惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
量子位
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
Y
Y Combinator Blog
Vercel News
Vercel News
云风的 BLOG
云风的 BLOG
宝玉的分享
宝玉的分享
Engineering at Meta
Engineering at Meta
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
Microsoft Security Blog
Microsoft Security Blog
B
Blog
Last Week in AI
Last Week in AI
有赞技术团队
有赞技术团队
博客园 - 聂微东
腾讯CDC
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks

Okta Security RSS Feed

Hunting Vulnerabilities Using Frontier Models HTTP/2 Crash: A Denial of Service (DoS) in HTTP/2 Flow Control OpenSSL HollowByte: A DoS Hiding in 11 Bytes Datadog and Okta Combine for New Customer Detections Detecting OpenClaw at Sign-In Okta Hardening Guide Updated to Secure Non-Human Identities Okta Pooled Security Audits: a One-Year Retrospective Account Recovery, without Password Resets Okta’s Response to React2Shell Uncloaking VoidProxy: a Novel and Evasive Phishing-as-a-Service Framework Attackers Target Hotelier Accounts in Malvertising and Phishing Campaign Using Auth0 Logs for Proactive Threat Detection Controlling Cross-App Data Sprawl in Google Workspace How this ClickFix campaign leads to Redline Stealer Paving the Path: Pooled Audits with Okta Security Enabling ISO/IEC 27001:2022 Compliance with Okta Okta’s Secure by Design Pledge - One Year On Leveraging Okta System Logs for Proactive Threat Detection Enhancing Customer Trust Through a Comprehensive Audit Program Okta's new Security Technical Implementation Guide (STIG) A Guide to DORA Compliance with Okta How AI services power the DPRK’s IT contracting scams Detect and Prevent Cross Device Authentication How Responsible Disclosures are Shaping a Safer Cyberspace Cybersecurity’s Next Gen Next.js CVE-2025-29927 CSO Conversations: Matthew Hansen, Regional CSO of Americas West Empowering Security with Customer Trust Solutions Putting Security First with Secure Development One trick finds the root of any Okta troubles
Building Confidence in Support Comms with Caller Verify a...
Carmen Girardin · 2025-06-18 · via Okta Security RSS Feed

In many of the most impactful incidents of the past two years, attackers gained privileged access to systems by tricking IT support personnel into resetting the passwords and MFA factors of system administrators.

Armed with access to privileged accounts, attackers were able to expand their access further by accessing directories of hashed passwords (NTDS.dit) stored in every Microsoft Active Directory environment. 

In most organizations, the challenge is how to validate the identity of callers to internal help desks or other technical teams before performing user lifecycle events. The days when the name of your childhood best friend or your first car model provided enough assurance to validate your identity are long gone.

So, when an employee does call for help, how do technical support personnel validate with confidence that the caller on the line is who they say they are? These processes need to be revisited, especially given recent advances in “deepfake” technology.

That’s where Caller Verify can help.

What is Caller Verify?

Caller Verify is an application that enables IT support to extend the multi-factor authentication prompts available via Okta Verify to quickly and securely verify the identity of inbound callers. 

Caller Verify is a third-party developed application awarded Okta’s "2024 AMER Rising Star Partner of the Year” winner. It can integrate with ITSM and CRM solutions, such as ServiceNow or Salesforce, to require that all inbound callers satisfy an MFA challenge before a support ticket is unlocked for use.

Caller Verify is compliant with the following regulations:

This solution allows Okta IT admins to enhance our employee experience with a timely response to confident, authenticated communications. By sending a prompt to the caller using Okta Verify, the technical support team can validate the caller’s identity before providing any level of assistance, protecting both the organization and the user.

Okta’s Use Case

Okta integrated Caller Verify into various IT support processes well over 12 months ago. Our use of Caller Verify ensures that only authorized employees can ask IT support to perform sensitive operations that involve an Okta account.

In line with Okta’s ongoing commitment to hardening our corporate infrastructure, Okta requires that users satisfy all authentication challenges using phishing-resistant authentication methods (such as FastPass with an Okta Verify-enrolled device, or a registered Yubikey), including the challenges required to open a support request.

Stay secure

Caller Verify plays an important role in Okta’s end-to-end ability to protect all enrollment, authentication and recovery flows with phishing-resistant authentication. 

To learn about Okta’s use of ID Verification to secure enrollment and recovery, read on for how we leverage Okta’s integration with Persona.

Carmen Girardin is a Manager, Security Communications at Okta. Backed by over a decade of experience in the fintech sector, Carmen is a proficient technical writer with domain expertise in Identity and Access Management (IAM). She is passionate about delivering engaging, timely customer communications on the cybersecurity ecosystem and the evolving threat landscape, to help our customers gain the most value from Okta. Carmen spends her downtime traveling, thrifting for treasures and reading.