Account Recovery: The Unseen Weakness in Identity Security
Microsoft and Okta have recently made significant announcements regarding identity security, highlighting the evolving nature of authentication methods. Microsoft has announced that passkeys will become the default authentication method in Microsoft Entra ID by the end of this year, while deprecating SMS and voice options. Meanwhile, Okta's threat intelligence team has published research showing how attackers are targeting passkey enrolment and recovery flows to complete account takeovers.
The convergence of these events raises a critical question for CIOs: what happens when an employee claims they have lost their device? Stronger authentication methods do not stop attacks, but rather redirect them to other vectors. Phishing-resistant MFA makes the login screen harder to crack, but attackers are moving to other parts of the identity lifecycle that are still soft.
Okta's research has identified enrolment and account recovery as the next weakest points in the user lifecycle. Microsoft has also documented a threat group, tracked as Storm-2949, which breached a cloud environment by triggering a self-service password reset (SSPR) for a target account. The attackers then impersonated IT support to talk the victim employee into approving an MFA prompt.
Account recovery is a critical aspect of identity security that has been overlooked in the shift towards stronger authentication methods. Authentication during account recovery does not verify the person behind the action, but rather confirms their access to something. This creates a social engineering opportunity for attackers.
The solution lies in designing a recovery flow that upgrades to an even higher-assurance factor. CIOs should evaluate their account recovery controls by asking whether they verify the identity of the human or only confirm their possession of a particular credential or device.