5 Ways to Secure Your Service Desk Against AI-Enabled Attacks

The most important service desk security control is simple: no password, MFA, or account recovery action should proceed until the user has passed an enforced identity-verification workflow.

5 Ways to Secure Your Service Desk Against AI-Enabled Attacks

An employee calls the service desk. They’ve replaced their phone, they explain, and can’t access Microsoft Authenticator. They know their employee number and their manager’s name, and just need to access their account before an important meeting. They even sound like the employee.

So how does the service desk know who is actually calling?

Generative AI is making that question harder to answer; attackers can now create convincing social engineering scams using AI tools, including voice cloning and synthetic video, to trick under-pressure agents into changing a password or recovering an account.

Organizations should increasingly assume that an attacker may be able to sound, look, and behave like the person they claim to be. Below are five ways to help secure the service desk against these AI-enabled attacks.

1. Stop using knowledge as proof of identity

Many service desks still verify callers by asking for information such as an employee ID or answers to security questions. While it’s tempting to assume that a caller that knows the answers is the real employee, knowing information about a person is not the same as proving you are that person.

An attacker can use AI to collect information from across the internet and build a detailed, convincing profile of the employee they aim to impersonate. AI voice cloning adds another layer of realism to the scam, together making a malicious call trickier to spot if the agent is relying solely on knowledge-based verification.

Strong identity verification allows agents to more confidently authenticate users, changing the question from “What do you know about this employee?” to “Can you demonstrate that you are this employee?”. When AI helps attackers better impersonate real employees, implementing processes that enforce verification through an authenticator and other MFA factors help minimize the risk of a malicious call getting through.

2. Password and MFA resets are your highest-risk service desk workflow

Multifactor authentication (MFA), passkeys, Conditional Access and device controls all make it harder for attackers to access accounts directly. But if someone can persuade the service desk to reset those controls, they may not need to defeat them technically.

That makes password resets, MFA resets and account recovery especially attractive targets. Plausible requests like “My laptop has died and I need access before a customer call” introduce urgency to what sounds like a routine request.

The attacker can then layer credibility from their AI-enabled reconnaissance. The danger is that an agent under pressure starts treating a convincing conversation as sufficient evidence of identity.

Sensitive actions should instead require strong verification before they are carried out. Crucially, verification shouldn’t be skipped because the caller knows the right information or claims the request is urgent.

How Specops helps: Secure verification at the service desk

The security of identity controls like MFA and passwords depends partly on how difficult it is to persuade the service desk to replace them. Solutions such as Specops Secure Service Desk help by requiring users to complete robust identity verification before an agent carries out those requests.

The process makes use of end user authentication factors that are more resistant to social engineering, such as 3rd party integrations with solutions like Duo and Okta. Agents can make use of any combination of more than 15 MFA factors, ensuring that any user, with a mobile device or not, can be securely verified.

3. Employees need a reliable way to verify IT requests

Microsoft highlighted in April that threat actors were impersonating helpdesk personnel and using Microsoft Teams to socially engineer employees into granting remote desktop access. From there, the attackers could deploy trusted applications to execute malicious code, pivot towards identity and domain infrastructure, attempt to access sensitive data or a host of other actions.

AI can make these interactions more credible. Attackers can use it to produce more natural messages, mirror internal terminology, and tailor their approach to the employee they are targeting.

Organizations should therefore set clear rules around how the service desk operates and communicates with employees. If someone claiming to be from IT asks an employee to take a sensitive action, the employee should be able to confirm that the request is genuine.

The objective is to create a support process where trusted channels, verified identities and controlled workflows reinforce one another; employees need a reliable way to trust the support channel, while service desk agents need strong evidence that the person requesting a sensitive action has been verified.

4. Assume your service desk procedures will fail until you test them

Organizations routinely test their attack surface for weaknesses. The service desk deserves the same attention; if an attacker can persuade an agent to grant access to an account, the result can be just as serious as exploiting a technical vulnerability.

Google Mandiant conducted a red team exercise with a client to demonstrate the effectiveness of AI-enabled social engineering. Researchers impersonated a member of the client’s security team by training a model on their voice, then spoofed calls to a curated list of targets to attempt to gain initial access.

While the exercise wasn’t conducted specifically against the service desk, it still shows how convincing AI-enabled vishing can be and why organizations should test their people and processes against it. Authorized social engineering exercises can help assess whether service desk procedures hold up when an attacker sounds credible. It is also worth considering testing the opposite direction: can someone impersonating IT persuade an employee to grant remote access, approve an MFA prompt or follow instructions outside the normal support process?

5. Train staff on processes in an era of convincing impersonation

Organizations should also consider staff training to spot the signs of social engineering. This training needs to account for the latest AI-supported threats; traditional signals like unusual wording, poor grammar, unfamiliar phone numbers, unexpected requests or a voice that does not sound quite right are becoming less dependable.

Agents should not be expected to decide whether a caller sounds sufficiently like an employee. Their job should be to follow a process that remains secure even when the caller is persuasive.

This is also where enforced verification controls support training. Technology can reduce the number of security decisions agents need to make in a high-pressure moment, while training reinforces when and how those controls must be used.

Make identity verification the foundation of service desk security with Specops

As AI makes impersonation more convincing, service desk agents need robust measures to confidently verify users before sensitive actions take place. Review every workflow that allows the service desk to reset a password, replace an MFA method, or recover an account. If an agent can complete any of those actions based on information the caller knows, how convincing they sound, or a manager’s informal approval, the process remains vulnerable.

The practical default should be enforced verification through an approved factor, with failed verification routed into a documented escalation workflow and not handled as an exception under pressure.

If you’re reviewing your service desk processes, Specops can help. Contact us today to see how stronger identity verification could reduce the risk of social engineering and impersonation attacks.