Skip to main content
Identity verification

Identity verification

Identity Verification proves who is on the phone before a technician acts on a request; this page explains the two methods, who can use them and how the management screen is laid out.

Written By Chris Scaminaci

Last updated About 2 hours ago

Identity Verification proves who is on the phone before a technician acts on what they ask for. Administrators use the management screen described here to set it up, bring clients on board and review the results. Technicians use a panel on the ticket during the call, which Verifying a caller covers.

Before you start: the Identity Verification module must be on in Module Management, and you need the Administrator or Identity Verification Admin role.

The Identity Verification management screen with its status banner, four totals and five tabs
The management screen with the Credentials tab open

Choose how callers are proven

QuantumOps offers two methods. You pick one for your organisation during setup, and each client can use the other.

MethodWhat the caller doesWhat it needs
Authenticator step-upCompletes a sign-in on their own phone and approves the prompt in Microsoft Authenticator.An app registration in your own Microsoft Entra tenant, and a one-time consent from each client's Microsoft administrator. Nothing to issue to users beforehand. The caller must have Microsoft Authenticator registered in their own organisation.
Microsoft Entra Verified IDShows a digital credential that you issued to them in advance. Face Check can add a facial match.Microsoft Entra Verified ID set up in your tenant and a credential for every user before they call. Issuance campaigns issue credentials in bulk.

The setup wizard marks Authenticator step-up as Recommended: it works on every Microsoft 365 plan and needs no rollout to users.

Set the assurance floor

Each client has a minimum assurance level. Your organisation-wide level is set in the wizard, and a client can override it (Clients and per-client policy).

LevelWhat reaches it
BasicAny multi-factor sign-in, including SMS and voice. Choose it deliberately, because those factors can be defeated by a SIM swap.
SubstantialAuthenticator step-up, or Verified ID without Face Check. This is the default.
HighVerified ID with Face Check.

A verification that resolves below the floor is refused, never quietly downgraded. Where it can be raised, it is: a Verified ID check below a High floor is raised by turning Face Check on, when Face Check is switched on for your organisation. Otherwise the technician is told that no method reaches the level, and the way forward is the recorded supervised override described in Verifying a caller.

Who can do what

TaskRoles
Open the management screen, run setup, onboard clients, change client policy, send campaignsAdministrator, Identity Verification Admin
Verify a caller, issue a credential, record a supervised override (Issuing credentials and supervised overrides)The roles above, plus Service Desk Manager, Dispatcher and Technician
Switch the module on in Module ManagementAdministrator

Accounts with the WhiteLabelPartner role are excluded from both groups of Identity Verification pages, even when they also hold one of the roles above. Assign roles in Team Management.

Turn it on and open it

  1. An administrator opens Module Management and switches the Identity Verification module on. The module's details panel, shown when you hover over its card, also has Run preflight, which runs the same health checks as the last step of setup, and Open Module, which takes you to the management screen.
  2. The Identity Verification link appears in the sidebar under Analytics & Reporting once the module is on and an active configuration exists. It shows only for the two administrator roles. Until then, use Open Module or go to /admin/identity-verification.

/settings/identity-verification opens the same screen. Every address in this section also answers with verifiedid in place of identity-verification, for example /admin/verifiedid, so old bookmarks, HaloPSA ticket notes and e-mails keep working.

Read the management screen

When Identity Verification is not set up yet, the screen shows Identity Verification Not Configured and a Set Up Identity Verification button that opens the setup wizard.

A Verified ID configuration whose credential contract was never created shows Setup Incomplete. Choose Complete Setup to return to the wizard. Reset deactivates the configuration after you confirm: your client settings, credentials and verification log stay in place, the wizard opens with your current values filled in, and finishing it reactivates the same configuration.

Once set up, the screen shows a status banner, four totals and five tabs.

  • Identity Verification Active is the status banner. Its switch pauses Identity Verification for your whole organisation (Identity Verification Paused). A paused installation shows as not configured the next time the screen opens, and you bring it back by going through Set Up Identity Verification again, which opens with your values filled in. While it is paused the sidebar link disappears, technicians are not offered the verification panel for any client, and a client administrator who opens a consent link sees that Identity Verification is not configured.
  • Help starts a guided tour of the screen, or of the Credentials, Verification Log or Configuration tab when one of those is open. Refresh reloads the data. Campaigns opens issuance campaigns. Onboard Clients opens Client Onboarding.
TotalWhat it counts
Total CredentialsEvery Verified ID credential issued for your organisation.
Active CredentialsCredentials that are active and not past their expiry date.
Successful VerificationsVerifications that completed successfully.
Failed VerificationsVerifications that ended in an error.

The credential totals count Verified ID credentials, so they stay at zero when every client uses Authenticator step-up.

TabWhat it is forWhere it is covered
CredentialsSearch the Verified ID credentials you issued, open one, or revoke it.Credentials and the verification log
Verification LogReview every verification attempt and its outcome.Credentials and the verification log
Client SettingsReview and change each client's effective policy in one grid.Clients and per-client policy
SandboxRehearse a verification before you rely on it.Sandbox, configuration and HaloPSA integration
ConfigurationOrganisation-wide settings: credential validity, Face Check, HaloPSA fields, e-mail and the Microsoft connection.Sandbox, configuration and HaloPSA integration

What happens automatically

  • An Authenticator step-up sign-in link the caller does not use expires after about three minutes, and a Verified ID request that goes unanswered expires after about five, so the technician's panel stops waiting. The log records either as Expired, and the check that does so runs every minute.
  • Credentials that pass their expiry date are marked Expired. This check runs about once an hour.
  • Log entries older than the retention period, 90 days by default, have their detailed claim and request data cleared. The entry itself stays, so the tamper-evident chain of the log still verifies. Nothing is deleted.

Roll it out in this order

  1. Set up your Microsoft connection and run preflight.
  2. Rehearse in the Sandbox (it contacts nobody), then run one real verification from the panel with a colleague you can phone, as described in Run one real verification before you rely on it, before anyone relies on it.
  3. Onboard clients: get each client's Microsoft administrator to consent and review their policy.
  4. If you use Verified ID, send issuance campaigns so users hold a credential before they call.
  5. Go live: technicians verify callers from the ticket panel (Verifying a caller).