ÎçÒ¹¾ç³¡

Security Flagged users

Steps Required when User Is Security-Flagged

A user account may be security‑flagged when CUNY detects suspicious activity. In such cases, the accounts (CUNY and ÎçÒ¹¾ç³¡ accounts) are locked until the user resets their passwords, reconfigures MFA, and completes the required cybersecurity training.

When an account is security-flagged, the following steps must be completed in the order listed:
  1. Reset CUNYfirst account password
    This can be done by any method listed below
    • Self‑service by the user
    • Assistance from EdTech
    • In person at IT
  2. Reset CUNYfirst Multi‑Factor Authentication (MFA)
    MFA must be set up again using one of the following methods:
    • Self‑service by the user
    • Assistance from EdTech
    • In person at IT
  3. Complete Cybersecurity Training (CIS Requirement)
    • Users must log into Brightspace
    • Re‑take the Cybersecurity training
    • Provide the latest completion certificate as proof
  4. ÎçÒ¹¾ç³¡ Email Account
    • MFA must be set up again
    • Most users are familiar with this process and can complete it independently
  5. ÎçÒ¹¾ç³¡ Account Reset
    • This step can only be completed in person at IT
    • Proof of completed Cybersecurity training in Brightspace is required
  6. Zoom Account Access
    • Zoom access is dependent on the ÎçÒ¹¾ç³¡ account
    • Once the ÎçÒ¹¾ç³¡ account is restored, Zoom access is automatically reinstated
 

Important Note Upon Regaining Account Access

Once access to the account is restored, users should carefully review their CUNYfirst and email account to ensure there are no unauthorized or suspicious changes.

We recommend taking the following actions immediately:

  • Review all account settings for unfamiliar or incorrect changes.
  • Update any suspicious information right away (for example, recovery email addresses in CUNYfirst).
  • In Outlook, review Inbox Rules and remove anything that appears unusual or unexpected.
We have encountered cases where these details were altered without the user’s knowledge.