{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/make-identity-proofing-recoverable-equitable-evidence-based/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/",
        "slug": "make-identity-proofing-recoverable-equitable-evidence-based",
        "url": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/make-identity-proofing-recoverable-equitable-evidence-based/"
        },
        "title": "Make identity proofing recoverable, equitable, and evidence-based",
        "summary": "Identity proofing establishes which real-world person is being enrolled; authentication later proves control of an authenticator. Select the needed assurance, protect proofing data, offer workable paths, and build redress for mistakes and fraud.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-11T10:37:00+00:00",
        "modified_at": "2026-08-11T15:18:11+00:00",
        "reviewed_on": "2026-08-11",
        "reading_minutes": 3,
        "word_count": 614,
        "potentially_affected": "Customer and workforce enrollment, credential service providers, help desks, identity evidence, remote proofing, biometrics, fraud operations, accessibility, privacy, account recovery, and high-impact transactions.",
        "dse_recommendation": "Define the identity assurance needed for each service, map enrollment paths and failure cases, minimize retained evidence, test fraud and accessibility controls, and establish independent redress with auditable outcomes.",
        "primary_source": {
            "name": "NIST SP 800-63A-4: Identity Proofing and Enrollment",
            "url": "https://csrc.nist.gov/pubs/sp/800/63/a/4/final",
            "published_on": "2025-07-31",
            "authority": "National Institute of Standards and Technology"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts: proofing and authentication answer different questions</h2>\n<p>NIST Special Publication 800-63A-4 addresses identity proofing and enrollment for digital authentication. During proofing, an applicant presents evidence to a credential service provider so the provider can resolve the applicant to a unique identity, validate evidence, and verify that the applicant is associated with that identity. Authentication later establishes control of an authenticator. A strong authenticator does not correct a proofing process that enrolled an impostor.</p>\n\n<p>The publication defines three identity assurance levels. IAL1 does not require linking the applicant to a specific real-life identity. IAL2 and IAL3 apply progressively stronger requirements based on the service’s risk and need for confidence. The guideline supports remote and attended processes under stated requirements and includes controls for evidence, validation, verification, notification, records, privacy, security, fraud mitigation, and redress.</p>\n\n<p>NIST also emphasizes customer experience and equity. Proofing failures and inaccessible methods can prevent legitimate people from receiving a service. The provider must consider privacy risk, data minimization, notice and consent, protection of personal information, alternative methods where required, and mechanisms for resolving complaints or correcting errors. Biometrics, when used, are one part of a controlled process rather than an identity by themselves.</p>\n\n<h2>DSE recommendation: choose assurance from the transaction’s harm</h2>\n<p>For each service, describe what a falsely enrolled identity could authorize, learn, alter, receive, or deny. Consider harm to the applicant, other people, the organization, and external parties. Decide whether a real-world identity is necessary at all; collecting identity evidence without a defined need creates privacy and breach exposure.</p>\n\n<p>When proofing is required, document the target assurance level, eligible evidence, authoritative or credible sources, resolution rules, validation checks, verification methods, fraud controls, retention, and approval. Keep this decision separate from authenticator strength and federation choices so one strong layer does not conceal a weak one.</p>\n\n<h2>DSE recommendation: design every enrollment path and failure path</h2>\n<ol>\n<li><strong>Map the applicant journey.</strong> Cover normal remote and attended enrollment, low-connectivity conditions, name changes, limited documentation, accessibility needs, failed automated checks, duplicate records, and suspected fraud.</li>\n<li><strong>Minimize proofing data.</strong> Collect and retain only what the approved purpose requires. Restrict operator and system access, protect transmissions and stored records, and set defensible deletion schedules.</li>\n<li><strong>Separate duties for exceptions.</strong> High-risk overrides should require documented evidence and independent approval. An operator should not be able to invent, approve, and conceal an identity exception alone.</li>\n<li><strong>Notify through a validated channel.</strong> Give the subject a meaningful opportunity to detect an enrollment they did not initiate without exposing sensitive proofing details in the notice.</li>\n<li><strong>Build redress outside the failed mechanism.</strong> A person rejected because a document or biometric check failed needs a secure way to challenge the result that does not simply repeat the same test.</li>\n</ol>\n\n<h2>DSE recommendation: measure fraud and legitimate-user harm together</h2>\n<p>Test presentation attacks, forged evidence, stolen identity data, synthetic identities, insider misuse, replay, source unavailability, and account-linking errors. Also test accessibility, language, device limitations, demographic performance where legally and operationally appropriate, completion rates, abandonment, false rejection, appeal time, and correction accuracy.