Identity-verified zero trust to stop laptop farms and insider threats
Key Points
- OIDC integration with Nametag
- Stops laptop-farm remote IT fraud
- Continuous identity verification and risk scoring
Summary
Remote “IT worker” fraud—organized laptop farms using stolen or deepfaked identities—bypasses device- and credential-based zero trust models. Cloudflare has partnered with Nametag to add workforce identity verification to Cloudflare Access via OIDC, providing cryptographic and biometric-backed identity attestation before initial onboarding and during sessions.
Key Points
- Threat: Attackers ship corporate laptops to mule addresses and log in remotely with valid credentials; traditional ZTNA, DLP, and UEBA detect issues only after compromise.
- Integration: Nametag plugs into Cloudflare Access as an OIDC IdP or external evaluation factor alongside Okta/Microsoft Entra, returning an ID token on successful verification.
- Verification flow: user submits work email, selfie, and government photo ID; Deepfake Defense™ analyzes authenticity and the right-to-be; verification takes <30 seconds and no biometrics are stored.
- Enforcement: Cloudflare grants or denies access based on identity attestation combined with device posture and Access policies; can protect onboarding, password resets, and MFA registration workflows to prevent social engineering.
- Continuous assurance: Cloudflare Access uses user risk scores to revoke or step-up authentication mid-session; teams can require Nametag re-verification or strong MFA when risk increases.
- Operational steps for engineers:
- Pilot with Cloudflare One (free for up to 50 users) and enable Nametag OIDC in Access.
- Protect high-risk portals (onboarding, IT support, password reset) behind identity-verified Access policies.
- Combine identity attestation with existing DLP, RBI, and CASB controls and enforce step-up checks based on risk signals.
Practical takeaways
- Do not rely solely on device/posture checks—verify the human behind credentials.
- Deploy Nametag OIDC for onboarding and critical self-service flows to stop deepfake and mule-farm attacks before access is granted.
- Use risk scores to automate step-up verification or session termination without large-scale disruption.