Summary
This article provides information on viewing user identity records using the Help Desk Interface in Sailpoint Identity IQ (IIQ). This article is meant to guide ET&S Help Desk staff and student workers through the screens. Sailpoint Identity IQ (IIQ) is the new identity management system for the unified University System of New Hampshire (USNH). It has been a long process to move from older, non-unified systems into IIQ. As of June 2023, Help Desk workers will be using IIQ instead of the older CAMP and APE systems.
Note: Access to the Help Desk IIQ requires being on the Enterprise VPN (Pulse Secure or Global Protect). It also requires being a member of one of the Help Desk AD groups. If you believe you should have access to Help Desk IIQ and are having trouble, please work with your Help Desk Team Lead.
HD IIQ Login Link - https://iiq.usnh.edu/identityiq
See also our article on Tips and Tricks for Finding Users in IIQ (ETS Internal)
Top "Viewing Identity" Banner
The banner at the top contains the following information:
Display Name (uses preferred names) – [username] – primary email address (if exists) – USNH ID Number (9-digit "9-number")

Back to top
Top Buttons
When viewing a user’s identity record, a series of buttons displays below the banner.

- Some buttons display for all users.
- Some buttons only display for certain users, depending on their present or past roles within USNH and what accounts they have access to.
- The order of the buttons may vary when looking at IIQ.
- Most buttons are display buttons which open a pop-up display of information about the user's accounts or access.
- A few buttons are action buttons. These open a pop-up confirmation which, if confirmed, will then perform an action on the user's accounts.
- Some action buttons are only available to HD Supervisors and certain other ET&S staff.
Below is a description of each of these buttons, presented in alphabetical order (not in IIQ display order):
Database Access
Displays for: All users.
- Button retrieves and displays information about the user’s enterprise database access (like the Accounts tab > Database Access section in CAMP).
- This table only displays databases the user has access to and will appear empty if the user has no current database access.
External Account Access
Displays for: All users.
- Button retrieves and displays information about certain account types (like the External Accounts section in CAMP).
- These are applications where access is manually tracked.
- This table only displays accounts the user has and will appear empty if the user has none of these applications.
- Current in scope applications:
- CRS
- Camera Access
- NextBus
- MasterCalendar
- UNHTV
- DegreeWorks
- UNHINFO
- UNH GIT Access
- AppExpress
- Elements
- DestinyOne
- myWildcat Success
- Tableau
- Little Forest
- CRM (Salesforce)
- TouchNet (ShopUNH)
- SalesforceCloud
- Bomgar/Beyond Trust
- myUNH Publisher
- Teacher Eval (Blue)
Jobs
Displays for: Users with an HR record.
- Button retrieves and displays both Active Jobs (if present) and Historical Jobs records (same as the Job History tab in CAMP).
- Entries are sorted in descending order of "Effective Date" (last column), newest on top.
- You can click on any of the column headers to sort by that data. Clicking again will reverse the sort order.

Notification History
Displays for: All users.
- Button retrieves and displays information about account claiming and password change notifications (like the Audit Trail > Notification History in CAMP).
- This data goes back to April 2023.
Password Log
Displays for: All users.
- Button retrieves and displays information about actions taken on a user’s account/password in CAMP or IIQ or by a script: securing, scrambling for an expired password, or recovering a secured account (like the Audit Trail > Password Log in CAMP).
- Important: this log does not include password changes initiated by the user.
- The majority of this data goes back to April 2023, though there may be some earlier dates visible.
Recover Secured User
Displays for: Users with a secured account.
Action Button
- When you click this button, you are prompted with a “Are You Sure...?” dialog box with "Yes" and "No" options.
- If you select "Yes", then the user is removed from the secured_accounts group in Azure and the AD secured attributes are cleared (in both Enterprise and Azure AD).
- A confirmation Secured user Recovered displays when complete.
- Then the user is permitted to and must set a new password to gain access to their account.
- If you select "No", then the dialog box closes with no further action.
Important: See full instructions in our ET&S Internal article on the Secured Account Process.
Role History
Displays for: All users.
- Button retrieves and displays information about USNH role changes (like the Audit Trail > Role History in CAMP).
- It provides a time stamp and lists which roles were added or removed at that time.
- Currently (as of June 2023), this data goes back to Jun 2022.

