Secure Help Desk Caller Verification with FastPass IVM
Streamline password management, enhance security, and reduce help desk workload with FastPass IVM backed by Duo verification.
The Risk
Your service desk receives calls all day long from users seeking assistance and access. Are all of the calls from real users – or can criminals / hackers exploit this channel?
Any hacker who gets access to internal systems can be a life-threatening experience for any enterprise. An obvious risk is the issuance of passwords from the service desk, but there are other transactions in the service desk where high risks are involved if we don’t know who is on the other end of the phone line.
The Problem
Hackers will use social engineering skills to talk your service desk supporters away from the official process of verification. Only with a forced workflow for password reset and other critical service desk transactions can you prevent skilled hackers from manipulating the supporters to give away your assets and access.
Users with DUO Verification
If you have already invested in DUO, then you can use DUO for end-user verification in new and important security situations:
- Verify end-user identity in the service desk
- Authenticate users in self-service of password reset
Users without DUO Verification
If you have users in special departments or regions without DUO, then these users can verify with other methods in FastPass with single factor or Multi Factor Authentication as you need.
FastPass Users
For the few users who still call the service desk FastPass offers a secure process for user verification at the service desk: FastPass Identity Verification Manager (IVM).
The Solution
When a call is initiated in your ITSM system (ServiceNow or other) then the ITSM system automatically transfers control to FastPass IVM. Now IVM verifies the end-user’s true identity. This is done according to rules set up by you. Only if the criteria are met will IVM grant the rights – be it a new password or any other asset.
The Result is
- A secure verification
- A complete audit logging for compliance review
- All supporters will follow the exact same management decided process – even new supporters will be forced. (the process can differ per user)
- Management can force new and better process instantly
- Improve ROI for your DUO investment
- Prevent social engineering against the service desk and other support functions
Features
Different verification processes for different user groups, and different verifications depending on the network the user accesses from.
Easy integrated to modern ITSM systems
Available for on-premise and from FastPass Cloud
As a benefit, the supporters access to tools to do the functions outside IVM can be reduced. As an example don’t give the supporters privileged access to reset passwords.
How It Works
FastPass, integrated with Duo's API (Auth 2), presents verification options dynamically based on user group and location. Factors include:
- Duo Push
- TOTP
- SMS
- Call back
Flexible Configurations:
Configure verification based on network access (e.g., LAN or remote).
What our customers are saying about us
The biggest businesses in different industries trust FastPassCorp
Implementing FastPass SSPR with Duo integration has been transformative for our organization.
What used to be hundreds of daily password reset requests has now dropped significantly, freeing up our help desk to focus on more critical tasks. The seamless Duo authentication has made it easy for employees to reset their passwords independently, reducing frustration and boosting productivity across teams.
The combination of Duo and FastPass SSPR has dramatically improved our security posture. We no longer worry about social engineering attacks targeting our help desk.
The straightforward self-service process empowers users while ensuring compliance with our stringent security policies. The result is a more secure, efficient, and cost-effective solution that has paid off almost immediately.
Ready to boost productivity and enhance security?
Contact us today for a tailored solution!
Frequently Asked Questions
FastPass IVM is a comprehensive solution designed to enhance security and efficiency at the IT help desk by automating user validation processes and protecting against social engineering attacks.
FastPass IVM leverages advanced authentication techniques and integration with leading ITSM platforms like ServiceNow to verify user identities swiftly and securely. It automates user validation processes, streamlining help desk operations while enhancing security.
: Key features of FastPass IVM include:
- Automated user identification and validation processes
- Protection against social engineering attacks
- Seamless integration with ServiceNow and other ITSM platforms
- Enhanced security through intelligent validation algorithms
Identity Verification Manager (IVM) is primarily used by personnel who require secure identity verification in their roles. This includes Service Desk supporters, who often need to confirm the identity of individuals requesting assistance, particularly when sensitive actions like password resets are involved.
Similarly, staff in HR and Finance departments also benefit from employee identity verification, as it ensures secure verification of employee identities, critical for maintaining confidentiality and security in these sensitive areas. IVM's robust identity verification process is essential in any situation where confirming an individual's identity is crucial to prevent potential security breaches.
