Zero Trust systems can verify established users through credentials and other authentication methods. But onboarding creates a gap: a new employee may not yet have a trusted device or enrolled authentication factor, while the organization still needs to decide who should receive access.
That gap matters because a weak initial identity check cannot be fixed by stronger controls issued afterward. During onboarding, service desk staff may activate accounts, issue initial credentials, enroll multi-factor authentication (MFA), register passkeys or security keys, and configure company devices. If an impostor passes the initial check, those normal steps can give the wrong person an account protected by MFA and linked to a trusted device.
The FBI has warned that North Korean IT workers use stolen or fraudulent identities to obtain remote jobs and access corporate networks. The source says the FBI recommends verifying remote workers’ identities during hiring and throughout their employment. It describes tactics including false identity documents, proxy infrastructure, and US-based facilitators.
Verizon’s Data Breach Investigation Report found that stolen credentials were involved in 44.7% of breaches. The article distinguishes identity proofing—checking whether someone is the person an organization intends to onboard—from authentication, which checks control of a credential already linked to an account.
Specops Secure Onboarding is presented as one approach. For new hires, it combines government-issued identity document scanning and validation with biometric liveness detection before credentials, MFA methods, devices, or application access are issued. It also requires trusted authentication factors for identity checks during later service desk requests.
Comments
0No comments yet. Be the first to comment.