Skip to content
MSP Process

HaloPSA AI VoiceAssist with Authenticator verification and SMS

Your clients, verified.
Your team, ready.

A shield cutting a hooked phone line

MSP Process helps your team verify callers and technicians through your existing multifactor authentication (MFA) before handling requests that change access. Social engineering calls exploit trust at the helpdesk, with MGM, Caesar's, Change Healthcare and Snowflake among the names in reported nine-figure breaches over two years.

U.S. social engineering losses 2023 to 24 (FBI IC3)
$13B+
Rise in vishing attacks since 2022 (CrowdStrike)
1,265%
Identity checks before privileged actions
100%

WHAT TO RECOGNISE

Familiar requests.
Reasons to verify.

Your team needs a consistent identity check before changing access, even when a caller sounds familiar or knows the client. These four social engineering patterns show the requests your service desk can encounter in 2026.

  • Caller identity before credential resets

    Reported incidents include MGM losing $100M+, Caesar's paying a $15M ransom and Snowflake customers exposing data from 165 companies, alongside helpdesk impersonation associated with Scattered Spider / UNC3944.

    • Employee names and familiar details
    • Urgent requests for credential resets
    • Requests for replacement authentication devices
    Scattered Spider, UNC3944
  • Identity checks before access changes

    Change Healthcare's $22M ransomware incident gives your team a concrete case to discuss when reviewing credential resets and caller identity checks.

    • Caller identity before credential changes
    • Verification of urgent access requests
    • Clear records of technician actions
    ALPHV / BlackCat
  • Identity beyond a familiar voice

    Arup engineering lost $25M in a deepfake video call where every "executive" was synthetic, illustrating why a familiar voice needs an identity check.

    • Familiar voices without identity proof
    • Executive names and urgent requests
    • Verification beyond displayed caller identity
    AI Voice Cloning
  • Approval checks with Authenticator and Duo

    Uber, Cisco and Microsoft faced approval-fatigue attacks in 2022 to 23, with repeated authentication prompts such as pushes at 11pm pressuring users into approval.

    • Repeated prompts on enrolled devices
    • Unexpected requests outside working hours
    • Caller verification alongside authentication approval
    MFA Push Bombing

INSIDE THE REQUEST

A request arrives.
An identity check matters.

Walk through a caller's request with your team, from the details they offer to the access they ask you to change. At step three, verification gives your technician a clear basis for handling the request.

  1. Public details gathered beforehand

    An attacker spends Three to seven days gathering staff names, reporting lines and project details from LinkedIn to make a helpdesk call sound familiar.

  2. A familiar sounding request

    The caller uses those details to impersonate an employee: "I'm locked out, my board call is in eight minutes, please."

  3. Access changed on trust

    Without verification, your technician may reset a password, enroll a replacement authentication device or approve a remote session based on the caller's story.

  4. Access beyond the original account

    The attacker searches for Tier-0 accounts, identity providers and endpoint detection and response consoles, then moves into connected systems. The described dwell time averages 11 to 28 days, while your security operations centre (SOC) investigates activity that appears internal.

  5. Disruption across the client's systems

    Encryption or data theft can interrupt your client's operations, with the investigation tracing the access change back to the call at step three.

A Zero Trust helpdesk that refuses to be the door.

The fix is not more training, more checklists, or a sharper script. It's a verification gate built into your service desk that runs the same way every time, on voice, in chat, on every channel. MSP Process answers the call, identifies the caller against your IdP, pushes MFA to a registered device, and refuses to grant access until the response clears.

Patent-pending voice verification, integrated with the MFA you already run.

The fix is not more training, more checklists, or a sharper script. It's a verification gate built into your service desk that runs the same way every time, on voice, in chat, on every channel. MSP Process answers the call, identifies the caller against your IdP, pushes MFA to a registered device, and refuses to grant access until the response clears.

The AI agent answers in your brand, captures the caller's intent, looks them up in Entra ID, Okta, or Active Directory, and pushes an Authenticator, Duo, or SMS challenge to the registered device. No challenge clears, no privileged action runs. No verification, no transfer to a human tech. A pretexting attempt is met with a polite refusal and an audit row, not a credential reset.

  • AI Voice agent answers 24/7, no after-hours bypass
  • Caller identified against your IdP, not caller ID or voice tone
  • MFA push (Authenticator, Duo, Okta) to the registered device
  • Deepfake- and voice-clone-resistant by construction
  • Reverse technician verification, clients confirm your tech is real
  • Full identity chain + transcript written to PSA ticket

SEE IT WORK

One call. A clear outcome.

