Credentials and the verification log
How an administrator finds, reviews and revokes issued credentials, reads and filters the verification log, checks that the log has not been changed and exports it.
Written By Chris Scaminaci
Last updated About 1 hour ago
The Credentials and Verification Log tabs of the Identity Verification screen are where an administrator reviews what has been issued and what has been verified. Use them to revoke a credential, to look into a suspicious result and to hand evidence to an auditor.
Before you start: the Identity Verification module is on, and you are signed in as an Administrator or an Identity Verification Admin. White-label partner accounts cannot open these screens. In the sidebar, select Analytics & Reporting → Identity Verification. The sidebar entry appears once Identity Verification has been set up. Credentials exist only for clients that use Microsoft Entra Verified ID. If your organisation uses only Authenticator step-up, the Credentials tab stays empty, while the Verification Log still records every verification.
Find a credential
- Open the Credentials tab.
- Type in the search box (Search by email or name...) to narrow the list by e-mail address or name.
- Select All, Active, Revoked or Expired to filter by status. Active lists credentials whose status is Issued.
The grid shows Email, Name, Status, Issued, Expires and Verifications, the number of times the credential has been used. It shows 15 credentials a page, and you can sort by any column.
Open a credential's details
- In the Actions column, select View Details (the eye) for the credential. The Credential Details page opens.
- Read the holder's name and e-mail address and the credential's status.
- Check Issued, Expires, Last Verified (Never if it has not been used) and Total Verifications.
- Read Verification History. It lists the latest 50 attempts against this credential. Each shows the outcome, the time and where it started, the FaceCheck score when Face Check was used, and the ticket number.
If the link no longer points at a credential, the page shows Credential Not Found. Select Go Back to return to the list.
Revoke a credential
Revoking disables the credential for good. The user needs a new one before they can be verified this way again, and revoking cannot be undone. Only credentials that are still active can be revoked. If someone presents a revoked credential, the technician sees that it has been revoked and treats the call as unverified.
- In the grid, select Revoke (the red button) for the credential. Or open its details and use the Revoke Credential panel, which has the same effect.
- In the Revoke Credential dialog, check the e-mail address, then write the Revocation Reason. It is required.
- Select Revoke Credential. The screen confirms Credential revoked successfully and the credential's status changes to Revoked.
To enrol the user again, use Issuing credentials and supervised overrides or an issuance campaign.
Review the verification log
The Verification Log tab lists every verification attempt: passes, failures, refusals, overrides and sandbox rehearsals.
- Select a period: Today, This Week, This Month or All Time. The log opens on This Week. Today counts from midnight UTC.
- Optionally filter by mode (Any mode, Microsoft Entra Verified ID or Authenticator sign-in, which is the log's name for Authenticator step-up), by assurance (Any assurance, Basic, Substantial or High) and by outcome (Any outcome, or one of Verified, Override granted, Reused prior verification, Subject mismatch, Downgrade blocked, Start refused: no identity, Failed, Expired and Cancelled).
- Read the grid. It shows the newest 200 rows that match, 20 to a page. To see more, narrow the period or use Export CSV.
The note above the grid explains the one result that needs care: Override granted is a caller the system could not verify who was waved through by a supervisor. It is counted and shown apart from a pass, never as one.
Read the Result column
Subject mismatch and Downgrade blocked are the rows worth reading regularly. A mismatch means someone other than the expected person answered a challenge. Repeated downgrade refusals for one client usually mean its policy asks for more than the methods available to it.
Check that the log has not been changed
The log is tamper-evident. Each finished verification takes its place in a chain and is sealed with a signature that covers the row before it. Changing a sealed row, or removing one, makes the chain fail its check. Rows that sandbox rehearsals create are part of the chain too, so they are kept rather than deleted.
Only an Administrator can run the check, from Module Management:
- In the sidebar, select System → Module Management.
- Hover over the Identity Verification module. A panel opens with a Health section. The module must be enabled.
- Select Verify audit chain. The button reads Verifying... while it recomputes every link.
- Read the line it returns. A healthy log reads Audit chain verified: followed by how many rows and client chains were checked.
If the line begins Audit chain FAILED verification, a sealed row was changed or removed after it was written. The panel names the first place the chain diverges. Do not export or edit anything further, and contact TechPulse through Getting help. If the line gives a warning instead, read the sentence under it and ask TechPulse if you cannot explain it.
Export the log
- Set the period and filters you want on the Verification Log tab.
- Select Export CSV. The browser downloads a file named identity-verification-log with the date and time.
The export contains every row that matches the period and filters, not only the 200 the grid shows. Each row includes the caller's e-mail address and name, the proven person's e-mail address, the client, the technician who started it, the ticket number and the error text, which holds the recorded statement for an override. This is personal data. Share the file only with people who need it, store it where your organisation keeps records of that kind, and delete your copy when you are done.
Related
- Identity verification is the overview of the screen and the two verification modes.
- Issuing credentials and supervised overrides explains how a credential is issued and how each override is recorded.
- Module Management is where the log's chain is checked.
- Sandbox, configuration and HaloPSA integration covers rehearsals and the Configuration tab.
Was this helpful?
Still need help? Ask the team