Employee onboarding has become a high-risk identity moment. Service desk teams are under pressure to help new starters quickly, but when speed takes priority over verification, strong checks can be missed and support processes can be manipulated. Major breaches involving Marks & Spencer and Clorox show how service desk workflows can become an attack path.
The risk is even greater when a new hire has not yet established a trusted identity within the organization. With artificial intelligence (AI) enabling more convincing impersonation attempts, organizations need stronger ways to confirm a new starter’s identity before granting access.
Why onboarding is now an identity security challenge
The service desk plays a key role in employee onboarding, but several trends are now making it harder for analysts to accurately judge the legitimacy of a request.
AI-powered attacks: AI helps attackers craft convincing phishing messages, create cloned voices and execute other social engineering techniques. Service desk analysts must treat every identity-related request with greater scrutiny.
Remote and hybrid work: New employees and contractors are often onboarded without meeting HR or IT in person. Global hiring and outsourced support mean analysts must establish trust remotely, with limited context and pressure to provide access quickly.
Attacks on identity workflows: Requests like password resets and account recovery can give attackers access without defeating security tools. Scattered Spider has repeatedly used employee impersonation to manipulate service desk teams, with attacks on M&S and MGM Resorts using convincing support requests.
Day-one pressure: The pressure to get new hires productive quickly can lead to risky shortcuts, such as sending temporary passwords by email. Without strong identity checks and approval workflows, attackers can hijack onboarding and gain a direct route into the business.
Securing the modern onboarding process
Secure onboarding combines protected credential creation, strong identity verification and consistent service desk controls. Specops Secure Onboarding supports each stage by confirming identities before access is granted or sensitive actions are completed.
Before day one
Rather than sending temporary passwords by email, SMS or manual handoff, the service desk can simply share a secure enrolment link through Specops Secure Onboarding. New starters verify their identity and create their own Active Directory password, removing the need for IT to generate or share credentials.
On the first day
Specops Secure Onboarding verifies that the person activating the account is the intended new hire. Biometric liveness detection confirms the user is real and present, while comparison with a government-issued identity document helps establish identity before first login.
When new hires need help
The service desk must continue verifying identity before password resets, MFA recovery and other high-risk actions. Specops Secure Onboarding prevents agents from completing sensitive requests until the user has passed secure identity challenges, reducing guesswork and helping genuine employees get support quickly.
Secure onboarding starts with strong identity assurance
As AI makes identity-based attacks more convincing, Specops Secure Onboarding puts identity verification at the heart of onboarding, helping organizations protect new starters, standardize the process and reduce service desk risk.
Identity assurance should extend to password risks already present in Active Directory. Specops Password Auditor gives teams a free, read-only view of weak, compromised or policy-related password issues before attackers can exploit them.
Contact us to book a demo and see how our solutions can strengthen your defenses against identity-based attacks.