Start with the account’s current status and sign-in method. Resetting a password does not bypass deactivation, required single sign-on (SSO), or multi-factor authentication (MFA).
Invitation and Account Problems
| Symptom | Likely cause | Action |
|---|---|---|
| The invitation has expired | Invitation links last seven days. | Ask an Owner or Administrator to resend it. Use the newest link; resending invalidates the previous one. |
| An old link no longer works | The invitation was resent or revoked. | Use the latest invitation, or ask an administrator to check whether the pending record was revoked. |
| You cannot sign in after deactivation | Deactivated accounts cannot use password sign-in or SSO. | Ask an authorized administrator to review and reactivate the account if access should be restored. |
| A new invitation is rejected | That email address already has an account or invitation. | An administrator should find the existing record and resend or reactivate it as appropriate. |
| SSO invitation acceptance fails | The provider email does not match the invited email. | Ask the provider administrator to check the email sent as NameID against the invitation. Capitalization is ignored. |
An expired invitation remains Invited, with a separate Expired invitation indicator. It does not become Deactivated.
Related guides: Invite Your First Users; Manage Users.
Password Problems
| Symptom | Cause or check | Action |
|---|---|---|
| Password sign-in is temporarily blocked | Five consecutive failed password attempts trigger a 15-minute block. | Wait for the block to end. Administrators cannot manually unlock the account. SSO is unaffected. |
| The password reset link fails | It may have expired, been used, or been replaced. | Request a new link. Links expire after 30 minutes and can be used once; a new request invalidates the previous link. |
| You never created a password | You may have used only SSO before it was disabled. | Use Forgot password to set a password. Meet current local MFA requirements at sign-in. |
Reset Your Password
- On the sign-in screen, enter your Email address and select Forgot password.
- Select Send reset link.
- Open the newest reset email before its 30-minute expiry.
- Enter and confirm a new password of 12–128 characters, then select Reset password.
- Return to sign-in and complete any required MFA challenge.
There is no required mix of character types. A password reset does not reset MFA, reactivate an account, or remove the requirement to use SSO.
Required SSO
When your organization requires SSO, Members and Administrators must select Continue with SSO. Owners can still sign in with a password and local MFA for recovery.
SSO and MFA Problems
| Symptom | Action |
|---|---|
| SSO succeeds at the provider but Northstar access fails | Ask an administrator to check for an Active account or valid invitation and a matching email. SSO does not create or reactivate accounts. |
| The identity provider is unavailable | Ask an Owner to investigate. Owners can use their password and local MFA; Members and Administrators cannot bypass required SSO with a password reset. |
| Your authenticator is unavailable | Select Use a recovery code and enter an unused code. Each recovery code works once. |
| You have no authenticator or recovery code | Ask an authorized administrator to reset local MFA. Owners can reset other users; Administrators can reset other Members only. |
| You are the sole Owner with no recovery method | Contact Northstar support. Support identity verification is outside this fictional sample; no automatic recovery is promised. |
| MFA fails during provider sign-in | Contact your identity-provider administrator. A Northstar MFA reset does not reset provider MFA. |
Information to Give Your Administrator
Provide the affected account email, the sign-in method, the approximate time in UTC, and the message shown. Do not send passwords, authenticator setup keys, or recovery codes.
Owners and Administrators can use Activity reports to review recorded sign-in successes and failures. Unknown identities appear as Unknown user; the report does not expose attempted email addresses.
Related guides: Configure SSO; Configure MFA; Generate Activity Reports.
