Account lockout and password reset: a secure help desk process

For help desks and staff: handle a lockout, forgotten password or lost MFA device, verify identity safely and spot account takeover.

Account lockout and password reset: a secure help desk processUserHelp DeskSecurityWHAT'S WRONGVERIFY IDENTITYRESET AND RECOVERSECURITY REVIEWForgot passwordYesNoLocked outYesYesLost MFA deviceYesNoNoYesPasswordMFA methodBothYesNoNoNo or not sureNoYesCan't sign in to a workaccountFor help desks and staff: handle alockout, forgotten password or lostMFA device, verify identity safely andspot account takeover.Typical practice. Adapt it to your ownpolicy. Based on NIST SP 800-63B-4(August 2025) and CISA and NCSCadvice.Which problem doyou have?Try self-service passwordresetUse the "Forgot password" link on thesign-in page. It checks a method youset up earlier, such as anauthenticator app, a security key or arecovery code.Did self-servicereset work?Signed in with a newpasswordContact the help deskthrough a known channelUse the phone number or portal fromthe intranet, your badge oronboarding pack. Never use contactdetails from an email, text or pop-up.Did you make the failedsign-ins yourself?Repeated wrong passwords lock orslow the account. Your policy setsthe limit and how long the lock lasts.If you didn't cause the lockout,someone may be guessing yourpassword.Wait for the lock to clear oruse self-service unlockCheck Caps Lock and the keyboardlanguage before you try again.Unlocked and signedin?Signed in after the lockclearedSign in with a backupmethod or recovery codeBackup methods include a secondsecurity key, another authenticatorapp, or saved one-time recoverycodes.Signed in with abackup method?Remove the lost device andregister a new oneRemove the lost phone or key fromyour security settings so nobodyelse can use it.Lost device removed. NewMFA registeredHelp desk takes the requestCallers can be attackers. Groupssuch as Scattered Spider phone helpdesks posing as staff to getpasswords reset and MFA moved totheir own devices (CISA advisoryAA23-320A).Check for signs ofcompromiseLockouts the user didn't cause,sign-in alerts or MFA prompts theydidn't trigger, new MFA devices, orsign-ins from unusual places.Pressure, urgency or requests to skipsteps are warning signs. Take extracare with admin and other privilegedaccounts.Any signs ofcompromise?Verify identity with a checkan attacker can't passDon't rely on facts an attacker canfind or buy: name, employee ID, dateof birth, manager's name or answersto security questions.Common checks: call back on thenumber already in the HR ordirectory record, not one the callergives. Or a video call against the IDphoto, an in-person visit, or managerapproval through a known channel.Is the identityconfirmed?Refuse the reset and log theattemptIdentity confirmedWhat needsresetting?Set a one-time passwordthat must change at nextsign-inGive it only through the verifiedchannel. Make it short-lived.Remove the old MFA methodand issue a one-time setupcodeRemove the lost device beforeadding a new one. Keep the setupcode short-lived. NIST allows 10minutes for codes sent by text orvoice and 24 hours by email.Reset the password andremove the old MFA methodIssue a one-time password and ashort-lived setup code through theverified channel.User signs in and sets a newpasswordChoose a long password not usedanywhere else. NIST says don't forceroutine password changes, butalways force a change when there'sevidence of compromise.Register MFA againPrefer phishing-resistant MFA suchas a security key or passkey (FIDO2or WebAuthn). CISA recommends it,especially for email, VPN and criticalsystems.Send a reset notice to theuser's other contactsNIST requires a notification afteraccount recovery so the real ownercan spot fraud. Send it to everynotification address on file.Log how identity was verifiedand what was resetRecord who asked, the time, theverification method, who approved itand what changed. Security teamsuse this to spot repeated attempts.Account recovered. TicketclosedReport suspected accounttakeover to securityInclude the user, the times oflockouts or alerts, source addressesif known, and any caller details suchas the number they called from.Revoke sessions and blocksign-inSign the account out everywhere andrevoke tokens. Keep sign-in blockeduntil the real owner is verified.Review sign-in logs, MFAchanges and mailbox rulesLook for new MFA devices, emailforwarding rules, risky or unusualsign-ins flagged by your identityprovider, and access to sensitivedata.Was the accounttaken over?Open a security incident andcontain itReset the password and every MFAmethod, find what was accessed, andfollow your incident response plan.Send back to the help deskfor a verified reset

What's wrong

  1. Can't sign in to a work accountUser

    For help desks and staff: handle a lockout, forgotten password or lost MFA device, verify identity safely and spot account takeover.

    Typical practice. Adapt it to your own policy. Based on NIST SP 800-63B-4 (August 2025) and CISA and NCSC advice.

  2. Which problem do you have?User
  3. Try self-service password resetUser

    Use the "Forgot password" link on the sign-in page. It checks a method you set up earlier, such as an authenticator app, a security key or a recovery code.

