Before you change anything about an account — password, MFA registration, group
membership, mailbox access, contact details — you must know you are talking to the
account holder.
This is not bureaucracy. Service desks are the softest route into an organisation
precisely because they exist to be helpful under pressure.
What does not count as verification
- The caller knows the user's name, job title, or manager. All public.
- The caller is calling from a number that displays as internal. Caller ID is trivially spoofed.
- The caller emails from the account. If the account is compromised, so is the email.
- The caller sounds senior and is annoyed. That is a technique, not a credential.
- The caller knows their own employee number. Often printed on things.
What does count
Pick at least one, and record which you used:
- Callback to the number held in the directory, not a number the caller supplies.
- Manager confirmation through a separately initiated channel.
- A verified identity workflow — a code delivered to an already-registered method
the caller is not asking you to change.
- In person, with a pass.
- Video call with a known face, for a user you or a colleague can recognise.
Raise the bar with the risk
| Request | Minimum |
|---|---|
| Read-only lookup, no change | Basic sanity check |
| Password reset | One independent verification |
| MFA reset or method removal | One independent verification, recorded |
| Mailbox access grant, forwarding, delegate | Independent verification plus the mailbox owner's consent |
| Anything for a finance, executive, or privileged account | Two independent verifications |
Red flags to escalate rather than serve
- Urgency combined with a reason you cannot check ("I'm about to board").
- A request to remove or change the only remaining authentication method.
- Requests to add a forwarding address, delegate, or mailbox rule.
- A request that the confirmation be sent somewhere other than the registered method.
- Reluctance to accept a callback.
- Any request touching payment details, bank details, or supplier records.
None of these prove an attack. Together with pressure, they are enough to stop and
ask someone.
Recording it
Write in the ticket how you verified, not that you did. "Verified" is not an
audit trail; "called back on the directory number, spoke to the user, confirmed
device serial" is.
Related
- Reset a user's MFA registration
- Responding to a compromised account
- Triaging a reported phishing message