What's wrong
- Can't sign in to a work accountUser
For help desks and staff: handle a lockout, forgotten password or lost MFA device, verify identity safely and spot account takeover.
Typical practice. Adapt it to your own policy. Based on NIST SP 800-63B-4 (August 2025) and CISA and NCSC advice.
- Which problem do you have?User
- Forgot password: go to step 3, Try self-service password reset
- Locked out: go to step 7, Did you make the failed sign-ins yourself?
- Lost MFA device: go to step 11, Sign in with a backup method or recovery code
- Try self-service password resetUser
Use the "Forgot password" link on the sign-in page. It checks a method you set up earlier, such as an authenticator app, a security key or a recovery code.
- Did self-service reset work?User
- Signed in with a new passwordUser
- Contact the help desk through a known channelUser
Use the phone number or portal from the intranet, your badge or onboarding pack. Never use contact details from an email, text or pop-up.
Then go to step 15, Help desk takes the request
- Did you make the failed sign-ins yourself?User
Repeated wrong passwords lock or slow the account. Your policy sets the limit and how long the lock lasts.
If you didn't cause the lockout, someone may be guessing your password.
- Yes: go to step 8, Wait for the lock to clear or use self-service unlock
- No or not sure: go to step 31, Report suspected account takeover to security
- Wait for the lock to clear or use self-service unlockUser
Check Caps Lock and the keyboard language before you try again.
- Unlocked and signed in?User
- Signed in after the lock clearedUser
- Sign in with a backup method or recovery codeUser
Backup methods include a second security key, another authenticator app, or saved one-time recovery codes.
- Signed in with a backup method?User
- Remove the lost device and register a new oneUser
Remove the lost phone or key from your security settings so nobody else can use it.
- Lost device removed. New MFA registeredUser
Verify identity
- Help desk takes the requestHelp Desk
Callers can be attackers. Groups such as Scattered Spider phone help desks posing as staff to get passwords reset and MFA moved to their own devices (CISA advisory AA23-320A).
- Check for signs of compromiseHelp Desk
Lockouts the user didn't cause, sign-in alerts or MFA prompts they didn't trigger, new MFA devices, or sign-ins from unusual places.
Pressure, urgency or requests to skip steps are warning signs. Take extra care with admin and other privileged accounts.
- Any signs of compromise?Help Desk
- Verify identity with a check an attacker can't passHelp Desk
Don't rely on facts an attacker can find or buy: name, employee ID, date of birth, manager's name or answers to security questions.
Common checks: call back on the number already in the HR or directory record, not one the caller gives. Or a video call against the ID photo, an in-person visit, or manager approval through a known channel.
- Is the identity confirmed?Help Desk
- No: go to step 20, Refuse the reset and log the attempt
- Yes: go to step 21, Identity confirmed
- Refuse the reset and log the attemptHelp Desk
Then go to step 31, Report suspected account takeover to security
- Identity confirmedHelp Desk
Reset and recover
- What needs resetting?Help Desk
- Set a one-time password that must change at next sign-inHelp Desk
Give it only through the verified channel. Make it short-lived.
- Remove the old MFA method and issue a one-time setup codeHelp Desk
Remove the lost device before adding a new one. Keep the setup code short-lived. NIST allows 10 minutes for codes sent by text or voice and 24 hours by email.
- Reset the password and remove the old MFA methodHelp Desk
Issue a one-time password and a short-lived setup code through the verified channel.
- User signs in and sets a new passwordUser
Choose a long password not used anywhere else. NIST says don't force routine password changes, but always force a change when there's evidence of compromise.
- Register MFA againUser
Prefer phishing-resistant MFA such as a security key or passkey (FIDO2 or WebAuthn). CISA recommends it, especially for email, VPN and critical systems.
- Send a reset notice to the user's other contactsHelp Desk
NIST requires a notification after account recovery so the real owner can spot fraud. Send it to every notification address on file.
- Log how identity was verified and what was resetHelp Desk
Record who asked, the time, the verification method, who approved it and what changed. Security teams use this to spot repeated attempts.
- Account recovered. Ticket closedHelp Desk
Security review
- Report suspected account takeover to securitySecurity
Include the user, the times of lockouts or alerts, source addresses if known, and any caller details such as the number they called from.
- Revoke sessions and block sign-inSecurity
Sign the account out everywhere and revoke tokens. Keep sign-in blocked until the real owner is verified.
- Review sign-in logs, MFA changes and mailbox rulesSecurity
Look for new MFA devices, email forwarding rules, risky or unusual sign-ins flagged by your identity provider, and access to sensitive data.
- Was the account taken over?Security
- Open a security incident and contain itSecurity
Reset the password and every MFA method, find what was accessed, and follow your incident response plan.
- Send back to the help desk for a verified resetHelp Desk
Then go to step 18, Verify identity with a check an attacker can't pass