IIQ: Using Yellow Flags (ETS Internal)

Summary

This article explains what a yellow flag on a customer's identity record in IIQ means and what technicians are responsible for doing if they see suspicious activity for that customer. This article is for USNH Client Services (Help Desk) Technicians and Collegis Technicians working in partnership with the USNH Help Desk.

Body

Summary

This article explains what a yellow flag on a customer's identity record in IIQ means and what technicians are responsible for doing if they see suspicious activity for that customer. Applying a yellow flag to a user’s account is a proactive measure to enhance security and protect user data. By following the criteria and procedures outlined in this document, tech support agents can effectively identify and respond to potential security threats. This article is for USNH Client Services (Help Desk) Technicians and Collegis Technicians working in partnership with the USNH Help Desk.

 

What a Yellow Flag Means

A Yellow Flag signifies a Risky User. There may have been suspicious activity on or potential security concerns with their account. The Yellow Flag serves as a warning to tech support agents to proceed with caution and perform additional verification steps before providing account-related information or assistance.

If the flag is being added by a technician, then it also signals the potential need for escalation to the cybersecurity team for further investigation.

A Yellow Flag appears as a yellow banner in the AD Account Status attribute section of flagged user record in IIQ.  There is added information provided in the colored banner about why the flag was applied to that user at that time. To see when the flag was applied, as well as any past flag activity for this user, click the "Flag History" button.

flag history

 

If the person's identity is already flagged with a red or yellow flag, then they MUST present a government-issued photo ID in person or on video with the on-site USNH team in order to regain normal access to their account.

When you see a yellow flag, please be alert and careful.  If the caller is only asking for generalized help with how to do something non-account or security related, then the yellow flag has little impact.  But if they are trying to gain information or make changes to ANYTHING account related, or if you have any feeling that things are "off" or suspicious in any way, then be very cautious.

Back to top

 

Criteria for Applying a Yellow Flag

Important: If you have any security questions or concerns during your interaction with the customer, please work with your supervisor during the call or interaction, to be sure we are all protecting the security of both the user's and the institutions' data and assets.

In working with the customer, if you observe suspicious activities or have reason to suspect something may be wrong, then you may decide to flag that identity record as a Yellow Flag - Risky User

Document ALL findings in the ticket, whether benign or suspicious, so others can see all the criteria you reviewed and what you found for each item.

Instructions (Items 1-3 may happen in any order)

Item 1Cross-check recent account activities with the user to confirm their legitimacy.

  • Document the user's stated activities in the ticket.

Item 2 - Review the user's account settings for any unauthorized changes. 

  • Review and confirm Microsoft account Security Info (MFA and password reset methods).
  • Check for unauthorized email Rules or other email changes.
  • Document the results of their reviews in the ticket.

Item 3 - Review the criteria listed below using the tools available to you. Document your findings in the ticket.

Step 4 - Decide in consultation with your supervisor whether to flag the user's account as a Yellow Flag - Risky User or not.

 

In IIQ (VPN required)

IIQ Flag History

  • The Flag History button on the user's record in IIQ shows a prior history of security flags. Read the Details to see when and why the flags were set or cleared.

AD Account Locked

 

In Azure/Entra (PIM required)

Sign-in Logs – Watch for changes to the user's normal patterns. 

  • Status – Some failures are normal. Watch for unusual failures – e.g. many failures, clustered in time, from significantly different IP addresses, etc.
  • Location – VPN or ISP servers may mask their true location. Watch for locations that are unusual for this user, in context of their physical location at the time, or multiple logins from different locations within a short timeframe.
  • Application – Watch for significant deviations from the user’s normal behavior, such as accessing unfamiliar or restricted resources.
  • Date / Time stamps – Can adjust filter to longer if need be.  Option for Custom time internal useful if "Last 7 days" is too much.  May have to "Load More" if list becomes too long. Watch for logins occurring at unusual hours, inconsistent with the user’s regular login patterns.

Audit Logs – Watch for changes to the user's normal patterns

  • Unexpected changes to account settings, such as password resets, email address changes, or MFA device changes.

Devices – Watch for unexpected changes

  • Logins from new or unrecognized devices, particularly if the device type or IP address (under Sign-in Logs) is significantly different, or newly registered devices, especially if the customer is not aware of them

 

In Exchange Admin Center

Mesage Trace – Watch for Email Spam Activity, such as their email account sending out large volumes of emails or their emails being flagged as spam.