  4. Did self-service reset work?User
  5. Signed in with a new passwordUser
  6. Contact the help desk through a known channelUser

    Use the phone number or portal from the intranet, your badge or onboarding pack. Never use contact details from an email, text or pop-up.

    Then go to step 15, Help desk takes the request

  7. Did you make the failed sign-ins yourself?User

    Repeated wrong passwords lock or slow the account. Your policy sets the limit and how long the lock lasts.

    If you didn't cause the lockout, someone may be guessing your password.

  8. Wait for the lock to clear or use self-service unlockUser

    Check Caps Lock and the keyboard language before you try again.

  9. Unlocked and signed in?User
  10. Signed in after the lock clearedUser
  11. Sign in with a backup method or recovery codeUser

    Backup methods include a second security key, another authenticator app, or saved one-time recovery codes.

  12. Signed in with a backup method?User
  13. Remove the lost device and register a new oneUser

    Remove the lost phone or key from your security settings so nobody else can use it.

  14. Lost device removed. New MFA registeredUser

Verify identity

  1. Help desk takes the requestHelp Desk

    Callers can be attackers. Groups such as Scattered Spider phone help desks posing as staff to get passwords reset and MFA moved to their own devices (CISA advisory AA23-320A).

  2. Check for signs of compromiseHelp Desk

    Lockouts the user didn't cause, sign-in alerts or MFA prompts they didn't trigger, new MFA devices, or sign-ins from unusual places.

    Pressure, urgency or requests to skip steps are warning signs. Take extra care with admin and other privileged accounts.

  3. Any signs of compromise?Help Desk
  4. Verify identity with a check an attacker can't passHelp Desk

    Don't rely on facts an attacker can find or buy: name, employee ID, date of birth, manager's name or answers to security questions.

    Common checks: call back on the number already in the HR or directory record, not one the caller gives. Or a video call against the ID photo, an in-person visit, or manager approval through a known channel.

  5. Is the identity confirmed?Help Desk
  6. Refuse the reset and log the attemptHelp Desk

    Then go to step 31, Report suspected account takeover to security

  7. Identity confirmedHelp Desk

Reset and recover

  1. What needs resetting?Help Desk
  2. Set a one-time password that must change at next sign-inHelp Desk

    Give it only through the verified channel. Make it short-lived.

    Then go to step 26, User signs in and sets a new password

  3. Remove the old MFA method and issue a one-time setup codeHelp Desk

    Remove the lost device before adding a new one. Keep the setup code short-lived. NIST allows 10 minutes for codes sent by text or voice and 24 hours by email.

    Then go to step 26, User signs in and sets a new password

  4. Reset the password and remove the old MFA methodHelp Desk

    Issue a one-time password and a short-lived setup code through the verified channel.

  5. User signs in and sets a new passwordUser

    Choose a long password not used anywhere else. NIST says don't force routine password changes, but always force a change when there's evidence of compromise.

  6. Register MFA againUser

    Prefer phishing-resistant MFA such as a security key or passkey (FIDO2 or WebAuthn). CISA recommends it, especially for email, VPN and critical systems.

  7. Send a reset notice to the user's other contactsHelp Desk

    NIST requires a notification after account recovery so the real owner can spot fraud. Send it to every notification address on file.

  8. Log how identity was verified and what was resetHelp Desk

    Record who asked, the time, the verification method, who approved it and what changed. Security teams use this to spot repeated attempts.

  9. Account recovered. Ticket closedHelp Desk

Security review

  1. Report suspected account takeover to securitySecurity

    Include the user, the times of lockouts or alerts, source addresses if known, and any caller details such as the number they called from.

  2. Revoke sessions and block sign-inSecurity

    Sign the account out everywhere and revoke tokens. Keep sign-in blocked until the real owner is verified.

  3. Review sign-in logs, MFA changes and mailbox rulesSecurity

    Look for new MFA devices, email forwarding rules, risky or unusual sign-ins flagged by your identity provider, and access to sensitive data.

  4. Was the account taken over?Security
  5. Open a security incident and contain itSecurity

    Reset the password and every MFA method, find what was accessed, and follow your incident response plan.

  6. Send back to the help desk for a verified resetHelp Desk

    Then go to step 18, Verify identity with a check an attacker can't pass

Outcomes

Signed in with a new password

You get here from step 4, Did self-service reset work? (Yes).

Signed in after the lock cleared

You get here from step 9, Unlocked and signed in? (Yes).

Lost device removed. New MFA registered

You get here from step 13, Remove the lost device and register a new one.

Account recovered. Ticket closed

You get here from step 29, Log how identity was verified and what was reset.

Open a security incident and contain it

Reset the password and every MFA method, find what was accessed, and follow your incident response plan.

You get here from step 34, Was the account taken over? (Yes).