Help desk verification
The process for proving a caller is who they claim before resetting a password or registering a new MFA device.
This has become a primary attack path, because it is the one place where a human can override every technical control at once. Several of the largest breaches of recent years began with a convincing phone call to a service desk rather than any exploit.
Knowledge-based checks like employee number or date of birth are no longer sufficient, since that information is usually available or already breached. Stronger approaches verify through an existing enrolled device, a callback to the number on record, or confirmation from the user's manager.
Where this comes up
Help desk verification sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.