Connect it yourselfHow do we verify the person behind a privileged access change?
Privileged access verification
Help-desk social engineering works because the reset path trusts a voice. Put a presence check in front of the reset, the grant and the enrollment — before the change applies.
A check inside the identity flow
The Okta connector calls Presence inline on a sensitive identity change — a reset, a privilege grant, a factor enrollment — and acts on the verdict before the change applies.
Because the check is bound to the specific action, an approval obtained for a benign change cannot be reused for a privileged one.
Check it yourself
The artifacts behind this page
- Okta surface and its readiness./surfaces/okta →