IVM elevates security beyond what standard procedures and well-trained staff can offer by systematically controlling the verification process. Even the most competent staff are vulnerable to manipulation by skilled social engineers. IVM mitigates this risk by automating Help Desk Identity Verification and removing the need for staff discretion in the verification process. This ensures a consistent, rigorous approach to verifying identities, significantly reducing the likelihood of security breaches due to human error or manipulation.
The effectiveness of Identity Verification Manager (IVM) lies in its use of Dynamic and Contextual tests, which are challenging for a hacker to circumvent. IVM assesses information from the user’s workstation to determine if the access attempt is from the user’s own PC. It also evaluates factors like geo-location and typical work hours. These multifaceted checks, which evaluate numerous tokens, create a verification environment that is extremely difficult for a hacker to replicate or prepare for, thereby significantly enhancing security against unauthorized access.
Yes.
Yes. However some verification tests are only available when SSPR is implemented.
Yes – but the supporter will not notice it. IVM can be integrated seamless with the ITSM tool, so the supporter will not see or know when the process switches to IVM and back to ITSM.
Using the IVM template it can be done fairly quick. Some organizations will however make their own verification process and even different processes for different groups and then it will take more time. Please see the IVM Implementation guide.
Technical implementation can be done in a day. Using FastPass templates then organizational implementation can be done fast too: Less than a week. When the customer wants to design an individual workflow then the decision process will take time. The technical implementation is relatively short.
With FastPass a POC can be up and running within a day. With additional target systems (SAP/Oracle etc.) expect to add some more days.
IVM integrates based on ticket-number and returns status to ITSM system. Easy integration with most major ITSM systems.
IVM offers versatile data integration options with back-office systems. This includes direct integration with Active Directory (AD), the ability to insert data directly into the FastPass database, and connecting through specific database tables. Additionally, IVM supports API integrations, typically utilizing JSON/REST formats, to facilitate seamless data exchange. This open-system architecture not only allows for easy data importation but also ensures that the data remains encrypted within FastPass, maintaining security and confidentiality.
Yes, within IVM, you have the flexibility to set specific proofing types as mandatory. This feature allows you to enforce certain verification steps as essential, ensuring adherence to your organization’s security protocols.
In cases where full proofing of a user's identity isn't possible, the recommended best practice is to escalate the issue to a supervisor or manager. The supervisor has the ability to employ alternative verification methods, such as contacting the user’s manager or colleagues. They also have the authority to override the score in FastPass, assuming responsibility for the user's verification. This escalation process ensures that verification decisions are made with adequate oversight and accountability.
FastPass utilizes a dedicated agent that is installed on the user's PC. This agent communicates with FastPass, informing it about the specific computer the user is currently logged onto. This mechanism enables FastPass to accurately identify the user's regular computer, enhancing the effectiveness of its security protocols.
: Absolutely, FastPass offers extensive flexibility in configuring its scoring system. You can tailor the rules based on group membership or specific user types. With 28 different scenarios available in the default profile, all of which are customizable, you can adjust the system to your specific needs. For example, if a user who typically connects with a computer fails to do so, this might be flagged as unusual, resulting in a deduction of points, like subtracting 25 points. Conversely, a user who normally doesn't use a computer for connection won't face any point deduction for this behavior.
To ensure the highest security standards, FastPass conducts weekly vulnerability scans, as well as additional scans following any significant changes in the IT environment. This comprehensive scanning includes all production systems, applications, and servers. Upon detecting new vulnerabilities, we classify them based on the severity of impact and the likelihood of exploitation. This systematic approach allows us to effectively manage and mitigate potential risks in our cloud infrastructure.
Yes, FastPass provides the functionality to automatically delete user data and restrict access as needed. This is achieved by FastPass regularly checking the source user repository. User data can be set to be automatically deleted under certain conditions, such as if the user account is deleted or disabled, is no longer a member of a group authorized to use FastPass, or becomes a member of a group specifically designated for deletion. This ensures that user data management aligns with the current status and permissions within the organization. Please note that the users history actions are kept in the Audit log.
