Defending Against Identity Threats: A Privilege-Centric Approach to Service Desk Security
Overcoming Cyberattacks Against Service Desks
Attacks targeting service desks are on the rise, with over half (51%) of organizations reporting that social engineering attacks on the help desk / service desk are their most significant risk.
Threat actors understand that compromising a service desk identity with access to accounts and standing privileges can give them the “keys to the kingdom”. Because service desks have the authority to perform high-risk actions, such as resetting passwords or disabling multi-factor authentication (MFA), they have become an attack vector used to bypass technical security controls.
Support teams are often targeted through sophisticated social engineering, phishing, and even deepfakes. Weak verification processes, shared administrative accounts, and broad VPN access only widen the attack surface.
To turn the tide, organizations must treat service desk solutions as a core component of their privileged access management (PAM) strategy. This involves:
- Removing “always-on” admin rights
- Switching to secure remote support that hides credentials
- Gaining end-to-end visibility into identity pathways
- Enforcing phishing-resistant MFA and monitoring high-risk identity actions, like MFA resets
The key to significantly hardened service desk security is to reduce unnecessary access while also keeping support teams fast and effective—ultimately a PAM approach to strengthening security where it matters most.
Continue Reading HERE
Customer Case Study
ivision: How ivision Simplifies and Scales Identity Security with BeyondTrust
Latest Available Version
Remote Support 26.1.1 - April 2026
Beekeepers Hot Topics
Password Safe and RS integration to add credentials to the vault from Password Safe
“I integrated Remote Support's Vault to import managed accounts from Password Safe, and the import is working perfectly. My question: When I perform a remote access, the Vault tab in the RS console shows the account that was imported and another generic credential created locally in the RS Vault. But when I perform a privilege escalation in Remote Support, I can only use the generic credential. I don't have the option to use the credential imported from Password Safe. Is this a limitation of Remote Support? Remember that since I'm using Remote Support for workstation support, I don't have the workstation endpoint registered in Password Safe under Managed System. Tks”
BeyondTrust with Windows Multi App Kiosk on Intune
“Does anyone know how to get BeyondTrust Jump Client or Customer Client working with interactivity on Intune Multi-App Kiosk machines? We have our Jump Client installed but there’s no interactivity in Kiosk mode. And Customer Client simply gets blocked.
Part of the issue with whitelisting apps with AssignedAccess seems to be the multiple EXEs to whitelist and not allowing dynamic paths. E.g. I think bomgar-scc.exe needs to be whitelisted but it lives in C:\Program Files\BeyondTrust\bomgar-scc\*\ bomgar-scc.exe”
The Representative Console appears to be running already, but the existing instance failed to activate.
“I have a user that launches the representative console, successfully authenticates with SSO and is redirected to the desktop application which then prompts with “The Representative Console appears to be running already, but the existing instance failed to activate.”
I have seen this before and a reboot fixes it, but not with this user.
-
This issue persists through reboots as well as a full uninstall/reinstall of the representative console for this user.
-
The web console works for this user.
-
If they sign in as a local Remote Support user (different than the SSO account) it will work through the desktop application.
-
I see in the debug logs it says, “Failed to obtain singleton lock”, but not much else for details.
Click here for the most popular articles In our Beekeepers Community.
Upcoming and In Case You Missed It Webinars
Road Maps: Remote Support Road Map
User Group: Remote Support User Group
Blog: Remote Support 26.1: Simplifying Secure Service Desk Operations
Tech Talk Tuesday - What's new in the Identity Security Risk Assessment 2.0?
Improving Confidence Beyond SSO and MFA – June 9, 2026
Least Privilege and AI – Can they co-exist? – June 11, 2026
Securing Industrial Control Systems: Rethinking Privileged Access in OT and SCADA Environments – Jun 11, 2026
Copilot Studio Agents: Attacks and Defenses – June 16, 2026



