Fortified ID
Fortified ID

Confirm user | Fortified ID

In order for a user to be able to use strong authentication, it is preceded by an activation/registration for the user. With Fortified ID Enrollment, a user can do this easily on their own or designated administrators can do this for the user. For example, a support technician can prepare a mobile phone so that it both has the app (e.g. Microsoft Authenticator) installed but also is tied to the user's account.

Confirm

integrity-white.png

Confirm is a complete solution for secure identity verification when users call a helpdesk or support organization. The product is available in two variants, both of which protect against social engineering, identity fraud and incorrect access in sensitive cases.

Why Confirm is needed

  • Prevents unauthorized access and reduces the risk of data leaks

  • Protects against social engineering and role hijacking

  • Ensures proper case management in sensitive support situations

  • Builds trust through transparency and strong authentication

  • Makes verification fast, easy, and integrated into the helpdesk flow

Overview

Get started

eID as a secure verification method in Confirm
Confirm includes a dedicated flow for reverse eID verification, developed to ensure that the caller is indeed the individual stated. Below is an example with mobile BankID.

1. Support initiates the verification
The employee enters the user’s social security number and a verification text to be displayed in the BankID app. The system then sends a BankID request to the correct person.

2. Information and consent

The user is informed that a verification is being initiated and that certain personal information is being shared for the purpose of establishing identity. Consent is required to continue.

3. Authentication in BankID

The person receives a notification in their BankID app, reads the verification text and signs to confirm their identity.

4. Automatic validation in the system

After signing, support receives immediate notification that the person has been authenticated with a valid BankID, along with relevant account data for the case.

5. Proof of possession

To verify that the same individual is on the phone, the user can read out the verification text from their BankID app — a simple but effective proof of possession.

6. Secure and correct case handling
Once the identity is confirmed, support can continue handling without the risk of confusion or fraud attempts.

Confirm via verification code

Confirm also offers a verification flow with a time-limited one-time code, designed to ensure that the caller is indeed the same individual who is logged into the service.

 
 1. Login
The user logs into the service with their username, password or e-ID.

 
2. Information and consent
The service informs the user that personal information will be shared with support in order to enable identification and correct case management.
The user must actively approve this before the function can be used.
 
3. Initiation of verification
When contact with support is needed, the user selects the option “Verify me”.
The system then packages the relevant login data as well as any supplementary information from the customer’s own system, such as customer number, case ID or user profile.
The information is temporarily stored for use during validation.
 
4. Generation of verification code
 The system creates a unique and time-limited code that is displayed to the user on the screen.
 
5. Code Sharing
 The user reads the code to the support person on the phone.
 
6. Code Validation
The support person enters the code into their system.
Confirm checks that the code is valid, links it to the previously packaged login and customer data, and confirms that the person on the phone is the same logged-in user.
 
7. Confirmed Identity

Once the verification is approved, support can continue the case in a secure and correct manner, with access to the information needed to help the user.

Confirm.jpg

Confirm offers either one-time code verification or reverse eID verification with BankID, allowing organizations to choose the method that best suits their processes and user groups.

Both variants are based on clear consent, a strong connection between

Confirm

BankID

eIDAS

EFOS

Certificate

Skolfederation

Svenska Pass

Sweden Connect

Sambi

SITHS eID

Passkey

Authenticator

eduID

Telia

Freja eID

Freja orgID

ID Porten

Suomi.fi

Authenticator

OTP

FIDO

ADFS

Our solutions are based on a module-based architecture, which enables a wide range of advantages for automation, monitoring and efficient management. We know these qualities are central abilities both for operations managers and DevOps. This makes it easier to have control over IT environments and, by extension, your digital identities with cost efficiency.