Onboarding is a uniquely high-risk process in that the IT department creates new identities and communicates with people who may not yet be fully embedded in the organization.
That creates opportunities for both mistakes and exploitation. Attackers may intercept credentials sent to a personal email address, while weak identity checks can allow the wrong person to activate an account.
A secure workflow therefore must protect how the first credential is created, confirm that the person enrolling is the intended employee and apply the same standard of identity verification when support is needed.
Securely Preparing and Delivering Access Before the First Day
The first security decision often happens before the employee starts at the company: who creates the initial password, and how does it reach them?
A common approach is for IT to create a temporary password and send it to the new hire by email or SMS. It may be convenient, but it also creates an unnecessary exposure point. The credential is known to someone other than the employee and may remain written somewhere long after onboarding is complete.
Best Practices for Secure Pre-Start Account Activation
- Avoid sending reusable credentials through ordinary communication channels: Do not send permanent passwords or long-lived temporary credentials through channels like personal email or SMS, as these can be intercepted.
- Prefer short-lived, single-use activation methods: Use one-time activation links, temporary tokens, or a secure onboarding portal. Tokens should expire quickly and become invalid as soon as they are used.
- Keep activation separate from identity proofing: Receiving an activation message only proves that someone can access the account or device. It should not, by itself, be enough to establish that they are the person the organization hired.
- Avoid predictable temporary passwords: Previous research has shown that terms like ‘Welcome’, ‘user’, and ‘temp’ commonly appear in breached password datasets, so shouldn’t be used even as temporary credentials.
- Use role-based access for standard entitlements: Define the systems and permissions employees should receive based on their role, department, or location rather than building access manually for each new hire.
The best way to mitigate the risk of first-day credential theft is to not share a credential at all. With Specops Secure Onboarding, IT sends the new hire a secure enrollment link so they can create their own Active Directory password before their first day. IT never creates, sees or sends the credential, removing the interception risk that comes with email and SMS handoffs.
Verifying Identity and Activating Accounts on the First Day
An activation email, temporary password, phone number, or even a company laptop can all end up in the wrong hands. If the service desk lets someone activate an account or enroll multi-factor authentication (MFA) without first confirming who they are, an attacker may be able to bind their own device or credential to the employee’s account before the legitimate user ever signs in.
Best Practices for Identity Verification and Activation
- Verify identity before granting full access: Build an explicit identity check into first-time activation rather than assuming that possession of an activation link or temporary credential is enough.
- Enroll MFA as part of the activation process: Avoid leaving new accounts in a password-only state for longer than necessary. MFA should be established before the employee receives access to sensitive systems.
- Prefer phishing-resistant authentication where possible: Phishing-resistant MFA, passkeys, FIDO2 security keys, and other methods reduce the risk of credentials or authentication codes being captured during onboarding.
- Protect MFA enrollment itself: Registering a new factor is a security-sensitive action. Require suitable identity checks before allowing MFA to be added to the account.
- Consider device trust as well as user identity: If corporate laptops are shipped before the start date, make sure device enrollment and first login are tied to the approved user rather than treating possession of the device as sufficient authorization.
Solutions like Specops Secure Onboarding add government-issued ID scanning and AI-driven biometric liveness detection to the onboarding process. It checks that the document is genuine and that the person presenting it is physically present, helping defend against document fraud, replay attacks and deepfake impersonation.
With support for more than 16,000 document types across 254 countries, Specops Secure Onboarding can apply the same verification standard across remote and international hiring workflows.
Securing Exceptions, Recovery and Service Desk Support
Password resets and account recovery can give attackers access to an account if robust verification processes aren’t in place. As such, the requester’s identity must be verified before the agent takes any high-risk action.
Best Practices for Securing Ongoing Service Desk Support
- Require strong verification before resetting authentication methods: Changes to MFA factors and recovery details should require stronger checks than routine support requests.
- Avoid knowledge-based verification: NIST recommends against using knowledge-based questions because they can be socially engineered or found online.
- Do not let urgency override verification: A new hire being unable to work is disruptive, but that should not become a reason to bypass identity checks or security controls.
- Restrict who can perform sensitive recovery actions: Limit the ability to reset MFA, change authentication methods, or issue replacement activation credentials to appropriately authorized support staff.
- Apply extra controls to high-risk accounts: Users with elevated permissions, such as administrators, may warrant additional approval or verification before recovery actions are completed.
Specops Secure Onboarding blocks service-desk agents from resetting passwords, unlocking accounts or granting access until the requester’s identity has been confirmed.
Native integrations with ServiceNow, Jira and other leading ITSM platforms place identity verification directly inside the support workflow. Agents can follow the approved process without switching tools, while the organization gets a consistent, auditable control for every high-risk request.
Build Identity Assurance into Every Onboarding Step
A secure new-hire workflow protects the first credential, verifies the employee before access is activated and applies the same standard when they later contact the service desk.
Specops Secure Onboarding
Specops Secure Onboarding brings those controls together by building identity verification into every stage of the new-hire workflow.
Contact us today to see how Specops can help you build a more secure account activation process.