ServiceDeskSimulator
AI coaching on Start

Knowledge base

Verifying a caller's identity

Reference: Contoso IT security standard SEC-04 · NCSC guidance on service desk verification

← All articles
securitysopidentitysocial-engineering

Before you change anything about an account — password, MFA registration, group

membership, mailbox access, contact details — you must know you are talking to the

account holder.

This is not bureaucracy. Service desks are the softest route into an organisation

precisely because they exist to be helpful under pressure.

What does not count as verification

What does count

Pick at least one, and record which you used:

the caller is not asking you to change.

Raise the bar with the risk

RequestMinimum
Read-only lookup, no changeBasic sanity check
Password resetOne independent verification
MFA reset or method removalOne independent verification, recorded
Mailbox access grant, forwarding, delegateIndependent verification plus the mailbox owner's consent
Anything for a finance, executive, or privileged accountTwo independent verifications

Red flags to escalate rather than serve

None of these prove an attack. Together with pressure, they are enough to stop and

ask someone.

Recording it

Write in the ticket how you verified, not that you did. "Verified" is not an

audit trail; "called back on the directory number, spoke to the user, confirmed

device serial" is.

Related