Published July 29, 2026
Last updated July 28, 2026

Stop social engineering attacks at the help desk with Microsoft Entra ID and Persona

Replace knowledge-based questions with identity verification flows to strengthen your help desk's security and reduce phishing risk.
Joshua Rodriguez
Joshua Rodriguez
3 min
Key takeaways
Help desk social engineering works by exploiting human judgment. But more training won't stop an attacker who’s done their research or is using a convincing deepfake.
Knowledge-based authentication (KBA) is inconsistent by nature: security depends on which agent handles the call, what questions they ask, and how legitimate an attacker looks or sounds.
Persona integrates with Microsoft Entra ID to add objective identity verification before a Temporary Access Pass (TAP) is issued, removing the subjective judgment call from the recovery workflow.

The help desk has become one of the most exploited entry points for social engineering. Attackers have learned that it’s easier to call the help desk and talk their way into a password reset or MFA re-enrollment than to break through modern MFA, SSO, and EDR directly.

Yet most recovery workflows still rely on a human. When an employee reaches out to change their MFA or recover an account, the help desk analyst must decide, in real time, whether the caller really is that employee.

The help desk’s standard defense is to ask the caller a few knowledge-based questions. But an attacker with a little bit of research can answer as convincingly as the real employee. With deepfakes and voice cloning tools, they can look and sound like one too.

Help desks need stronger defenses than knowledge-based authentication (KBA) alone can provide. Persona’s integration with Microsoft Entra ID verifies the employee’s identity before the IT agent restores their access.

How do Persona and Entra ID strengthen help desk recovery flows?

With Persona, your IT agents can objectively verify an employee’s identity before restoring access. Here’s how that works:

  1. Trigger: When an employee asks to reset their password, change their MFA, or enroll a new device, your organization’s IT agent can trigger a verification request to ensure that the employee is who they claim to be.

  2. Verification request: Next, Persona asks the employee to submit a photo of a government-issued ID (such as a driver’s license) and a live selfie.

  3. Check and analysis: Persona checks the ID to ensure authenticity and for signs of tampering. Persona also analyzes the selfie to confirm a real person is present (i.e., the selfie is not a photo or deepfake) and matches the ID portrait.

  4. Risk signals: Throughout the verification process, Persona also collects rich device and behavioral signals such as proxy usage, GPS data, and jailbroken device detection to flag key risk vectors.

  5. Access: Once verification is complete, the help desk agent can proceed to issue the employee a Temporary Access Pass (TAP). The time-limited, single-use passcode lets the verified employee re-register their password or authenticator and regain access to their account.

With traditional security practices, granting account recovery came down to whether an agent believed the caller. Persona and Entra ID replace that approach with a confirmed identity check before your help desk proceeds with a sensitive action.

How Persona and Microsoft Entra ID improve help desk flows

Introducing identity verification during critical help desk moments can strengthen your organization’s defenses against social engineering. It does so by:

  • Moving teams beyond KBA without adding unnecessary friction. Traditional recovery processes put IT teams in a difficult position: ask too few questions and you risk letting attackers through; ask too many and you frustrate legitimate employees who need to get back to work. Persona provides a consistent, automated verification step so agents don’t have to make a judgment call every time someone calls in.

  • Reducing human-in-the-loop vulnerability. Even if one attack on the help desk fails, a threat actor can just keep calling until they reach an agent who handles KBA differently. With Persona embedded in the recovery workflow, every request goes through the same verification standard, regardless of which agent handles it, what time of day it is, or how busy the queue is.

  • Giving help desk agents the signals they need. Social engineering attacks often succeed because the tools available don’t give agents enough information to make the right call. Persona gives agents the verification layer they need to confirm identity before granting access.

More than half of security leaders consider the help desk their single biggest identity risk. With the right account recovery controls in place, security teams can stop attackers at the help desk before the call becomes a compromised account.

Get started with Persona and Microsoft Entra ID

Persona’s integration with Microsoft Entra ID is part of Persona’s broader approach to workforce identity. From candidate verification and onboarding to account recovery, Persona helps organizations confirm that people are who they claim to be and strengthen identity assurance at critical moments across the employee lifecycle.

No organization is too large or small to be targeted through the help desk, and the frequency and sophistication of these attacks are increasing. Book a demo to see how Persona and Microsoft Entra ID work together, or explore Persona’s workforce identity solution.

The information provided is not intended to constitute legal advice; all information provided is for general informational purposes only and may not constitute the most up-to-date information. Any links to other third-party websites are only for the convenience of the reader.

FAQs

How do threat actors socially engineer the help desk?

Toggle description visibility

Many attackers call IT help desks and pose as legitimate employees. The attacker may claim to be locked out of their account because they forgot their password or MFA or that they need to enroll a new device. To pass basic knowledge-based questions, the attacker may use personal information gathered from social media platforms like LinkedIn, data breaches, or even prior phishing.

Once the attacker has convinced the agent to reset MFA or issue a temporary bypass, they gain full account access. Cybercrime groups like Scattered Spider used these attack tactics to execute the high-profile breaches targeting MGM Resorts and Caesars in 2023.

What is vishing and how does it target IT support agents?

Toggle description visibility

Vishing, or voice phishing, is a social engineering attack conducted over phone calls. The attacker may impersonate a trusted person (e.g., an employee) to manipulate the target (e.g., an IT agent) into providing sensitive information. 

Vishing exploits a person’s natural instinct to be helpful. For example, the attacker may create false urgency by pretending to be a frustrated executive or remote employee locked out of an account before an important meeting. 

IT support agents are frequent targets for vishing due to their authority to reset passwords, disable MFA, and provision account access. Without strong identity verification protocols, IT agents can be manipulated into handing over access in minutes.

What is the best way to prevent social engineering at the service desk?

Toggle description visibility

The most effective defense combines strict process controls with continuous help desk training. Security teams should:

  • Require identity verification regardless of how urgent the caller's situation seems. 

  • Implement a zero-trust policy for high-risk actions (e.g., MFA changes, admin access grants) that requires approval from a manager or security team. 

  • Regularly run tabletop exercises and simulated social engineering calls so IT agents can practice recognizing manipulation and refusing fraudulent requests.

Joshua Rodriguez
Joshua Rodriguez
Joshua Rodriguez is a product marketing manager at Persona covering fraud and workforce identity. You'll find him around the Bay Area exploring parks and museums with his wife and two kids.

Continue reading