Summary
This article provides information for Help Desk and Desktop technicians regarding the secured account process, both how accounts can be secured and how to assist a customer to recover their account access when the account has been secured. The Client Services part of this process takes place in the Help Desk IIQ system.
Note: Access to the Help Desk IIQ requires being on the Global Protect VPN with Enterprise permissions. It also requires being a member of one of the Help Desk AD groups. If you believe you should have access to Help Desk IIQ and are having trouble, please work with your Help Desk or Desktop Support Team Lead.
Overview
First, if an account appears compromised or if a user self-reports that they think their account may be compromised, then a Help Desk Team Lead (or M365 Admin, or IAM or Cybersecurity staff) can Secure the User’s account in IIQ. This article has detailed steps for HD Team Leads to secure a user's account below. Choosing to Secure a User triggers a script which:
- scrambles the user's password and “secures” the account in Enterprise AD,
- adds the user to the secured_accounts group in Azure AD,
- sends an email to the user's Personal Email notifying them, and
- creates a TDx ticket with notes if any were provided by the person securing the account.
At that point, the user cannot log into their accounts, though existing logins may remain active for some amount of time.
Second, while the account is secured this shows in Help Desk IIQ, with a red-labelled Secured row in the AD Account Status section on the Attributes tab. The Secured section includes the TDx ticket number, provide brief instructions, and point to this article for further details.
Third, when the user reaches out to the Help Desk, we must carefully verify their identity, then walk them through the process to recover their account. This article has detailed steps for HD Techs to help a customer recover their secured account below. Basically, we:
- Carefully verify the user’s identity in IIQ
- Pull up the TDx ticket shown in IIQ and discuss why the account was secured with the user.
- Use IIQ top button “Recover Secured User” to clear all secured attributes in AD for that account
- Walk user through resetting their password – use the process for “Forgot password” as they no longer have a working, current password.
- Complete the TDx ticket.
How-To
Task: To help a customer recover their secured account
Instructions
Step 1 – Search for the user in IIQ and open their identity record. You will see in the AD Account Status that they are Secured. These steps are only for users whose accounts say they are Secured.
Note: If you have a customer self-reporting or asking to have their account secured, work with you Help Desk Team Lead who can do this step. Once the account has been secured, then you can go through this process.
Step 2 – Verify their identity. Be extra diligent in this step since we know their account may have been compromised. See full instructions in article IIQ: Verifying Identity with ID Proofing (ETS Internal).
If you cannot do ID proofing or if the user is not able to do ID proofing successfully, STOP. The account should not be Unsecured and the user should be referred to in-person support.
Step 3 – Open the TDx ticket mentioned in the Secured section and read the stated reason the account was secured. The TDx ticket automatically closes after a week, but that doesn’t affect our ability to help the customer.
Important: Check for any special instructions – some tickets say that the Help Desk should NOT help them recover the account, usually if Cybersecurity needs to work with the user directly. So READ the ticket carefully and ask your Supervisor or Team Lead if you have any questions.
Step 4 – Discuss why the account was secured with the user. We hope they can understand what happened and, if it was something they did (like clicking on a phishing email), not do it again. If you hear anything concerning, like they had lots of personal information in their account, notify your supervisor to see if any extra steps may need to be taken.
Step 5 – When you are sure you should proceed, click the “Recover Secured User” button at the top of IIQ. You will be prompted with an “Are You Sure...?” confirmation dialog box with “No” and "Yes" options.

Step 6 – If you are sure, click Yes. Behind the scenes, it takes a few seconds for the system to remove the user from the secured_accounts group in Azure AD and to clear the secured attributes from their AD account. A confirmation Secured user Recovered box displays when the process is complete.

Step 7 – Walk the user through resetting their password using SSPR. Use the process for “Forgot password” as they no longer have a working, current password. See full instructions in our article on MyAccount: Resetting Your Password. Note: this is a public article; feel free to share with the customer.
Step 8 - Walk the user through re-adding their MFA methods. Their sign-in MFA methods were probably removed when their account was secured. Walk them through adding them in again.
Important: Be sure the customer is able to log into their resources before you end the interaction.
Step 9 – Complete the TDx ticket:
9.1 - Assign the ticket to HD Internal
9.2 - Confirm that the Requestor, Institution, and Role are correct. Edit the ticket if necessary to add/fix those or other information (such as phone number or alternate email address).
9.3 - Update the ticket with your notes about what you did and set the following:
- Status: Resolved at First Contact (or Closed if applicable)
- Resolution Action: Provided Account/Password Help
- Probable Cause: Account Secured
Outcome
The customer once again has access to their account with a new password. The related TDx ticket has been moved to HD Internal, updated with notes, and resolved.
Back to top
Task for HD Team Leads Only: To Secure a user’s account using IIQ
Instructions
This process begins when a customer notifies the Help Desk that either they responded to a phishing email or otherwise suspect their account has been compromised. In this situation, after the user’s identity has been verified, then a Help Desk Team Lead can follow these steps. Access to the "Secure User" button is controlled by AD group membership. If you believe you should have access to Secure User and are having trouble, please work with your Help Desk Team Lead.
Step 1 – Search for the user in IIQ and open their identity record. Confirm you are looking at the correct identity, then click the “Secure User” button in the IIQ top button bar.
Step 2 – You will see the Secure User dialog box. You must use the Select Reason drop-down to indicate why you are securing the account. Options are:
- Impossible Journey - when username is logging in from different parts of the world within impossibly short time frames. Sometimes mis-identified if customer is using VPN one one device and not on another at the same time from a distant locale.
- Other
- Phishing Attack
- Publicly Posted Credentials - our Cybersecurity team gets lists of credentials that are out in public and may secure people's accounts in response. Sometimes CyberOps may give the customer a chance to change their password first and only secure the account if the customer does not do so within the specified time frame.
- Sending Phish/Spam

Step 3 – You may also add notes in the Comments box. The comments are added to the TDx ticket created by the Power Shell (PS) script. This is optional, but recommended.

Step 4 – When you are sure, click the Secure button. Selecting “Secure” triggers the call to the PS script. It takes a few seconds for the script to return a result. If successful, a confirmation message with the TDx ticket number will display.

Step 5 – Click the “Refresh” link in the blue banner at the top right of the identity record to reload the data from AD.

In the AD Account Status section on the Attributes tab, the user’s account will now show as Secured.

Step 6 – You can now proceed to help the customer recover their account, following the instructions above.
Outcome
The customer's AD account has been Secured and their password scrambled. A TDx ticket has been created with the Comments you included when securing the account.
Back to top
Further Readings
IIQ: Verifying Identity with ID Proofing (ETS Internal)
IIQ: Viewing a User Identity Record (ETS Internal)
MyAccount: Resetting Your Password
Need Additional Help?
If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.
The Group: ET&S CN - IAM Identity & Access Systems owns the IIQ tool.