</p>\n\n<p>Protect detailed fraud signals from public disclosure that would enable evasion, but provide governance with enough evidence to compare paths. Review vendors for subcontractors, data locations, model and process changes, breach duties, evidence access, retention, and termination support. Include proofing service outages and supplier termination in continuity exercises so legitimate enrollment does not depend on an untested fallback. Record assurance decisions, test results, exception rates, complaints, redress outcomes, and approved improvements. Identity proofing is trustworthy only when it resists impersonation while giving legitimate people a safe, understandable, and correctable route to enrollment.</p>\n\n<h2>Official references</h2>\n<ul>\n<li>National Institute of Standards and Technology, <a href=\"https://csrc.nist.gov/pubs/sp/800/63/a/4/final\" target=\"_blank\" rel=\"noopener noreferrer\"><em>SP 800-63A-4: Digital Identity Guidelines—Identity Proofing and Enrollment</em></a>, July 31, 2025; reviewed August 11, 2026.</li>\n</ul>",
        "content_text": "Source facts: proofing and authentication answer different questions\nNIST Special Publication 800-63A-4 addresses identity proofing and enrollment for digital authentication. During proofing, an applicant presents evidence to a credential service provider so the provider can resolve the applicant to a unique identity, validate evidence, and verify that the applicant is associated with that identity. Authentication later establishes control of an authenticator. A strong authenticator does not correct a proofing process that enrolled an impostor.\n\nThe publication defines three identity assurance levels. IAL1 does not require linking the applicant to a specific real-life identity. IAL2 and IAL3 apply progressively stronger requirements based on the service’s risk and need for confidence. The guideline supports remote and attended processes under stated requirements and includes controls for evidence, validation, verification, notification, records, privacy, security, fraud mitigation, and redress.\n\nNIST also emphasizes customer experience and equity. Proofing failures and inaccessible methods can prevent legitimate people from receiving a service. The provider must consider privacy risk, data minimization, notice and consent, protection of personal information, alternative methods where required, and mechanisms for resolving complaints or correcting errors. Biometrics, when used, are one part of a controlled process rather than an identity by themselves.\n\nDSE recommendation: choose assurance from the transaction’s harm\nFor each service, describe what a falsely enrolled identity could authorize, learn, alter, receive, or deny. Consider harm to the applicant, other people, the organization, and external parties. Decide whether a real-world identity is necessary at all; collecting identity evidence without a defined need creates privacy and breach exposure.\n\nWhen proofing is required, document the target assurance level, eligible evidence, authoritative or credible sources, resolution rules, validation checks, verification methods, fraud controls, retention, and approval. Keep this decision separate from authenticator strength and federation choices so one strong layer does not conceal a weak one.\n\nDSE recommendation: design every enrollment path and failure path\n\nMap the applicant journey. Cover normal remote and attended enrollment, low-connectivity conditions, name changes, limited documentation, accessibility needs, failed automated checks, duplicate records, and suspected fraud.\nMinimize proofing data. Collect and retain only what the approved purpose requires. Restrict operator and system access, protect transmissions and stored records, and set defensible deletion schedules.\nSeparate duties for exceptions. High-risk overrides should require documented evidence and independent approval. An operator should not be able to invent, approve, and conceal an identity exception alone.\nNotify through a validated channel. Give the subject a meaningful opportunity to detect an enrollment they did not initiate without exposing sensitive proofing details in the notice.\nBuild redress outside the failed mechanism. A person rejected because a document or biometric check failed needs a secure way to challenge the result that does not simply repeat the same test.\n\nDSE recommendation: measure fraud and legitimate-user harm together\nTest presentation attacks, forged evidence, stolen identity data, synthetic identities, insider misuse, replay, source unavailability, and account-linking errors. Also test accessibility, language, device limitations, demographic performance where legally and operationally appropriate, completion rates, abandonment, false rejection, appeal time, and correction accuracy.\n\nProtect detailed fraud signals from public disclosure that would enable evasion, but provide governance with enough evidence to compare paths. Review vendors for subcontractors, data locations, model and process changes, breach duties, evidence access, retention, and termination support. Include proofing service outages and supplier termination in continuity exercises so legitimate enrollment does not depend on an untested fallback. Record assurance decisions, test results, exception rates, complaints, redress outcomes, and approved improvements. Identity proofing is trustworthy only when it resists impersonation while giving legitimate people a safe, understandable, and correctable route to enrollment.\n\nOfficial references\n\nNational Institute of Standards and Technology, SP 800-63A-4: Digital Identity Guidelines—Identity Proofing and Enrollment, July 31, 2025; reviewed August 11, 2026.",
