Account Troubleshooting Guide

Body

Policy Statement

Innovative Technology Solutions (OITS) provides identity and authentication services for faculty, staff, students, and affiliated users. This article provides guidance for troubleshooting common account-related issues and identifying the appropriate escalation path.


Reason for Policy

The purpose of this article is to provide a consistent process for diagnosing authentication and account issues while ensuring users are directed to the appropriate OITS support team.


Policy

Account Status

Student Accounts

Student accounts are designed to remain active throughout the student's lifecycle.

Student accounts are not disabled due to inactivity or lack of enrollment. Student accounts are only disabled under the following circumstances:

  • The account has never been claimed.
  • The account has been disabled due to a security incident or suspected compromise.

Students who are no longer enrolled may retain their account in accordance with university account lifecycle policies.


Faculty and Staff Accounts

Faculty and staff accounts are disabled when employment ends or when required by university policy.

Accounts may also be disabled if they are determined to be compromised or present a security risk.


Initial Troubleshooting

Before escalating an account issue, review the user's account using the following tools.

Texan Lookup

Texan Lookup should be the first resource used when troubleshooting authentication issues.

Information available includes:

  • Account status (Enabled/Disabled)
  • Claim status (Students and Student Workers only)
  • Password expiration
  • Microsoft Authenticator registration
  • Recent Azure sign-in activity
  • Required Information Security Awareness (ISA) training
  • Account restrictions

The More section provides additional information, including whether the user is currently restricted due to incomplete Information Security Awareness training.


Microsoft Entra ID

Microsoft Entra ID provides additional troubleshooting information including:

  • Sign-in logs
  • Audit logs
  • Group membership
  • Authentication methods
  • MFA registration
  • Account status
  • User attributes

Troubleshooting Process

Is the Account Disabled?

If Yes:

Determine whether:

  • The account has been disabled because of a security incident.
  • The employee has separated from the university.
  • The account has been administratively disabled by OITS.

Important: Student accounts are generally not disabled unless they are unclaimed or have been compromised.

Review recent sign-in activity for indications of compromise.

If compromise is suspected, assign the ticket to the Security Team.

If there is no indication of compromise, assign the ticket to Server Support.


Can the User Authenticate?

If the account is enabled but authentication fails:

Verify:

  • Information Security Awareness training is current.
  • MFA registration is valid.
  • The account is not restricted.
  • Password status.
  • Recent sign-in failures.

Users with overdue Information Security Awareness training may authenticate only to Tarleton SSO until the required training has been completed.


Information Security Awareness Restrictions

Users with overdue security awareness training are automatically restricted.

To verify this status:

  • Review Security Training Required within Texan Lookup.
  • Review Microsoft Entra ID group membership for:
    • SEC_NoSecurityTraining

Users must complete the required training before normal access is restored.


Student Workers

When assisting Student Workers:

Verify they are signing in using their Student Worker account and not their student account.

If authentication continues to fail:

  • Attempt an InPrivate or Incognito browser session.
  • Verify cached credentials are not being used.

Microsoft Authenticator Issues

If authentication problems appear related to MFA:

  • Verify the user's identity using standard verification procedures.
  • Reset Microsoft Authenticator registration.
  • Assist the user with re-registering their authentication methods.

Former Employees

Former employees no longer have access to university Active Directory accounts.

Former employees may continue to access Human Resources information through TAMUS Single Sign-On.

Password assistance for former employee accounts should be assigned to the Security Team.


Suspected Compromise

If an account is believed to be compromised:

  • Verify the user's identity.
  • Reset or re-register Microsoft Authenticator.
  • Review mailbox rules when appropriate.
  • Escalate the incident to the Security Team.

If email sending has been restricted by Microsoft, the Security Team is responsible for requesting removal of the restriction.


Email Sending Restrictions

Microsoft may temporarily restrict accounts that exceed sending limits.

Current university limits include:

Faculty and Staff

  • 500 recipients per hour
  • 1,000 recipients per day

Students

  • 50 recipients per hour
  • 150 recipients per day

Users requiring mass communications should utilize approved shared mailboxes or Emma, where applicable.

Accounts restricted for excessive email sending should be assigned to the Security Team.


Escalation Guide

Issue Escalate To
Account compromised Security Team
Suspicious sign-in activity Security Team
Restricted email sending Security Team
Employee termination questions Server Support
Disabled account (non-security) Server Support
Microsoft Authenticator issues

Service Desk / Security Team / Server Team

Information Security Awareness restriction Service Desk

Definitions

Texan Lookup

The university's identity lookup tool used to review account status, authentication information, claim status, and other identity-related information.

Microsoft Entra ID

Microsoft's cloud identity platform used for authentication, Microsoft 365 services, and identity management.

Claim Status

Indicates whether a student or Student Worker has completed the initial account claim process.

Information Security Awareness (ISA)

Required university security training that must be completed to maintain access to university resources.

Restricted Sender

A Microsoft-imposed restriction preventing an account from sending email due to excessive or suspicious email activity.

Details

Details

Article ID: 23105
Created
Mon 8/3/26 5:30 PM
Modified
Mon 8/3/26 5:30 PM