new methods themselves.
Step 4: Add friction for privileged resets
Require two help desk staff or security approval for resets of admin and executive accounts.
Step 5: Limit help desk permissions
Help desk roles should not be able to reset MFA for privileged users. Use restricted management administrative units for sensitive accounts.
Step 6: Monitor and notify
- Notify users (through a separate channel) when their MFA methods change.
- Alert security on resets for privileged accounts.
Step 7: Train and test
Run vishing simulations against the help desk.