Loading_
Loading_
Self-service credential recovery with adaptive verification that removed 31% of all service desk calls.
Measured outcomes
92s
Median self-service reset
4,100 → 380
Monthly password calls
0
Social-engineering incidents
$412k
Annual saving
Password and lockout calls were the single largest ticket category — 4,100 a month, each costing roughly nine minutes of an agent’s time and leaving the user blocked in the meantime.
The portal handles reset, unlock and MFA re-enrolment with verification strength that adapts to risk signals, and it works from the Windows lock screen for users who cannot log in at all.
Headline result
0%
of all calls removed
Tags
Five capabilities that define the system. Each one exists because something specific was broken.
Verification strength scales with risk — unfamiliar device, impossible travel or off-hours access demand more.
A credential provider extension lets locked-out users self-recover without a second device.
New passwords are checked against AD policy and a breached-password corpus before submission.
Resets propagate to on-prem AD and Entra ID with confirmation from both.
Every verification factor, decision and outcome is recorded for investigation.
A hardened public endpoint that never talks to AD directly — an outbound-only agent inside the perimeter performs the write.
3 components
No inbound path to the domain; DMZ holds no credentials.
3 components
The agent polls out; the firewall needs no inbound rule.
3 components
Write-back confirmed against both directories before success is reported.
No mystery components. Everything below is either open source or a platform you already own.
Interactive mock-ups of the shipped interface. The live environment is available during a demo session.
Adaptive factor selection based on risk score
The running environment is available during a booked session — including a sandbox tenant you can drive yourself.
The real sequence, in order. Steps with a command are copy-pasteable.
App Service with WAF, plus Key Vault for secrets.
$terraform apply -var-file=prod.tfvarsDomain-joined Windows service with a delegated reset-only account.
$msiexec /i AIInfraEngine.Bridge.msi /qnSet factor requirements per risk band and connect the breached-password feed.
Deploy the lock-screen extension through Intune or SCCM.
Published rather than hidden behind a call. Volume and multi-year terms move these numbers.
Platform
$1.80per user / month
Deployment
from $28kone-time
Need this scoped against your estate? We will size it properly, in writing, within a week.
Request a quoteWe will walk you through the architecture, the trade-offs we made, and what would change for your environment.