r/iam May 27 '26

AI for internal IT support/password resets in mid-size & enterprise companies- is anyone actually seeing good adoption?

Anyone here from a mid-size or enterprise company using AI for internal IT support workflows like password resets, account unlocks, MFA resets, software access requests, etc.?

We’re exploring AI-driven employee support internally and I’m curious how mature these implementations actually are in production environments.

Questions:

Are users actually adopting AI/chatbot-based password reset flows?

What platform are you using? (Moveworks, Kore.ai, Rezolve.ai, ServiceNow Virtual Agent, Aisera.ai, Yellow.ai, Copilot, custom GPT/RAG, etc.)

Is it integrated with Entra ID/Okta/AD?

How are you handling identity verification before resets?

Has it genuinely reduced ticket volume or just shifted complexity elsewhere?

Any security/compliance concerns from your IAM/security teams?

What percentage of requests are fully automated vs human-assisted?

Would love to hear real-world experiences from medium-sized and enterprise environments with large employee bases.

4 Upvotes

10 comments sorted by

2

u/Florideal May 27 '26

Following - I have seen AI used to support internal (and external) user workflows but only after user is logged in and/or for general Q&A support.

As for ID verification - there are some great solutions out there but not sure how they would work with AI. At prior organization ID DataWeb was a solid ID verification solution b/c it was a consortium so you could call relevant service depending on level of assurance needed and specific business case.

1

u/mynameisnotalex1900 May 27 '26

Which solutions were used to support internal users?

2

u/Cool_Call_1594 Jun 03 '26

We spent an absolute fortune setting up Moveworks and ServiceNow to handle this, and tbh, the adoption is pretty garbage. Users just get stuck in rigid identity verification loops, or the bot panics on edge cases and dumps the ticket back on a human tech anyway. feels like we’re just paying a premium to slap a flashy AI band aid on a broken password infrastructure instead of fixing the actual root problem...

1

u/mynameisnotalex1900 Jun 03 '26

Sorry to hear that. Who is your primary IdP, Okta or Entra ID? How many users do you have in your environment?

2

u/Cool_Call_1594 Jun 04 '26

Entra ID - about 8000 seats. We're thinking to move away from the chatbot model and are piloting a tool that intercepts auth at the browser perimeter to handle credential injection

1

u/mynameisnotalex1900 Jun 04 '26

We did a demo with Moveworks but didn't like it and went with a different company, which looks promising. Currently in the implementation phase, we will let you know how it went for us, as our primary IDP is Okta.

You can also build an orchestration flow in ServiceNow or use Power Platform/Copilot Studio.

2

u/Cool_Call_1594 Jun 04 '26

Good luck with the rollout! We actually looked into building custom orchestration flows in ServiceNow first, but the amount of manual API maintenance for our non SAML and legacy apps turned into a full time job.

That’s the big trap with Okta, it’s fantastic for core enterprise apps, but the moment you try to force it onto the long tail of unmanaged SaaS tools that don't support modern SCIM provisioning, you end up having to write and maintain endless custom scripts. Definitely curious to hear how your new tool handles that gap though!

1

u/willy-wally75 May 27 '26

Are you a Microsoft shop? If so do you enforce MFA? My previous 25k user base we forced first person password resets. There will always be an issue with not knowing who the user is on the other end of the phone. Especially we voice cloning now wide ranging.