Secure User
Displays to HD Team Leads for: Any user with an Enterprise AD account.
Access to the "Secure User" button is controlled by AD group membership. If you believe you should have access to Secure User and are having trouble, please work with your Help Desk Team Lead.
Action Button
- See full instructions in detailed steps for HD Team Leads to secure a user's account.
- Briefly, choosing to Secure a User triggers a script which:
- scrambles the user's password and “secures” the account in Enterprise AD,
- adds the user to the secured_accounts group in Azure AD,
- sends an email to the user's Personal Email notifying them, and
- creates a TDx ticket with notes if any were provided by the person securing the account.
- At that point, the user cannot log into their accounts, though existing logins may remain active for some amount of time.
SIS Data
Displays for: Users with a record in UNH Banner, KSC Colleague, or (coming soon) PSU Banner.

- Selecting the button will show options for the SIS application(s) in which that user has a record.
- Selecting an application (UNH Banner or KSC Colleague) displays current student or applicant info, course registrations, or instructor information, if applicable (like what displays for UNH Banner on the UNH Student tab in CAMP).
- Empty sections mean there is no data of that type to display.
Sample UNH Banner information for faculty member brn1011

- The section for UNH Parent Account Information appears at the bottom of the UNH SIS data, but only if it contains information.
Sample UNH Banner information for incoming student bes1075

Unlock AD Account
Displays for: Any user with an Enterprise AD account.
Important: Display of this button does NOT mean the account is locked. Locked status is shown in the AD Account Status section of the identity record. See below.
Action Button
- When you click this button, you are prompted with a “Are You Sure...?” dialog box with "Yes" and "No" options.
- If you select "Yes", then the lockoutTime attribute in Active Directory is cleared, unlocking the account if it was locked.
- If you select "No", then the dialog box closes with no further action.
WebCat Reset
Displays for: Users with a record in UNH Banner.
Action Button
- When you click this button, you are prompted with a “Are You Sure...?” dialog box with "Yes" and "No" options.
- If you select "Yes", then the user’s security questions in WebCat are cleared (same as the WebCat Reset button in CAMP).
- If you select "No", then the dialog box closes with no further action.
WebRock Reset
Displays for: Users with a record in GSC Banner.
Action Button
- When you click this button, you are prompted with a “Are You Sure...?” dialog box with "Yes" and "No" options.
- If you select "Yes", then the user’s security questions in WebRock are cleared (same as the WebRock Reset button in CAMP).
- If you select "No", then the dialog box closes with no further action.
Back to top
Attributes Tab
Below the top buttons are two tabs: Attributes and Accounts.

Scroll down the Attributes tab to see the following sections:
AD Account Status Section
Displays for: Users with an Enterprise Active Directory (AD) account.
- This section loads information in real time from the Enterprise (on-prem) Active Directory.
- If this section is missing, then the user does not have an Enterprise AD Account.

- Account Status: Enabled or Disabled
- If Disabled, contact the IAM Team to find out why and whether they can refresh the user's account to re-enable it.
- Secured: This shows only if the user’s account is currently secured.
- Details as to when the account was secured, and the TD ticket number are provided.
- Lock Status: Unlocked or Locked with the lock time displayed in red.
- Password Last Set: Password Last Set date and time is displayed.
- If the last time the password was set, it was scrambled due to lack of change compliance, “Password Scrambled” will display in red along with the date and time. This means the user's password expired, so they will need to set a new one with the Password Reset process.
Example Locked AD Account with Password Scrambled

