Verify Identity
When a user contacts the service desk, there needs to be a reliable way to confirm that they are who they claim to be. Specops Secure Service Desk helps protect against impersonation and social engineering through stronger identity verification.
Verification takes place in the Verify identity section, where you can select one or more methods that the user has enrolled in. Selecting multiple methods strengthens the verification.
Some verification methods are weaker than others, and a single weak method may not provide enough assurance. When Require more than a single weak factor to verify a user is enabled, verification must include at least one strong method or at least two weak methods.
Verification can also be enforced before sensitive service desk actions. When Enforce identity verification is enabled, the user’s identity must be verified before an agent can perform other actions, such as resetting the user’s password or unlocking their computer. For more information, see Identity verification and security.
Verification Methods
There are two types of verification methods:
- Agent-managed methods
- Browser-link methods
Agent-managed methods
Agent-managed methods are initiated and managed by the service desk agent, and do not require the user to open a browser link. Depending on the method, the user may approve a request in an app, read a code aloud, or provide information that the agent enters.
Browser-link methods
With Browser-link methods, the user completes authentication in their web browser by opening a link sent by the service desk agent. These verification methods are marked with Requires sending a browser link to the user.
If multiple browser-link methods are selected for identity verification, the user receives one single link and completes all authentication steps in the same browser session.
Identity Services that support both methods
Identity services that support both agent-managed and browser-link verification appear as two separate entries in the Verify identity list. The entries are named as follows:
| Method | Name |
|---|---|
| Specops Verified ID |
Note: Both methods are shown when the Specops Verified ID verification method is set to Both. If only one method is enabled, a single Specops Verified ID entry appears. |
| RSA SecurID |
|
| Okta Verify |
|
| Manager Identification |
|
Verify a User's Identity
After locating the user (see Search for a user), do the following:
- Click Verify identity.
- If needed, select the language to use for text messages sent to the user during identity verification.
- Select one or more verification methods and click Start verification.
- Follow the on-screen instructions to initiate verification. If you selected a browser-link method, forward the link to the user.
-
Keep the Verify identity tab open until verification is complete.
The Unverified status appears in the upper-right corner of the Verify identity page until the user’s identity has been verified. The indicator consists of a red Unverified label and a red user icon with a diagonal line through it. After successful verification, the label changes to Verified, and the indicator turns green.
-
After verification is complete, a message confirms that the user’s identity has been successfully verified. You can then perform the service desk actions.
Use Manager Identification
In some situations, communication or data restrictions may prevent users from verifying their own identity. In these cases, the user’s manager can confirm their identity on their behalf.
To enable Manager Identification, see Manager Identification.
To use Manager Identification as a verification method:
- Click Verify Identity.
- Select the Manager Identification verification method and click Start verification.
- The manager (if registered as such in Active Directory) will receive an email asking to verify the user. It is up to the manager (and the user in question) to make sure the correct user is verified (e.g. by calling the user).
- The manager clicks Continue in the Manager Identification email. The manager is redirected to a browser window with the Service Desk verification request.
-
The manager clicks Verify to verify the user.
Warning
It is essential in these types of scenarios that the manager is aware of the Service Desk call, and that they ascertain that it is in fact the user in question who is trying to get verified.
Identity Verification and Security
If the Enforce identity verification setting is enabled, the identity of a user who contacts the service desk must be verified before the agent can perform other actions, such as resetting the user’s password or unlocking their computer, thereby increasing the security of the interaction. Once the identity is verified, the interaction with the Service Desk will rely on the creation of secure session tokens to maintain session integrity.
In a typical service desk session, the service desk agent issues an identification request to the user, using one of the user’s identity services. Once the user has authenticated with the identity service, the secure token is created. This token is shared between the specific service desk agent and the user for the duration of the session. Every interaction (password reset, unlock computer) is validated against this token. For the duration of the session, the token will only work for the service desk agent who initiated the identity verification, to perform action for the user who verified their identity.
Traceability
Besides providing a secure way to authorize actions from the Service Desk, the tokens also allow for the creation of a continuous event log associated with every Service Desk session. This makes every session trackable and searchable. All information regarding the session is accessible through the Reporting menu.