The verification workflow

From “it’s me” to a verified account.

A defined exchange for your callers and your team. Microsoft handles authentication. Proofcall connects the result to the person you expect on the call.

Watch the overview · 92 seconds

From the first question
to a verified caller.

See how the caller, Microsoft and your engineer or AI agent work together. Follow the verification exchange and the evidence behind the result.

Illustrated workflow with fictional examples and synthetic narration.
Read the video transcript

A support conversation can lead to a sensitive account change. Proofcall gives your team a defined way to verify the caller before deciding what happens next.

First, your engineer or AI agent selects the organisation and the expected caller. Proofcall connects the verification request to that person’s Microsoft account.

The caller opens a verification link and signs in with their own Microsoft organisation, using an authentication method they already have. No separate Proofcall app or factor enrolment is needed.

After authentication, Proofcall shows the caller its own separate code. The caller reads that code to the engineer or voice agent. Never ask for a Microsoft sign-in code or password.

The handler submits the code. Proofcall returns the result and records the account, authentication evidence and who handled the check. Your support workflow then applies its policy to the requested action.

Engineers work in the console. Compatible AI agents connect through the API or MCP. Plan a human handoff when verification cannot be completed, including when the caller cannot use their authentication method.

Start with one Microsoft tenant and test the complete caller experience. Proofcall. Verify the caller. Then help.

01 Start with the right person

Your engineer or AI agent selects the organisation and caller. Proofcall binds the request to that person’s Microsoft identity.

02 Let Microsoft authenticate

The caller opens the verification link and signs in with their organisation. They use an authentication method they already have.

03 Bring proof back to the call

After authentication passes, the caller receives a separate Proofcall code and reads it to the handler. Never ask for a Microsoft sign-in or Authenticator code.

04 Record the result

The handler submits the code. Proofcall returns a result and records the authentication evidence, with the human or automated handler identified.

An example of the evidence

Verification complete

Verified
Caller
Maya Patel
Organisation
Northstar
Identity provider
Microsoft Entra ID
Verification
Direct · caller authenticated
Handled by
Named engineer / AI agent
Recorded
Identity, time and outcome

A record your team can review. Available authentication details are retained with the result. Approver verification is labelled separately.

Why the read-back matters

The caller brings the proof to the conversation.

An unrelated user approving a notification is not enough to complete this exchange. The handler needs the separate Proofcall code issued after the expected account authenticates.

CALLER

Authenticate with your organisation.

The sign-in takes place with Microsoft. After it succeeds, a Proofcall code appears on the caller’s screen.

HANDLER

Enter what the caller reads.

The engineer or agent cannot retrieve the answer from the verification API. They submit the code supplied by the caller.

RESULT

Review the evidence.

Proofcall checks the submitted code and returns a result. The support workflow then applies your policy to the requested action.

A Proofcall code is not a Microsoft sign-in code. The handler only asks for the separate code on the Proofcall page after authentication. Never share a password or Microsoft Authenticator code.

Connect a tenant. Try a real workflow.

An administrator connects your organisation and configures a Conditional Access authentication context for verification. Callers need Entra ID P1 and a usable authentication method.

Your engineers then use the console to find callers and start checks. MSPs can connect client tenants; internal teams can begin with their own organisation.

Plan for the caller who cannot authenticate.

A caller who has lost their only factor cannot complete direct verification. A forgotten password may also prevent sign-in unless another supported method is available.

Proofcall includes an approver flow: a colleague authenticates and vouches for the caller. The record distinguishes that attestation from direct verification. Your organisation decides when it is sufficient and when a separate recovery process is needed.

Understand the verification boundary →
Put verification into practice

Make your next support conversation a verified one.

Start with one Microsoft tenant and your own team. Follow the caller’s experience, review the result and build verification into your workflow.

14 days · No card required · Microsoft Entra ID P1