Live
  1. 01A password reset requestCaptured

    1 "This is Alex, reset my password, board call in 8."

  2. 02The caller's identity lookupIdentified

    An identity match in Entra ID, with a device enrolled.

  3. 03An identity approval request

    The push times out without approval from the enrolled device.

  4. 04The request refused and recordedBlocked

    ServiceNow INC0143 is flagged for your security operations centre to review.

WHERE IT WORKS

Your clients' channels.
Your verification process.

MSP Process brings the same identity check to phone calls, Teams chat, email, text messages and your client portal before access changes.

  • Verification for voice and phone

    Your helpdesk, branch and after-hours calls go through identity verification before your team handles a reset, unlock or remote session.

    • Identity checks for inbound calls
    • Verification before resets and unlocks
    • Caller checks before remote sessions
  • Verification within Microsoft Teams

    Your clients' "Hey IT" requests in Teams trigger a verification challenge within the conversation, keeping the identity check alongside the request.

    • Verification within the existing conversation
    • Identity challenges for support requests
    • Client requests and checks together
  • Verification for SMS & WhatsApp

    A text from "the CFO" requesting a credential reset gets a separate identity check before your team responds to the request.

    • Identity checks for text requests
    • Separate verification of claimed identities
    • Credential requests checked before response
  • Email and client portal verification

    Your clients' email-driven password resets, beneficiary changes and document-sharing approvals go through an authentication push before the requested action takes place.

    • Authentication before email-driven password resets
    • Identity checks for beneficiary changes
    • Verification before document-sharing approvals proceed

WHAT YOU LEAVE WITH

Your verification records.
Ready for review.

We help your team bring caller verification records to renewal conversations with Coalition, At-Bay, Chubb and Travelers. Use those records to explain your process, including how you handle identity checks as a documented control beyond "best practice".

  • Evidence for insurance renewal

    We help your team show how callers are verified before credential changes, with records for your insurance renewal review.

    • Records of caller identity checks
    • Verification evidence for credential changes
    • Helpdesk process details for review
  • SOC 2 Type II

    We help your team bring verification records to discussions about access control and monitoring during your audit review.

    • Caller verification records for review
    • Recorded outcomes of access requests
    • Evidence of helpdesk identity checks
  • HIPAA Security Rule

    We help your team gather identity verification records for a review of your process against 45 CFR 164.308.

    • Identity verification records for review
    • Documented checks before access changes
    • Helpdesk request outcomes and records
  • PCI DSS 4.0

    We help your team bring helpdesk authentication records to your review of Req. 8 and the access requests you handle.

    • Authentication records for helpdesk requests
    • Verification outcomes before access changes
    • Request records for authentication review
  • FFIEC CAT

    We help your team explain helpdesk identity checks during a review of external dependencies and access to client systems.

    • Helpdesk identity checks for review
    • Records of client access requests
    • Verification evidence for dependency discussions
  • NIST CSF 2.0

    We help your team bring identity verification records to discussions of PR.AA Identity management and your helpdesk access process.

    • Identity records for access reviews
    • Verification outcomes for helpdesk requests
    • Documented checks before credential changes
  • CIS Controls v8

    We help your team present helpdesk verification records when reviewing Control 6.5 and the authentication steps around access requests.

    • Helpdesk authentication records for review
    • Verification evidence before access changes
    • Recorded outcomes of identity checks
  • ISO 27001:2022

    We help your team bring helpdesk verification records to your review of A.5.16 identity management and related access processes.

    • Identity management evidence for review
    • Caller checks before credential changes
    • Recorded verification outcomes for requests

WHAT TO REVIEW

Your helpdesk process.
Visible in the records.

0
Privileged actions without identity verification
Refused at the helpdesk before any access change
< 6s
Time from call to verified identity
From AI greeting to MFA push approval
100%
Requests with an attached audit record
Caller, method, device, time on every action
−73%
Time your team spends handling requests
AI handles intake & triage before the tech

LET'S TALK VERIFICATION

Bring your helpdesk process.
See verification at work.

In a walkthrough, we'll show a simulated social engineering call reaching the AI Voice agent, the authentication challenge and the refused action. You'll see the audit record in a sample PSA (professional services automation) environment.

  1. Walkthrough

  2. Product walkthrough

  3. A quote for your MSP

Tell us about your MSP.

  • Torch Awards, Most Innovative 2025
  • AICPA SOC for Service Organizations