Do we need Fctr Portal to verify IT callers?
No. With Fctr Verify, support can initiate supported caller-verification workflows through a customer-deployed integration such as ServiceNow while employees use Fctr in Teams or Outlook. Where enabled, employees can also request another person's verification directly in the app. Fctr Portal adds a helpdesk workspace for live identity context, verification, policy-authorized actions, and audit evidence.
What is reverse caller verification?
It lets an employee verify a caller claiming to be IT or support before the employee follows instructions or continues a sensitive support interaction.
How can employees verify someone claiming to be IT?
The IT caller starts a request in Fctr Portal or a supported integration under the organization's verification policy. Independently open Fctr Verify in Teams or Outlook and choose Check pending requests. Review the caller details and reason, then select and submit the phrase the caller says. Wait for Verification complete. If the caller is not verified, end the call. Do not read the choices aloud. If none matches or you are not on a call, choose None of these / Not on a call, then End request. Do not rely on a link supplied only by the caller.
Can an employee start the verification?
Yes, where employee-initiated verification is enabled. Independently open Fctr Verify in Teams or Outlook, choose Request verification, search for the claimed caller by name or work email, and send the request to the matching person. That person opens Fctr, checks pending requests, and chooses Verify yourself to complete verification using their enrolled, organization-managed factors. Check the result in Fctr before continuing. If the caller is not verified, end the call and contact the person using details you already trust. Successful verification does not authorize a support action.
Is reverse verification the same as two-way verification?
Two-way, or bidirectional, caller verification covers both directions: helpdesks verify employees, and employees verify IT or support callers. Reverse caller verification is the employee-verifies-IT direction.
Who completes the challenge?
The IT caller must meet the organization's factor-verification policy before creating a caller-verification request. The employee's phrase selection records their confirmation, not a fresh MFA challenge for that employee. For employee-initiated requests, the selected caller verifies using their enrolled, organization-managed factors. When an employee calls the helpdesk for account assistance, the employee completes the supported verification required for that workflow.
How does Fctr help protect against AI voice cloning and deepfake callers?
Fctr helps protect against AI voice phishing and deepfake impersonation by using supported organization-managed verification rather than voice or appearance. Helpdesks verify employees, and employees can verify callers claiming to be IT. Available methods depend on the provider, policy, and verification direction. Fctr does not analyze audio or video to detect deepfakes.
What if caller verification fails or is incomplete?
If verification fails or remains incomplete, do not treat the caller as verified. End the call and contact the person or support using details you already trust.
What happens after verification?
The result returns to the active support workflow. A matching phrase does not authorize a password reset, enrollment, or other support action. Those actions require their own verification, role, and policy checks.
Do employees need another authenticator?
No. Fctr uses supported factors already managed through Microsoft Entra ID or Okta, including Cisco Duo MFA for Entra ID.