Two-way caller verification

Know who's calling.
Before you act.

IT callers prove who they are. Employees can ask for verification.
Verify a support caller or colleague using the identity providers and enrolled factors your organization already manages.

See caller verification happen Automatic illustration · IT-initiated request

01 Send the request

IT support · Fctr Portal “Hi, I'm calling from IT.”

Support signs in to Fctr Portal, which generates a random phrase.

✓ Request sent
Read this phrase to the employeeBlue harbor

Also available through a supported integration, such as ServiceNow.

02 Select the matching phrase

Employee · Fctr Verify Match what the caller says
Silver meadow
Blue harbor
Amber forest
Matching phrase submitted

The employee opens Fctr in Teams or Outlook and selects the phrase the caller says.

03 See the verified result

Employee · Fctr Verify
Caller verified

Verification complete. The employee sees the result in Fctr.

The employee waits for Verification complete before continuing the conversation.

Illustrative sequence. No real verification request is sent.

Your existing factorsNo new factor enrollments.

  • Entra ID
  • Okta
  • Cisco Duowith Entra ID

The workflows, step by step

Two ways to start an IT-caller check.

Support can start a phrase request, or an employee can ask a caller or colleague to verify. Here is how each path works.

IT support initiated

Support starts the request.

Caller says it. Employee selects it.
  1. 1. Support creates a request.

    The caller meets your organization's verification policy and starts in Fctr Portal or a supported integration, such as ServiceNow.

  2. 2. The employee opens Fctr.

    Independently open Fctr Verify in Teams or Outlook. Choose Check pending requests and review the caller details and reason.

  3. 3. Match the caller's phrase.

    Select the phrase the caller says, submit, and wait for Verification complete.

    Never read the choices aloud. If nothing matches or you're not on a call, choose None of these / Not on a call, then End request.

Phrase selection confirms the interaction; it is not a new MFA challenge for the employee.

Employee initiated

The employee asks for proof.

Caller verifies. Employee checks the result.
  1. 1. Find the claimed caller.

    Independently open Fctr Verify in Teams or Outlook. Choose Request verification, search by name or work email, and send the request to the matching person.

  2. 2. The caller verifies.

    The selected person opens Fctr, checks pending requests, and chooses Verify yourself. They complete verification using their enrolled, organization-managed factors.

  3. 3. Check the result.

    The employee checks the result in Fctr and waits for successful verification before continuing.

    If the caller is not verified, end the call and contact the person using details you already trust.

Available where employee-initiated verification is enabled. Both people use the organization's configured Fctr app.

Fits your identity setup

Existing factors. Familiar tools.

Entra ID Okta Cisco Duo for Entra ID
  • Passkeys
  • Microsoft Authenticator
  • Okta Verify
  • Duo MFA
  • TOTP

Available methods depend on provider, policy, and verification direction. Verified ID + Face Check is also supported for employee verification where configured.

Helpdesk verification

Verify employees calling your helpdesk.

Two-way verification also covers employees calling the helpdesk. In Fctr Portal, the agent finds the employee, verifies them with a supported enrolled factor, and takes only actions their role and policy allow.

  • Live identity context
  • Policy-authorized actions
  • PII-masked evidence
  • No standing IdP admin role for supported workflows
Explore Fctr Portal

Why both directions matter

Attackers impersonate both sides of support.

Fake IT → employeeMicrosoft Incident Response · DART

A support call can grant initial access.

Microsoft Incident Response documented persistent Teams vishing in which an attacker impersonated IT support. A targeted employee ultimately granted Quick Assist access, enabling the initial compromise of a corporate device.

Read the Microsoft case
Employee → helpdeskMandiant · M-Trends 2026

Helpdesks are a path around MFA.

Mandiant reports that highly interactive voice phishing reached 11% of observed intrusions in 2025, making it the second-most common initial infection vector. Its research specifically describes attackers targeting IT helpdesks to bypass MFA and reach SaaS environments.

Read M-Trends 2026

Common questions

Two-way verification, clearly.

Do we need Fctr Portal to verify IT callers?

No. With Fctr Verify, support can initiate supported caller-verification workflows through a customer-deployed integration such as ServiceNow while employees use Fctr in Teams or Outlook. Where enabled, employees can also request another person's verification directly in the app. Fctr Portal adds a helpdesk workspace for live identity context, verification, policy-authorized actions, and audit evidence.

What is reverse caller verification?

It lets an employee verify a caller claiming to be IT or support before the employee follows instructions or continues a sensitive support interaction.

How can employees verify someone claiming to be IT?

The IT caller starts a request in Fctr Portal or a supported integration under the organization's verification policy. Independently open Fctr Verify in Teams or Outlook and choose Check pending requests. Review the caller details and reason, then select and submit the phrase the caller says. Wait for Verification complete. If the caller is not verified, end the call. Do not read the choices aloud. If none matches or you are not on a call, choose None of these / Not on a call, then End request. Do not rely on a link supplied only by the caller.

Can an employee start the verification?

Yes, where employee-initiated verification is enabled. Independently open Fctr Verify in Teams or Outlook, choose Request verification, search for the claimed caller by name or work email, and send the request to the matching person. That person opens Fctr, checks pending requests, and chooses Verify yourself to complete verification using their enrolled, organization-managed factors. Check the result in Fctr before continuing. If the caller is not verified, end the call and contact the person using details you already trust. Successful verification does not authorize a support action.

Is reverse verification the same as two-way verification?

Two-way, or bidirectional, caller verification covers both directions: helpdesks verify employees, and employees verify IT or support callers. Reverse caller verification is the employee-verifies-IT direction.

Who completes the challenge?

The IT caller must meet the organization's factor-verification policy before creating a caller-verification request. The employee's phrase selection records their confirmation, not a fresh MFA challenge for that employee. For employee-initiated requests, the selected caller verifies using their enrolled, organization-managed factors. When an employee calls the helpdesk for account assistance, the employee completes the supported verification required for that workflow.

How does Fctr help protect against AI voice cloning and deepfake callers?

Fctr helps protect against AI voice phishing and deepfake impersonation by using supported organization-managed verification rather than voice or appearance. Helpdesks verify employees, and employees can verify callers claiming to be IT. Available methods depend on the provider, policy, and verification direction. Fctr does not analyze audio or video to detect deepfakes.

What if caller verification fails or is incomplete?

If verification fails or remains incomplete, do not treat the caller as verified. End the call and contact the person or support using details you already trust.

What happens after verification?

The result returns to the active support workflow. A matching phrase does not authorize a password reset, enrollment, or other support action. Those actions require their own verification, role, and policy checks.

Do employees need another authenticator?

No. Fctr uses supported factors already managed through Microsoft Entra ID or Okta, including Cisco Duo MFA for Entra ID.

Reverse + two-way caller verification

See caller verification in your support workflow.

Walk through both initiation paths and the Portal controls with your identity platform in mind.

Request a demo.

Tailor the demo Optional

Used only for this request. Privacy policy.