Opens in a new tab

The Day-One Gap in Zero Trust: Why Identity Verification Has to Start Before the First Login

  • Home
  • Blog
  • The Day-One Gap in Zero Trust: Why Identity Verification Has to Start Before the First Login
New hire login screen glowing on dark office desk

Organizations that have spent years hardening Zero Trust architecture can still hand an attacker a fully provisioned, MFA-protected account on Day One, because the identity behind the credentials was never properly verified in the first place. Onboarding and service desk processes remain a pressure point where a single high-impact access decision is made with limited context, and attackers only need to convince one person that they are who they claim to be.

Why manual identity checks are the weak link

Zero Trust principles are now common in enterprise infrastructure, with investments in identity and system controls that have made established users much harder to compromise through credentials that assumed enrolled MFA, registered devices, security questions and historical context. The moment a new hire is onboarded, those factors are absent, and the identity behind the new credential is being judged with weaker evidence than the system will ever accept again.

For an established employee, the service desk has plenty of ways to verify identity: enrolled MFA, registered devices, security questions, historical context. A new hire typically has none of those factors in place yet. If the initial check is weak, the controls that follow cannot fix it. The organization ends up building a trusted identity on top of an unverified person.

The fraudulent identity problem during hiring

The FBI has repeatedly warned that North Korean IT workers are using stolen or fraudulent identities to secure remote jobs and gain access to corporate networks. In some cases, workers have used false identity documents, proxy infrastructure and US-based facilitators to appear to be legitimate applicants.

This inverts the usual identity security model. Intrusion techniques typically involve an attacker stealing an employee’s credentials and using them to gain access. In an onboarding attack, the attacker passes the hiring process, and the organization creates credentials for them. North Korean fake worker schemes are persistent threats, and the FBI now recommends identity verification during the hiring process and throughout the employment of remote workers. The wider lesson is that organizations need to apply the same level of scrutiny to creating an identity as they do to authenticating one that already exists.

Why strong MFA has a weak point: enrollment

Once a new employee has passed onboarding, the service desk is often heavily involved in getting them set up. Agents may help activate the account, issue an initial credential, enroll MFA, register a passkey or security key, and configure a corporate device. If the wrong person reaches this stage, strong authentication does not correct the mistake. The attacker can end up with an account secured by MFA and linked to a trusted device, all issued through normal processes.

Users are exposed during credential bootstrapping, when they may still depend on weaker authentication before phishing-resistant credentials such as passkeys or security keys are registered. Attackers who compromise this window can interfere with enrollment and establish persistent access before stronger controls are fully in place.

What Day One identity verification actually looks like

Authentication asks whether someone can prove control of a credential linked to an account. Identity proofing asks whether the person in front of you is the individual the organization intends to give that account to. For an existing employee, a trusted factor such as an enrolled authenticator or registered device can provide enough assurance for many service desk requests. New starters may not yet have a corporate device or any established authentication factor the organization can trust, which means Day One needs its own verification process, especially when the user is about to receive access to sensitive systems or register the credentials that will represent them going forward.

Validating a government-issued identity document and pairing it with biometric liveness checks can provide assurance in the absence of existing authentication factors. This helps establish confidence in the person before the organization starts issuing trust.

Making verification part of the workflow, not a judgment call

Verification should be a required step in the onboarding process rather than something left to the service desk agent to judge case by case. As onboarding is usually the point where trust is first created, if an identity is poorly established at that stage, every control that follows is built on the wrong foundation. The same principle continues after onboarding. When that employee later contacts the service desk for help, the agent should require verification using trusted authentication factors before proceeding. This removes much of the guesswork from the process. Agents do not have to decide whether a caller sounds convincing or whether the information they provide is good enough. Verification becomes part of the workflow itself.

What Zero Trust should look like before the first login

Organizations have become much better at verifying users once they are inside the environment. The next step is applying the same thinking to the moment those identities are created. A new employee should not become trusted simply because an onboarding email reached the right inbox or a service desk agent was convinced by a caller. Identity needs to be established before credentials and access are issued, then verified again when sensitive support requests arise.

FAQ

What is the Day-One gap in Zero Trust?

The Day-One gap is the period during onboarding when a new hire has not yet enrolled MFA, registered devices or set up the authentication factors the organization normally relies on. If identity is not verified before credentials are issued, every Zero Trust control built on top is protecting an unverified person.

Why does the FBI recommend identity verification during hiring?

The FBI has repeatedly warned that North Korean IT workers use stolen or false credentials, and in some cases false identity documents and US-based facilitators, to secure remote jobs and gain access to corporate networks. The FBI now recommends identity verification during the hiring process and throughout the employment of remote workers because the attack happens before authentication, not after.

What should a Day One identity verification step include?

A strong Day One verification step validates a government-issued identity document and pairs it with a biometric liveness check. This provides assurance that the person being onboarded is who they claim to be before credentials, MFA methods, devices or application access are issued.


This article summarizes reporting from bleepingcomputer.com.

← All Articles