Yes, FastPass features a comprehensive and detailed audit log that meticulously records every action. This includes not only user activities but also all operations conducted within the IVM tool and the Admin interface. This extensive logging capability ensures thorough tracking and accountability for all interactions within the FastPass system, providing an essential tool for security and administrative oversight.
All personnel supporting FastPass cloud are as a minimum are BPSS checked and are annually trained on Data Protection and personal data best practice. They are also required to sign NDAs and the Information Security Policy and Data Protection policy. These policies are aligned with ISO 27001 / EU GDPR. Read more about GDPR and Service Desk here: https://www.fastpasscorp.com/why-fastpass/insights/idc-gdpr-password-reset/
FastPass offers versatile integration capabilities with various MFA providers, employing different technologies to ensure seamless and secure authentication. For instance, with Okta, we utilize their API for integration. In other cases, we might use SAML (Security Assertion Markup Language) or RADIUS (Remote Authentication Dial-In User Service) integrations, depending on the specific requirements. This flexibility allows FastPass to adapt to a wide range of MFA systems, enhancing overall security. For detailed information on integrating FastPass with your preferred MFA provider, please contact us.
Absolutely. FastPass prioritizes data security, especially during data transit. One of our fundamental security measures is the mandatory use of SSL (Secure Sockets Layer) certificates for all communications. This ensures that any data exchanged between users and FastPass is encrypted, significantly enhancing security and protecting against data interception or unauthorized access during transmission. For Cloud operation TLS 1.2 is used.
Yes, FastPass ensures that all sensitive data is encrypted when stored in our database. This includes any data at rest within the FastPass system, providing an added layer of security against unauthorized access. For specific details on the types of data that are read, stored, and require write access within Active Directory and Entra ID, we recommend consulting the respective documentation. This information will give you a comprehensive understanding of our data handling practices and the security measures in place to protect your data at all times.
User validation is crucial for ensuring that only authorized users gain access to sensitive information and resources. By verifying user identities, organizations can mitigate the risk of unauthorized access and data breaches.
FastPass IVM employs intelligent validation algorithms to detect and prevent social engineering attacks, such as impersonation or manipulation of help desk agents. It enhances security by automating user validation processes and reducing the risk of human error.
FastPass IVM is designed to seamlessly integrate with leading ITSM platforms like ServiceNow. Our team can work with you to ensure compatibility with your existing IT infrastructure and customize the solution to meet your specific requirements.
Explore our insights and resources on our website to understand how FastPass IVM revolutionizes IT help desk security. You can also contact us to schedule a consultation and learn more about how FastPass IVM can protect your organization against social engineering attacks.
FastPass V4 has been penetration tested by Backbone Security.com Inc. - 811 Ann St. Stroudsburg PA 18360
FastPass's Self-Service PC Client is fully compatible with Windows 10 and Windows 11, while legacy support is available for Windows 7 in older versions of the software. For Bring Your Own Device (BYOD) scenarios and browser use, our client features a responsive design that adapts seamlessly to a wide range of devices, ensuring a smooth user experience across different platforms.
IVM's primary interface for administrators and supporters is in English. However, for user verification purposes, the questions can be translated into various local languages to accommodate the needs of users in different regions. This feature ensures that while the system's core operations are managed in English, the user verification process is accessible and user-friendly across diverse linguistic backgrounds
Notifications can be setup to notify on unusual number of access from individual users having multiple failed attempts.
Has been tested with 100,000+ users.
The FastPass solution is available for on-premise as well as for FastPass Cloud. Service Providers can operate their own multi-tenant cloud solution.
IVM knows what PC the user normally uses and will flag if the user comes from a new device. Location- based information is planned for release in early 2022 it will also learn the user’s normal behavior and use it as a baseline.
With IVM, users don’t have to be enrolled. Enrolling users will however increase the number of verification tests and the quality. Users already being enrolled in an earlier version will immediately be able to benefit from the Enrollment.
Integrating FastPass with an ITSM system streamlines the Service Desk process, offering a seamless transition from the ITSM system to FastPass for users. This integration also enables FastPass to record detailed proofing data directly within ITSM tickets, creating a clear and comprehensive audit trail. Such integration enhances operational efficiency and ensures transparency in identity verification processes.