        "content_markdown": "## Source facts: proofing and authentication answer different questions\n\nNIST Special Publication 800-63A-4 addresses identity proofing and enrollment for digital authentication. During proofing, an applicant presents evidence to a credential service provider so the provider can resolve the applicant to a unique identity, validate evidence, and verify that the applicant is associated with that identity. Authentication later establishes control of an authenticator. A strong authenticator does not correct a proofing process that enrolled an impostor.\n\nThe publication defines three identity assurance levels. IAL1 does not require linking the applicant to a specific real-life identity. IAL2 and IAL3 apply progressively stronger requirements based on the service’s risk and need for confidence. The guideline supports remote and attended processes under stated requirements and includes controls for evidence, validation, verification, notification, records, privacy, security, fraud mitigation, and redress.\n\nNIST also emphasizes customer experience and equity. Proofing failures and inaccessible methods can prevent legitimate people from receiving a service. The provider must consider privacy risk, data minimization, notice and consent, protection of personal information, alternative methods where required, and mechanisms for resolving complaints or correcting errors. Biometrics, when used, are one part of a controlled process rather than an identity by themselves.\n\n## DSE recommendation: choose assurance from the transaction’s harm\n\nFor each service, describe what a falsely enrolled identity could authorize, learn, alter, receive, or deny. Consider harm to the applicant, other people, the organization, and external parties. Decide whether a real-world identity is necessary at all; collecting identity evidence without a defined need creates privacy and breach exposure.\n\nWhen proofing is required, document the target assurance level, eligible evidence, authoritative or credible sources, resolution rules, validation checks, verification methods, fraud controls, retention, and approval. Keep this decision separate from authenticator strength and federation choices so one strong layer does not conceal a weak one.\n\n## DSE recommendation: design every enrollment path and failure path\n\n- Map the applicant journey. Cover normal remote and attended enrollment, low-connectivity conditions, name changes, limited documentation, accessibility needs, failed automated checks, duplicate records, and suspected fraud.\n\n- Minimize proofing data. Collect and retain only what the approved purpose requires. Restrict operator and system access, protect transmissions and stored records, and set defensible deletion schedules.\n\n- Separate duties for exceptions. High-risk overrides should require documented evidence and independent approval. An operator should not be able to invent, approve, and conceal an identity exception alone.\n\n- Notify through a validated channel. Give the subject a meaningful opportunity to detect an enrollment they did not initiate without exposing sensitive proofing details in the notice.\n\n- Build redress outside the failed mechanism. A person rejected because a document or biometric check failed needs a secure way to challenge the result that does not simply repeat the same test.\n\n## DSE recommendation: measure fraud and legitimate-user harm together\n\nTest presentation attacks, forged evidence, stolen identity data, synthetic identities, insider misuse, replay, source unavailability, and account-linking errors. Also test accessibility, language, device limitations, demographic performance where legally and operationally appropriate, completion rates, abandonment, false rejection, appeal time, and correction accuracy.\n\nProtect detailed fraud signals from public disclosure that would enable evasion, but provide governance with enough evidence to compare paths. Review vendors for subcontractors, data locations, model and process changes, breach duties, evidence access, retention, and termination support. Include proofing service outages and supplier termination in continuity exercises so legitimate enrollment does not depend on an untested fallback. Record assurance decisions, test results, exception rates, complaints, redress outcomes, and approved improvements. Identity proofing is trustworthy only when it resists impersonation while giving legitimate people a safe, understandable, and correctable route to enrollment.\n\n## Official references\n\n- National Institute of Standards and Technology, [SP 800-63A-4: Digital Identity Guidelines—Identity Proofing and Enrollment](https://csrc.nist.gov/pubs/sp/800/63/a/4/final), July 31, 2025; reviewed August 11, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/",
                "url": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-11"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Make identity proofing recoverable, equitable, and evidence-based",
                        "item": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/#article",
                "identifier": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/",
                "url": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/",
                "headline": "Make identity proofing recoverable, equitable, and evidence-based",
                "description": "Identity proofing establishes which real-world person is being enrolled; authentication later proves control of an authenticator. Select the needed…",
