- Owner
- IT Security Manager
- Effective date
- September 15, 2026
- Review cycle
- Every 6 months
1.Purpose
To verify a requester's identity before any password reset or account unlock, and to restore access securely without exposing the organization to social engineering or unauthorized account takeover.
2.Scope
Applies to self-service and help-desk assisted password resets and account unlocks for employee accounts in the identity provider and connected applications. New account creation and privileged administrator credential resets are covered by other procedures.
Definitions
- Identity verification
- Confirming a requester is who they claim to be before making any change to their account.
- Social engineering
- An attempt to manipulate a person into bypassing security controls, such as urgent or impersonation-based reset requests.
- MFA re-enrollment
- Registering a new device or method for multi-factor authentication after a lost or replaced device.
- Account lockout
- A security control that disables sign-in after repeated failed login attempts.
3.Responsibilities
- Service Desk Analyst
- Verifies identity, logs the request and delivers the new credential securely.
- System Administrator
- Reviews sign-in activity, performs the reset or unlock, and manages MFA re-enrollment.
- End User
- Requests the reset, completes identity verification and confirms successful login.
RACI matrix
| Activity | Service Desk Analyst | System Administrator | End User |
|---|---|---|---|
| Receive and verify the reset request | R/A | I | C |
| Check sign-in activity for suspicious behavior | C | R/A | I |
| Reset the password or unlock the account | C | R/A | I |
| Confirm login and close the ticket | R/A | I | C |
R = Responsible, A = Accountable, C = Consulted, I = Informed
4.Materials and PPE
Materials, tools and systems
- โIdentity provider admin console
- โTicketing system
- โIdentity verification checklist
- โMFA management tool
- โPassword complexity policy reference
5.Procedure
- 5.1
Receive the reset request
Service Desk AnalystThe Service Desk Analyst logs a ticket noting the request channel, whether self-service portal, phone or chat, and the stated reason for the reset or unlock.
- 5.2
Verify the requester's identity
Service Desk AnalystThe Service Desk Analyst verifies identity using an approved method, such as a callback to the number on file, security questions, or manager confirmation, before touching the account.
Checkpoint: No account change is made until identity is positively verified, regardless of how urgent the request sounds.
Warning: Watch for social engineering: urgency, impersonating an executive, or refusing standard verification are all red flags.
- 5.3
Confirm account details match
Service Desk AnalystThe Service Desk Analyst confirms the account, department and manager on the request match the identity provider record exactly.
- 5.4
Review sign-in activity
System AdministratorThe System Administrator reviews recent sign-in and audit logs for the account to check for suspicious activity or an unusual lockout reason before proceeding.
Checkpoint: Requests tied to suspicious sign-in activity are escalated to security before any reset is performed.
- 5.5
Reset the password or unlock the account
System AdministratorThe System Administrator resets the password or unlocks the account in the identity provider, setting the account to require a password change at next login.
- 5.6
Confirm password policy is enforced
System AdministratorThe System Administrator confirms the identity provider applies the standard password complexity policy to the new temporary password.
- 5.7
Handle MFA re-enrollment if needed
System AdministratorIf the request involves a lost or replaced device, the System Administrator re-enrolls MFA only after completing an additional layer of verification beyond the standard reset check.
Warning: MFA re-enrollment is higher risk than a password reset alone and requires stronger verification before proceeding.
- 5.8
Deliver the temporary credential securely
Service Desk AnalystThe Service Desk Analyst delivers the temporary password through a channel separate from the one used to make the request, such as a phone call after a portal request.
- 5.9
Confirm successful login
Service Desk AnalystThe Service Desk Analyst confirms with the end user that they logged in successfully and completed the required password change.
Checkpoint: The ticket is not closed until the user confirms they can sign in.
- 5.10
Log the verification method used
Service Desk AnalystThe Service Desk Analyst records which verification method was used and any notes on the reason for the reset in the ticket.
- 5.11
Close the ticket
Service Desk AnalystThe Service Desk Analyst closes the ticket once login is confirmed and documentation is complete.
6.Quality checks
- โEvery reset ticket records which identity verification method was used.
- โNo password is reset or account unlocked without positive identity verification.
- โMFA re-enrollment requests go through the additional verification step before completion.
- โReset requests tied to suspicious sign-in activity are escalated to security before completion.
7.Records
- โPassword reset ticket with verification method noted
- โSign-in log excerpt for escalated or suspicious cases
- โMFA re-enrollment confirmation
8.KPIs
- โAverage time to complete a verified reset
- โPercentage of resets completed through self-service
- โNumber of resets escalated for suspicious activity
9.Common mistakes
- โResetting a password from an emailed request without verifying the sender out of band.
- โSkipping the sign-in activity check before resetting a locked account.
- โSending the username and the new temporary password in the same message.
- โNot requiring a password change at the next login after a reset.
10.Revision history
| Revision | Date | Description | Reviewed by |
|---|---|---|---|
| 1.0 | September 15, 2026 | Initial release | Ilia Pirozhenko |
This is a template. Adapt it to your organization, equipment and local regulations before use.