Example Secured AD Account

Biographic/Demographic Data Section
Displays for: All users.
At the top of this section, the following information lines always display (even if the data is blank/empty):
- USNH Roles
- Primary User Type
- Primary Campus – drives the user’s primary email address
- Privacy Flag – if Y, then user will not appear in the Global Address List or Teams chat list.
- USNH ID Number (9-digit 9-number)
Other attributes display if they are present:
- PSU ID Number
- Colleague ID Number
- Department
- Title
- Supervisor
Sponsored Data Section
Displays for: Users with historical Sponsored Role information in IIQ
- This section displays Sponsored Role Type, Role Status, Approval information, Effective date of the current role status, and the date the sponsored role Expires.
- Be sure to verify the user's active roles in the USNH Roles Field in the Biographic/Demographic Data Section above. This Sponsored Data section is likely to include Inactive entries that are part of the person's sponsored system record history in IIQ.
- The Approval Information data includes the date the request for sponsorship was approved, by whom or which office, and who requested the sponsorship.
- If this section is missing, then the user does not have any sponsored role history to display.
Source Data Fields Section
Displays for: All users.
- This section displays Names, Dates of Birth (DOB), Personal Email Addresses, Privacy Flags, and Physical Addresses, when present, under each of the different data sources (like the Banner/Colleague/Sponsored data included in the Person Details section in CAMP).
- Additionally, it displays all the user’s institutional email addresses.
- The primary email address, for their primary campus, is also displayed in the banner at the top of the page.

- If a data source column is empty, then there is no record for that user in that data source.
Back to top
Accounts Tab
Below the top buttons are two tabs: Attributes and Accounts.

The Accounts tab displays details of account types that the user holds and that IIQ aggregates/reads.
Example Accounts Tab for student mws1034:

By selecting any of the application names, details about the selected account are displayed. You can open the details for more than one application at a time.
Example of UNH Canvas Account for student mws1034:

Back to top
Non-Primary Accounts
Any non-primary accounts the user is owner of, or that have been assigned to the user, will show in addition to their primary "Enterprise AD" account. The account name for non-primary accounts begin with a prefix that corresponds to the type:
pl_ for Pool accounts
sy_ for Secondary accounts
svc_ for Service accounts
adm_ for Admin accounts
In this example, student mws1034 has a non-primary "Enterprise AD - Pool" account "pl_UNH_TNHNews01" assigned to them. You can also see the non-primary account type in the name of the OU right after the account name, in this example "OU=Pool".
Example of non-primary Pool Account "pl_UNH_TNHNews01" assigned to student mws1034:

The fully qualified username for a non-primary account is the AccountName@usnh.edu. In this example, it is: pl_UNH_TNHNews01@usnh.edu
Non-primary accounts use the same password change process as primary accounts (as of Aug. 1, 2023), just with the non-primary account fully qualified username instead.
Back to top
Data Refresh
Attributes tab
You are viewing the user's IIQ identity record data (which is where Biographic Data comes from) in real time. This includes name, USNH ID, and email address in the top banner and USNH Roles on the Attributes tab. Changes to this IIQ identity data can happen throughout the day as a result of a change in one of the authoritative source systems (HR/FIN, student systems, sponsored system).
IIQ reads from these authoritative source systems multiple times a day.
Click the Refresh link near the right end of the top "Viewing Identity" banner to re-load the current data from IIQ.
Accounts tab
How often the data updates on the Accounts tab depends on what process causes a change to the account. Some types of accounts and some types of account changes are managed by IIQ directly, others are not.
When IIQ makes a change to an account directly, those changes are displayed in real-time. For example, changes to Canvas, TeamDynamix, Kaltura, and Enterprise AD accounts display in real time. And name changes, email changes, or status changes (active/inactive, isstudent, isemployee, etc.) display in real time.
Changes made by non-IIQ processes for most account types are picked up once a day.
For Enterprise AD, IIQ picks up changes made by other processes hourly.
- Note: While IIQ manages many Enterprise AD attributes, many others are changed outside of IIQ – group memberships, lock status, password change date, etc.
For AzureAD, IIQ picks up changes every 4 hours.
Back to top
Further Readings
Accounts: Identity Verification SOP (ETS Internal)
IIQ: Overview of USNH User Roles & Types (ETS Internal)
IIQ: Finding Users in IIQ (ETS Internal)
IIQ: Secured Account Process (ETS Internal)
IIQ Login Link - https://iiq.usnh.edu/identityiq
Need additional help?
If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.
The Group: ET&S CN - IAM Identity & Access Systems owns the IIQ tool.