Yes, IVM's engine is designed with high flexibility, allowing for the customization of score values. This customization can be applied universally for all users or can be tailored based on specific criteria such as the user's group membership or the type of operation being conducted. This flexibility ensures that the identity verification process can be finely tuned to meet the unique security needs and policies of different user groups within an organization.
Absolutely. IVM is equipped to support diverse profiles for each user or Service Desk group. This means that you can customize different proofing options for various Help Desk groups, tailoring the identity verification process to suit the specific requirements or security levels of each group.
Direct connection to FastPass for user verification is not mandatory. The need for users to connect depends on your organization’s policies and the available proofing methods. If multiple secure authentication options are in place, direct user connection may not be essential. Users can choose to connect via a web browser or mobile device, offering versatility to suit different needs. Additionally, connecting directly through FastPass allows users to set their own password, rather than receiving a temporary one over the phone, enhancing both security and user autonomy.
Yes, it is currently possible to verify an IT worker's identity to an end-user using FastPass's IVM backend. When a user connects to IVM, it confirms that the Service Desk account is operated by an authorized user with access to IVM in FastPass. We are also planning to introduce more seamless features in the future to further enhance this verification process.
Absolutely, FastPass is fully compliant with FIPS (Federal Information Security Management) 140-2 standards, starting from version 4.0 onwards. We utilize a 256-bit AES algorithm for encryption and a PBKDF algorithm for hashing. This compliance extends across all FastPass components, from the Windows Client to the Server and Domain Controller parts, ensuring robust security throughout the system.
Indeed, FastPass's cloud operations are proudly certified with Cyber Essentials Plus, affirming our commitment to robust cybersecurity practices.
FastPass offers two secure methods for connecting to Active Directory:
- LDAPS Connection: Utilizes port 636, enabling secure communication over an encrypted channel.
- Standard Ports: Connects using standard ports 389 and 445, offering an alternative method for integration with AD.
These options ensure flexible and secure integration with your Active Directory environment, catering to different network and security configurations.
For optimal operation of FastPass, certain delegated rights in Active Directory are recommended for the privileged account:
- Reset Password: Allows password management.
- Write Permissions: Specifically for 'LockOutTime' and 'PwdLastSet' attributes, enabling effective account management.
- Read-Only Access: Limited to specific fields for general operational needs.
For a comprehensive understanding of these permissions and their setup, we encourage reviewing our 'Delegating Permissions in Active Directory' document for detailed guidance.
To integrate FastPass with Entra ID (Azure AD), you need to create an Enterprise Application. This application facilitates the granting of access rights, ensuring FastPass has permissions only to the necessary data fields. This approach helps maintain data security by limiting access strictly to the required information for effective operation.
Yes, FastPass IVM is designed for global accessibility, allowing users to connect from anywhere on the internet. We strongly recommend using MFA while logging in. We prioritize security and offer a range of customizable access options. These include setting FastPass IVM as an internal-only tool or restricting access to specific countries or through the client. We are committed to helping you find the ideal balance between ease of access and robust authentication methods. Contact us to have a discussion on the options at hand.
FastPass ensures regular updates for optimal performance and security. For the server components, such as the SSPR backend and IVM, we typically release a major version upgrade once a year. Additionally, we provide 2-3 smaller updates annually, focusing on introducing new features and addressing bug fixes. It's important to note that the Windows Client, along with the Password Interceptor and Filter components, are designed to be backward compatible with the latest two major versions. This compatibility feature offers flexibility and ease during the upgrade process, ensuring a smooth transition for users and IT administrators.
FastPass adopts a version-based approach for our End-of-Life policy, focusing on Major and Minor releases. We offer support for the current Major release and the last officially released Major version. For instance, as of now, we support versions 3.6 and 4.0. This means that if you encounter any issues with version 3.6, our support team will assist you, including making necessary fixes to facilitate upgrades. However, we do not provide the same level of support for versions that are two Major releases behind the current one. To ensure continuous support, we recommend upgrading at least once every year, aligning with our Major version release cycle.
Protect your Passwords today with FastPass
Get in touch with us today by filling up the form and our team will get back to you as soon as possible.