Lessons · IT support · the password reset
A password reset: prove who is asking before anything else
A reset gives a stranger a way in if you do the reset before you know who is on the phone. The identity check comes first, every time, by the desk's agreed method: a call back on the number in the directory, a manager's confirmation, or an answer only the real person knows. Then a temporary password that must be changed at the next sign-in.
Hone is a place to practise a career, one idea a day. This is one of its lessons, written out in full and free to read without an account.
What it is for
A friendly voice says they are the finance director, they are at the airport, and they need their password reset right now. Everything about the call is designed to make you skip one step. The real finance director will not mind a callback on her office mobile. The person pretending to be her will hang up.
How to think about it
Verify first, by the desk's rule and not by how the caller sounds. Confirm the exact account name. Set a temporary password, and set the account so the first sign-in forces a change, so the temporary one is dead within minutes. Hand it over by the agreed channel, never by reply to the email that asked. Stay on the line while they sign in, then write the ticket with the method of verification named.
Worked example
Caller: 'I am J. Reyes, I need my password reset now'The request. Nothing has been done yet, and nothing should be.
Verify: call back on the directory number for J. Reyes → she answersThe check, by the desk's method. Now you know who is asking.
Reset to a temporary password; must change at next sign-inThe temporary password lives for one sign-in.
Given by phone on the callback; she signs in and changes it while you wait; note: 'verified by directory callback'Handed over on the channel you trust, verified live, and the ticket says how identity was proved.
Your turn
A caller asks for a reset. Write what you do before you touch the account.
Before any reset: the caller's identity
Solve one, graded on the server
The trap
Sending the new password by replying to the email that asked for it. If the mailbox was the thing that was stolen, you have just handed the thief the second key too.