 

Other Activities

If you are told about or experience any of these suspicious activities, consider setting a yellow flag on the user's record.

Report from Others

  • Security Alerts – automated security alerts triggered by unusual activity, such as firewall logs, intrusion detection systems, or antivirus software.
  • Spam or phishing – Reports from other users about receiving unusual communications or phishing attempts from the customer's account.

Failure to Verify Identity

Back to top

 

Procedure for Applying a Yellow Flag

Task: To set a Yellow Flag on a user's identity record in IIQ

Follow these instructions if you have identified suspicious activity on the user's account based on the criteria above and in consultation with your supervisor. You should already be looking at their IIQ record and have reviewed their Flag History.

Instructions

Step 1 – Advise the user to change their password. Document in the ticket.

Step 2 – Remove any Microsoft security authentication methods that are suspicious or unfamiliar to the user.  You may do this yourself in Azure/Entra or walk the user through removing them through their Microsoft account Security info tile. Document in the ticket.

Step 3 – In the user's record in IIQ, click on the "Flag User" button in the button bar. 

Note: Help Desk and Collegis Technicians will only see this button if there is no current security flag set.  Supervisors will see this button on all identity records. 

Step 4 – In the Flag User IIQ dialog, choose "Yellow Flag – Risky User" from the Set Flag Account Status drop-down list.

Step 5REQUIRED – Fill in the Notes field.  Document the reason for the flag, detailing the specific suspicious activities observed. Include date & time of the suspicious activities and how you were interacting with them (on the phone, via video call, in person, etc.).

Step 6 – Click the "Update" button.

Step 7 – Document that you set a Yellow Flag on the user's record in IIQ. Include a copy of the Notes from the Yellow Flag in the ticket.

  • USNH Techs – assign the ticket as your supervisor advises and post the user's name and ticket number in the "Client Services Team Chat" so the entire team is aware.
  • Collegis Techs – escalate all Yellow Flag tickets to the USNH on-site team through the usual channels.

 

Outcome

The user's identity record in IIQ displays the Yellow Flag banner. The Flag History shows the username of the technician who set the yellow flag along with the date/time stamp and Details from the Notes field of the submission. The ticket documenting the decision to set the Yellow Flag has been assigned or escalated for review.

Back to top

 

Next Steps

After flagging the account, the next steps include monitoring the flagged account for further suspicious activity and escalating the case to the cybersecurity team if necessary. The user should also be advised to take steps to secure their account.

 

What do we tell the customer?

Inform the customer that their account has been flagged due to suspicious activities. Explain the need for additional security measures, such as changing their password and reviewing their account settings. Emphasize the importance of verifying any unusual activities with them.

 

How do they make the situation better?

The customer should change their password. They should review and verify their Multi-Factor Authentication (MFA) methods to ensure no unauthorized changes have been made. They should also be vigilant in monitoring their account for any further suspicious activities.

 

How long should a Yellow Flag remain in place?

A Yellow Flag should remain in place until the suspicious activities have been thoroughly investigated and the account is confirmed to be secure. The duration can vary depending on the severity of the activities and the outcome of the investigation.

 

Who reviews them? What is the process for that?

The review process typically involves supervisors or cybersecurity personnel. They review the flagged account, check the details provided in the Flag History, and assess whether the flag can be removed or if further action is needed.

 

What is the process for supervisors to remove a yellow or red flag?

Supervisors, IAM Accounts, and/or Cybersecurity must thoroughly review the Flag History, verify that all issues have been resolved, and confirm that the account is secure. If all criteria are met, they can remove the flag by accessing the user's IIQ record and updating the Flag Account Status. Documentation of the decision to remove the flag should also be included.

 

What are the criteria for supervisors to remove flags?

Criteria for removing flags include:

  • Confirmation that the suspicious activities were either resolved or determined to be non-malicious.
  • Verification that the user has taken recommended security measures, such as changing passwords and reviewing and confirming MFA methods.
  • Assurance that no further suspicious activity has been observed for a reasonable period.

Back to top

 

Need additional help?

If you have questions or need additional help with these topics, please reach out to your Team Lead or supervisor for assistance.

The Group: ET&S CN - IAM Identity & Access Systems owns the IIQ tool.

Details

Details

Article ID: 4990
Created
Mon 8/19/24 9:28 AM
Modified
Thu 6/18/26 10:36 AM
Applicable Institution(s):
Keene State College (KSC)
Plymouth State University (PSU)
University of New Hampshire (UNH)
USNH System Office