Directory is the account management console. It is where most access tickets are solved: lockouts, password resets, group membership, licences and MFA.

Open it from Tools, under Infrastructure.

Find a user

Type into Search users… and select the person from the list. Their record opens with five tabs: Profile, Groups, Licenses, Devices and Authentication.

Profile holds the identity details: Username, Display Name, Email, Department, Title, Phone and Manager. Change Name & Email edits them.

Devices holds Computer Name, Last Login and the Drive Encryption Recovery Key. Computer Name is the field you want when a ticket sends you to Remote Desktop next, since it tells you which machine to connect to.

What you can do to an account

The Actions area on the Authentication tab carries:

  • Reset Password
  • Unlock Account, or Lock Account depending on the current state
  • Enable Account, or Disable Account
  • Reset MFA
  • Delete User, only on accounts you created yourself

Each confirms in place, for example Account unlocked. or MFA reset. The user will be prompted to re-enroll at next sign-in.

Groups and licences are handled on their own tabs rather than as buttons here. On Groups, pick from Add to group… and select Add, or use Remove on a row. On Licenses, pick from Assign license… and select Assign, again with Remove to take one away. Both removals ask you to confirm.

New User creates an account from the main directory list.

If you reset MFA on somebody who never enrolled, you get This user has no MFA enrolled, so there is nothing to reset. That is information, not an error.

Verify identity before you reset anything

This is the part that catches people out. Before you reset a password or MFA, confirm the person asking is who they claim to be. Use the Identity Verification section:

  1. Select Send Verification Code. On account-lockout tickets the same control reads Send Code to Phone (not Company Chat), which is the point either way: the code goes to the number on the account, not to whoever is messaging you.
  2. You will see Code sent to the user’s name and registered phone.
  3. Ask the user for the code and enter it.

Skip this and you get Password/MFA reset performed before identity verification — procedure violation (-10 pts). Verify the user first.

Two details worth knowing:

  • Only the most recent code is valid. Codes from earlier sends expire, and a failed attempt reminds you of that.
  • On the social-engineering tickets, resends are capped at three. Everywhere else you can keep sending a genuine requester a fresh code.

An unlock or a reset handed to the wrong person is the whole point of the security tickets in the queue, so it is worth building the habit here.

Locked-out users cannot reply in chat

If somebody is locked out of their account, they cannot answer you in Company Chat either. The app says so, naming them: … is locked out of their account, so they can’t reply on Company Chat.

For those tickets you either call the person, or send the temporary password to their manager to pass on. The ticket shows a banner with both options when it applies.