                "abstract": "Identity proofing establishes which real-world person is being enrolled; authentication later proves control of an authenticator. Select the needed assurance, protect proofing data, offer workable paths, and build redress for mistakes and fraud.",
                "articleBody": "Source facts: proofing and authentication answer different questions\nNIST Special Publication 800-63A-4 addresses identity proofing and enrollment for digital authentication. During proofing, an applicant presents evidence to a credential service provider so the provider can resolve the applicant to a unique identity, validate evidence, and verify that the applicant is associated with that identity. Authentication later establishes control of an authenticator. A strong authenticator does not correct a proofing process that enrolled an impostor.\n\nThe publication defines three identity assurance levels. IAL1 does not require linking the applicant to a specific real-life identity. IAL2 and IAL3 apply progressively stronger requirements based on the service’s risk and need for confidence. The guideline supports remote and attended processes under stated requirements and includes controls for evidence, validation, verification, notification, records, privacy, security, fraud mitigation, and redress.\n\nNIST also emphasizes customer experience and equity. Proofing failures and inaccessible methods can prevent legitimate people from receiving a service. The provider must consider privacy risk, data minimization, notice and consent, protection of personal information, alternative methods where required, and mechanisms for resolving complaints or correcting errors. Biometrics, when used, are one part of a controlled process rather than an identity by themselves.\n\nDSE recommendation: choose assurance from the transaction’s harm\nFor each service, describe what a falsely enrolled identity could authorize, learn, alter, receive, or deny. Consider harm to the applicant, other people, the organization, and external parties. Decide whether a real-world identity is necessary at all; collecting identity evidence without a defined need creates privacy and breach exposure.\n\nWhen proofing is required, document the target assurance level, eligible evidence, authoritative or credible sources, resolution rules, validation checks, verification methods, fraud controls, retention, and approval. Keep this decision separate from authenticator strength and federation choices so one strong layer does not conceal a weak one.\n\nDSE recommendation: design every enrollment path and failure path\n\nMap the applicant journey. Cover normal remote and attended enrollment, low-connectivity conditions, name changes, limited documentation, accessibility needs, failed automated checks, duplicate records, and suspected fraud.\nMinimize proofing data. Collect and retain only what the approved purpose requires. Restrict operator and system access, protect transmissions and stored records, and set defensible deletion schedules.\nSeparate duties for exceptions. High-risk overrides should require documented evidence and independent approval. An operator should not be able to invent, approve, and conceal an identity exception alone.\nNotify through a validated channel. Give the subject a meaningful opportunity to detect an enrollment they did not initiate without exposing sensitive proofing details in the notice.\nBuild redress outside the failed mechanism. A person rejected because a document or biometric check failed needs a secure way to challenge the result that does not simply repeat the same test.\n\nDSE recommendation: measure fraud and legitimate-user harm together\nTest presentation attacks, forged evidence, stolen identity data, synthetic identities, insider misuse, replay, source unavailability, and account-linking errors. Also test accessibility, language, device limitations, demographic performance where legally and operationally appropriate, completion rates, abandonment, false rejection, appeal time, and correction accuracy.\n\nProtect detailed fraud signals from public disclosure that would enable evasion, but provide governance with enough evidence to compare paths. Review vendors for subcontractors, data locations, model and process changes, breach duties, evidence access, retention, and termination support. Include proofing service outages and supplier termination in continuity exercises so legitimate enrollment does not depend on an untested fallback. Record assurance decisions, test results, exception rates, complaints, redress outcomes, and approved improvements. Identity proofing is trustworthy only when it resists impersonation while giving legitimate people a safe, understandable, and correctable route to enrollment.\n\nOfficial references\n\nNational Institute of Standards and Technology, SP 800-63A-4: Digital Identity Guidelines—Identity Proofing and Enrollment, July 31, 2025; reviewed August 11, 2026.",
                "datePublished": "2026-08-11T10:37:00+00:00",
                "dateModified": "2026-08-11T15:18:11+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/make-identity-proofing-recoverable-equitable-evidence-based/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Make identity proofing recoverable, equitable, and evidence-based"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Microsoft 365 & Identity",
                    "Guide",
                    "Important priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 614,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "NIST SP 800-63A-4: Identity Proofing and Enrollment",
                    "url": "https://csrc.nist.gov/pubs/sp/800/63/a/4/final",
                    "datePublished": "2025-07-31"
                }
            }
        ]
    }
}