Skip to content

Credential & Identity Access

Credential and identity access manipulates the people and workflows that govern identity, including users, helpdesk agents, approvers, administrators, mobile carriers, and access owners. The objective may be a password, authenticator action, account recovery, session, token, consent grant, delegated access, or control of a phone number used in recovery.

Credentials, sessions, tokens and access grants can turn a successful interaction into authenticated or continuing access. Identity controls may be weakened where a user, support agent, approver, or administrator is induced to disclose, reset or approve something outside the intended workflow.

A valid authentication or genuine approval does not by itself establish that the underlying request was authorised or safe. Credential and identity access can be assessed by asking:

  • What credential, factor, session, token, approval, or access state is being targeted?
  • Who is being influenced to create or expose that access?
  • Does the action match an expected identity workflow and business need?
  • What notification, review, or recovery step can detect and contain misuse?

Credential & Identity Access includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Credential and identity access activity may involve one or more of the following behaviours:

Credential and authentication targeting

  • directing users to login portals, consent screens, verification pages, or approval prompts
  • requesting usernames, passwords, recovery codes, one-time codes, device codes, or MFA approvals
  • creating urgency around account access, security, suspension, compliance, or missed messages
  • delivering login, recovery, consent, or approval lures through email, SMS, chat, calendar invites, shared documents, or collaboration platforms
  • using fake authentication interfaces, system notifications, support interactions, or mirrored identity workflows

MFA and approval manipulation

  • sending multiple MFA push notifications in quick succession
  • asking users to approve a prompt, enter a code, scan a QR code, or complete a device-code flow
  • framing the approval as routine, urgent, required, or part of an IT/security process
  • exploiting fatigue, cognitive load, confusion, fear, urgency, or authority pressure to gain approval
  • asking users not to report unexpected prompts because the issue is “being handled”

Identity workflow and recovery behaviour

  • requesting password resets, MFA resets, account unlocks, security information changes, or recovery method updates
  • pressuring helpdesk, identity, HR, or managers to act quickly on account recovery or access restoration
  • using stories about lost phones, urgent travel, inaccessible accounts, locked portals, or business disruption
  • targeting a mobile carrier to port, transfer, or reassign a user’s number so SMS or voice one-time codes and phone-based recovery can be intercepted
  • providing documents, phone numbers, email addresses, or identity proofing details that cannot be independently verified
  • attempting repeated recovery through different staff, teams, or channels after delay or refusal

Access and consent behaviour

  • encouraging users or administrators to grant app consent, external sharing, delegated access, mailbox access, privileged access, or elevated roles
  • presenting access approval as already authorised, routine, time-sensitive, or required by a senior person
  • exploiting shared accounts, generic accounts, delegated permissions, weak ownership, or unclear approval paths
  • requesting approval outside the expected workflow or without a verifiable business need