Skip to main content

Verify Caller Identity

You don't want to reset passwords or unlock accounts for bad actors pretending to be your customer. Use ZeroTek's Verify Caller Identity feature to ensure the person calling and asking for assistance is who they say they are, especially before you perform security-sensitive actions like resetting passwords or authenticators.

Verify Caller Identity uses the Okta Verify authenticator app to issue a multifactor authentication (MFA) challenge to a user's phone, then indicates whether the challenge was met with success or failure.

Both the action of issuing the challenge and the outcome are logged and viewable in ZeroTek Audit logs.

If ZeroTek Admins have configured Fail-Safe Options, all ZeroTek users will be required to verify the identity of a caller before proceeding with security-sensitive user management actions.

ROLE REQUIRED

ZeroTek Administrator
ZeroTek Technician
ZeroTek Technician without Deep Linking
ZeroTek Help Desk (limited user actions)

Requirements

The caller/user must have the Okta Verify app installed and enrolled as an authenticator on a device in their possession.

Okta Verify with push notifications must also be enabled in the user's Okta org. (By default, Okta Verify with push is enabled in all new Okta orgs.)

Verify the identity of a caller

  1. In ZeroTek, navigate to the caller's Okta account either from the Users area or by using the global User Search in the upper right corner of the ZeroTek app.

  2. With the user's details page open, select the Authenticators tab.

  3. If the requirements listed above have been met, you will see an Authenticator Type called Push, with the Provider listed as Okta:

  4. Click Verify Caller Identity in the top row.

  5. Depending on whether ZeroTek Admins have configured Fail-Safe Options, you may be required to enter the ID of the help desk ticked you are working off in the Ticket ID field. Select the device to authenticate against from the Enrolled Device list.

  6. Click Verify Caller Identity. ZeroTek checks for the results of the push challenge. You can also click Check Outcome to refresh the screen.

  7. When the user you are trying to verify correctly responds to the push challenge, the screen displays a "Success" message. Click Close to exit.

View the history of past challenges

  1. In ZeroTek, navigate to ZeroTek Audit.

  2. Authenticator challenge requests appear with a "Verified Caller Identity" message.

  3. Expand the audit event to see the outcome of the challenge.

  4. Filter results by typing a ticket ID in the Ticket ID field and/or specifying a date filter (last 24 hours, last 7/30 days, or a custom date range).

Did this answer your question?