How Okta Embraces Identity Verification Using Persona

Stephanie Kolobaric

With remote work becoming the norm, today’s organizations face a critical challenge: ensuring that users accessing their systems and data are in fact who they claim to be. Given our highly distributed workforce here at Okta, we leverage Persona for Identity verification.

The threat landscape

Given the current geopolitical environment, it is concerningly common for individuals to use fraudulent, or stolen Identities to apply for employment with highly targeted companies, especially in the cybersecurity industry.  At best, these individuals do not have the purported skills and capabilities required for the role and can drain company resources. In the most extreme cases, the individuals may be from sanctioned countries and operate for malicious threat actors with the aim of generating income via ransomware attacks or acquiring sensitive, proprietary information with ill-natured intent.

As part of the Okta Secure Identity Commitment (OSIC), our long-term initiative to lead the industry in the fight against Identity attacks, we’re tackling this issue head-on with the introduction of Identity verification using Persona’s trusted technology. Internally, ID verification has been introduced as a compulsory component of our evolving onboarding process and secure account recovery activities.

What is Persona? 

Persona’s technology offers a unified Identity platform that provides businesses the building blocks they need to securely collect, verify, manage, and make informed decisions about individuals' and businesses' Identities. Okta leverages Persona’s industry-leading technology to securely protect access to online accounts by verifying government-issued identification and comparing it to live, attention-aware photographs to provide greater assurance that the person behind the access attempt is in fact who they're claiming to be.

In practice, Identity verification inquiries with Persona involve up-to-date, live photography capturing varying angles in addition to government-issued photo identification, where a series of validation activities are then performed to assess the veracity of the access attempt. Only once both the photographs and identification have passed a series of secure checks, will the individual have been deemed to “pass” the verification process and subsequently gain access to the controlled environment. 

Positioned highest for Ability to Execute in the 2024 Gartner Magic Quadrant for Identity Verification, Persona offers the following capabilities:

  • Collection, verification, enrichment and analysis of user information;

  • Enablement of decision-making based on user information analysis; 

  • Integration of third-party data for additional insights; and 

  • Evaluation of behavioral risk signals and automation of decisions using customizable workflows.

Okta’s Use Case

Persona’s technology offers use case customization, allowing configuration for required or non-required validation. In Okta’s case, we’ve customized our Identity verification process to include country verification to ensure legal alignment to relevant restrictions, limiting the access of Okta’s products in jurisdictions where US import controls or economic sanctions laws are in effect.

Persona’s customizable options include enabling indicators of particular interest during an Identity challenge. This is a key capability for insider threat security teams who can for example, flag the face likeness of known malicious threat actors which can provide increased assurance to prevent repeated attempts to gain unauthorized access to critical company resources. 

During initial testing of Persona’s capabilities, we found it to be both very effective at flagging a variety of identity-based attacks, while being nuanced enough to allow for benign inconsistencies which often occur with identifications and selfies, such as variation in the name order e.g. given names and surnames may be interchangeable. This means teams responsible spend less time working through false positives. Our ID proofing implementation journey has been one of ease, with Persona seamlessly integrating with our existing infrastructure and technology stack.  Okta has fully-embedded the Persona widget into our workflows, enabling users to verify their identity without ending their Okta session. 

At 2024’s annual Oktane conference, we announced a new ID proofing feature that allows customers to create Identity verification challenges during a workflow, as governed by their Okta Account Management Policy (OAMP). Through the introduction of this new feature, Okta is leveraging Persona’s technology to address two high-risk  use cases where Identity verification is essential: employee onboarding and self-service account recovery.

In line with our efforts to free everyone to safely use any technology, the introduction of mandatory ID proofing during onboarding increases the integrity, robustness and security of Okta’s new hire process. ID proofing aims to ensure the new hire is who they say they are, and that they are the same individual who has participated throughout the recruiting process.

Post-onboarding, using ID proofing for self-service account recovery offers higher assurance that a legitimate, authorized user is the one unlocking the user account in question. This in turn mitigates and reduces the risk of an impersonation attack. It also allows Okta’s technical support teams to spend less time manually performing account unlock activities for employees who find themselves locked out of their accounts.

What’s next? 

Persona is the first ID proofing vendor we’ve integrated with, here at Okta. We continue to prioritize Identity verification and validation for our workforce in addition to prioritized phishing-resistant authentication.

We’re looking forward to exploring additional ID proofing integrations to tackle evolving Identity theft trends in our continued fight against Identity threats. Stay tuned as we continue to evolve our Identity verification capabilities, partnering with industry leaders to prioritize securing your systems and data.

Stephanie Kolobaric
Principal, Insider Threat Specialist

Stephanie Kolobaric is a Principal, Insider Threat Specialist at Okta. Based in Australia, she leverages her security expertise to assess and advise on threats to Okta from a personnel perspective. Stephanie’s background includes previous roles in national security and intelligence, as well as senior leadership roles in Government focused on organizational change management, international policy and strategy development. In her downtime, Stephanie enjoys gardening, hiking and spending quality time with her family.