Account Recovery
The process by which a user regains access after losing their authenticator: a lost device, a forgotten password, or a revoked credential. It is a parallel authentication path, and its strength sets the real strength of the account.
Recovery is the most commonly under-designed part of an identity system. Deploying phishing-resistant authentication and then allowing a help desk to reset credentials after a few knowledge-based questions means the account's real assurance level is whatever the help desk enforces, and attackers know it. Passwordless deployments face this acutely: with no password to fall back on, recovery has to be designed deliberately, usually through multiple enrolled authenticators, a recovery code, or identity proofing at the same assurance level as enrolment.
See also: help desk social engineering, what is passwordless, passkey, IDV
Related on Start with Identity
- GlossaryCIAM
Customer Identity and Access Management. The identity stack for end users of a product, distinct from workforce IAM. CIAM optimizes for self-service signup, con
- BlogHow to vet a national digital ID before you build KYC on it
Not every national ID is equally trustworthy or equally easy to verify. A practical seven-point checklist for evaluating a country's digital ID before you wire
- GlossaryIdentity Assurance Level (IAL)
NIST 800-63A levels describing identity proofing strength. IAL1: self-asserted. IAL2: remote or in-person verification with evidence. IAL3: in-person verificati
- GlossaryKYC
Know Your Customer. Regulatory obligations to identify and verify the identity of customers, primarily in financial services. KYC is a workflow built on top of
- GuideIdentity Federation Implementation Guide: Protocols, Trust, and Cross-Domain SSO
A step-by-step guide to implementing identity federation covering SAML, OIDC, and WS-Federation protocols, trust relationship configuration, attribute mapping,
- GuideImplementing Passkeys in the Enterprise
A practical guide to deploying passkeys across your enterprise, covering WebAuthn integration, device attestation policies, account recovery workflows, and stra