Why Zero Trust Must Start Before Day One: Stopping Identity Fraud During Onboarding
Zero Trust principles are now commonplace in enterprise infrastructure. Organizations have spent years investing in controls that protect identities and systems from increasingly sophisticated attacks.
However, human error can still be exploited, especially when trust is established manually. Employee onboarding and service desk processes are natural pressure points because agents may need to make high-impact access decisions with limited context. An attacker only needs to convince one person that they are who they claim to be.
Established users can often be verified through registered authentication factors, trusted devices, and other security controls. New hires typically do not have those verification methods configured yet, even though organizations still need to establish trust. If the initial identity check is weak, subsequent controls cannot correct the mistake.
Organizations therefore need a reliable way to verify identities and close the gap attackers are increasingly targeting.
The identity fraud problem
The FBI has repeatedly warned that North Korean IT workers are using stolen or fraudulent identities to secure remote jobs or access corporate networks. In some cases, individuals may use fake identification, proxy infrastructure, or U.S.-based intermediaries to appear to be legitimate applicants.
This inverts the usual identity security model. Traditional intrusion techniques often involve attackers stealing employee credentials and using them to gain access. In an onboarding attack, the attacker moves through the recruitment process and the organization creates credentials for them.
The FBI’s guidance on North Korean IT workers highlights the persistent nature of this threat and the importance of identity verification during the hiring process and throughout the employment of remote workers.
The broader lesson is that organizations need to apply the same level of scrutiny to identity creation as they do to authenticating existing identities.
Strong MFA has a weakness: credential registration
Once a new employee passes onboarding, the service desk is often heavily involved in setting up their access. Agents may activate accounts, issue initial credentials, enroll multifactor authentication (MFA), register passkeys or security keys, and configure corporate devices.
If the wrong person reaches this stage, strong authentication will not fix the mistake. An attacker could receive an account protected by MFA and linked to a trusted device, with both issued through legitimate organizational processes.
Users are especially vulnerable during this credential-bootstrapping stage, when they may still rely on weak authentication before phishing-resistant credentials are registered. An attacker who compromises this window could disrupt registration and establish lasting access before stronger controls are fully implemented.
Verizon’s data breach investigation report found that 44.7% of breaches involved stolen credentials.
Easily protect your Active Directory with compliant password policies, block over 4 billion leaked passwords, improve security, and dramatically reduce support effort.
Day One requires its own identity verification layer
Authentication asks whether someone can prove control of the credentials linked to an account. Identity verification asks whether the person in front of the organization is the individual to whom it is granting that account.
For existing employees, trusted factors such as registered authenticators and devices can provide sufficient assurance for many service desk requests. New employees may not yet have corporate devices or established authentication factors that the organization can trust.
This means Day One requires its own validation process, particularly when users are about to receive access to sensitive systems or register credentials that will represent them in the future.
Strong forms of identification, such as validating government-issued identification and combining it with biometric liveness detection, can provide assurance even when existing authentication factors are unavailable. This helps organizations establish trust in individuals before initiating access.
Make identity verification part of the onboarding workflow
A solution such as Specops Secure Onboarding applies this principle by making identity verification a required step in the onboarding process instead of leaving service desk agents to make case-by-case decisions.
Onboarding is typically the first point where trust is established. If identity is not verified properly at that stage, every subsequent control may be built on the wrong foundation.
Specops Secure Onboarding combines the scanning and verification of government-issued documents with biometric liveness detection for new employees. This gives organizations greater assurance that the person being onboarded is who they claim to be before credentials, MFA methods, devices, or application access are issued.
The same principle continues after onboarding. When an employee later contacts the service desk for assistance, Specops Secure Onboarding requires the agent to verify the employee’s identity using a trusted authentication factor before proceeding.
This removes much of the guesswork from the process. Agents do not have to decide whether a caller sounds persuasive or whether the information provided is sufficient. Instead, identity validation becomes part of the workflow itself.
Zero Trust must start before the first login
Organizations have become much better at authenticating users after they enter the environment. The next step is applying the same thinking to the moments when identities are created and access is first granted.
New employees should not be trusted simply because an onboarding email reached the right inbox or a service desk agent was convinced by a caller. Identity should be established before credentials and access are issued, then verified again when sensitive support requests occur.
To strengthen identity verification across your onboarding and service desk processes, book a demo with Specops to learn how its solutions can help.
Sponsored and written by Specops Software.
Source: www.bleepingcomputer.com


