For years, security teams have been making account takeover harder. Multi-factor authentication (MFA) added crucial protection to password-only authentication, while conditional access and device trust add further checks before users can reach sensitive systems.
However, these controls give attackers a reason to look for another route. Some attacks that are becoming increasingly common target the processes around authentication mechanisms, in particular account recovery. After all, why steal a user’s second factor if you can convince someone with the rights to manage it to replace it for you?
That makes the service desk more than a support function. It makes it part of the organization’s identity security boundary.
MFA Has Raised the Cost of Account Takeover
Even if an attacker captures a user’s credentials, MFA means a second authentication factor still stands between them and the account.
Further strengthening that barrier is the fact that many organizations are moving away from weaker factors such as SMS and toward authenticator apps, FIDO security keys and passkeys. Phishing-resistant authentication can make credential theft considerably harder to turn into account access, while conditional access and device trust add further checks based on factors such as the device, location and context of a login.
None of this means that MFA has failed. In many cases, the opposite is true: MFA works well enough that attackers have an incentive to find ways around it rather than attack it head-on.
That can mean stealing session tokens, abusing existing authenticated sessions or targeting authentication processes that sit outside the normal login flow. And one of the most important processes is account recovery.
Every strong authentication system still needs an answer to a routine problem: what happens when a legitimate employee loses access to it? At that point, the security of the account may depend less on the MFA technology protecting it and more on the process used to reset it.
Secure your Active Directory passwords with Specops Password Policy Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches.
... continue reading