Body
Policy Statement
Innovative Technology Solutions (OITS) provides identity and authentication services for faculty, staff, students, and affiliated users. This article provides guidance for troubleshooting common account-related issues and identifying the appropriate escalation path.
Reason for Policy
The purpose of this article is to provide a consistent process for diagnosing authentication and account issues while ensuring users are directed to the appropriate OITS support team.
Policy
Account Status
Student Accounts
Student accounts are designed to remain active throughout the student's lifecycle.
Student accounts are not disabled due to inactivity or lack of enrollment. Student accounts are only disabled under the following circumstances:
- The account has never been claimed.
- The account has been disabled due to a security incident or suspected compromise.
Students who are no longer enrolled may retain their account in accordance with university account lifecycle policies.
Faculty and Staff Accounts
Faculty and staff accounts are disabled when employment ends or when required by university policy.
Accounts may also be disabled if they are determined to be compromised or present a security risk.
Initial Troubleshooting
Before escalating an account issue, review the user's account using the following tools.
Texan Lookup
Texan Lookup should be the first resource used when troubleshooting authentication issues.
Information available includes:
- Account status (Enabled/Disabled)
- Claim status (Students and Student Workers only)
- Password expiration
- Microsoft Authenticator registration
- Recent Azure sign-in activity
- Required Information Security Awareness (ISA) training
- Account restrictions
The More section provides additional information, including whether the user is currently restricted due to incomplete Information Security Awareness training.
Microsoft Entra ID
Microsoft Entra ID provides additional troubleshooting information including:
- Sign-in logs
- Audit logs
- Group membership
- Authentication methods
- MFA registration
- Account status
- User attributes
Troubleshooting Process
Is the Account Disabled?
If Yes:
Determine whether:
- The account has been disabled because of a security incident.
- The employee has separated from the university.
- The account has been administratively disabled by OITS.
Important: Student accounts are generally not disabled unless they are unclaimed or have been compromised.
Review recent sign-in activity for indications of compromise.
If compromise is suspected, assign the ticket to the Security Team.
If there is no indication of compromise, assign the ticket to Server Support.
Can the User Authenticate?
If the account is enabled but authentication fails:
Verify:
- Information Security Awareness training is current.
- MFA registration is valid.
- The account is not restricted.
- Password status.
- Recent sign-in failures.
Users with overdue Information Security Awareness training may authenticate only to Tarleton SSO until the required training has been completed.
Information Security Awareness Restrictions
Users with overdue security awareness training are automatically restricted.
To verify this status:
- Review Security Training Required within Texan Lookup.
- Review Microsoft Entra ID group membership for:
Users must complete the required training before normal access is restored.
Student Workers
When assisting Student Workers:
Verify they are signing in using their Student Worker account and not their student account.
If authentication continues to fail:
- Attempt an InPrivate or Incognito browser session.
- Verify cached credentials are not being used.
Microsoft Authenticator Issues
If authentication problems appear related to MFA:
- Verify the user's identity using standard verification procedures.
- Reset Microsoft Authenticator registration.
- Assist the user with re-registering their authentication methods.
Former Employees
Former employees no longer have access to university Active Directory accounts.
Former employees may continue to access Human Resources information through TAMUS Single Sign-On.
Password assistance for former employee accounts should be assigned to the Security Team.
Suspected Compromise
If an account is believed to be compromised:
- Verify the user's identity.
- Reset or re-register Microsoft Authenticator.
- Review mailbox rules when appropriate.
- Escalate the incident to the Security Team.
If email sending has been restricted by Microsoft, the Security Team is responsible for requesting removal of the restriction.
Email Sending Restrictions
Microsoft may temporarily restrict accounts that exceed sending limits.
Current university limits include:
Faculty and Staff
- 500 recipients per hour
- 1,000 recipients per day
Students
- 50 recipients per hour
- 150 recipients per day
Users requiring mass communications should utilize approved shared mailboxes or Emma, where applicable.
Accounts restricted for excessive email sending should be assigned to the Security Team.
Escalation Guide
| Issue |
Escalate To |
| Account compromised |
Security Team |
| Suspicious sign-in activity |
Security Team |
| Restricted email sending |
Security Team |
| Employee termination questions |
Server Support |
| Disabled account (non-security) |
Server Support |
| Microsoft Authenticator issues |
Service Desk / Security Team / Server Team
|
| Information Security Awareness restriction |
Service Desk |
Definitions
Texan Lookup
The university's identity lookup tool used to review account status, authentication information, claim status, and other identity-related information.
Microsoft Entra ID
Microsoft's cloud identity platform used for authentication, Microsoft 365 services, and identity management.
Claim Status
Indicates whether a student or Student Worker has completed the initial account claim process.
Information Security Awareness (ISA)
Required university security training that must be completed to maintain access to university resources.
Restricted Sender
A Microsoft-imposed restriction preventing an account from sending email due to excessive or suspicious email activity.