For years, security teams have been making account takeover harder. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems.

However, these controls give attackers a reason to look for another route. Some attacks that are becoming increasingly common target the processes around authentication mechanisms, in particular account recovery. After all, why steal a user’s second factor if you can convince someone with the rights to manage it to replace it for you?

That makes the service desk more than a support function. It makes it part of the organization’s identity security boundary.

MFA Has Raised the Cost of Account Takeover

Even if an attacker captures a user’s credentials, MFA means a second authentication factor still stands between them and the account.