Iru Web Login Outage

Incident Report for UAA IT Services

Resolved

IRU Authentication Outage

Problem Impact Analysis

Event Occurrence: 20260803

Background

The IRU authentication service provides user authentication capabilities for managed macOS devices and web-based access through Kandji Passport. The service relies on integration between Kandji Passport, Microsoft Entra ID, Conditional Access policies, and Duo MFA to provide secure authentication for users.

Break Down of the Problem

On August 3, 2026, users experienced authentication issues when attempting to access IRU services. The issue affected users attempting to authenticate through Kandji Passport Web Login and impacted the ability to complete the login process.

The issue was investigated through Entra ID sign-in logs, Conditional Access policies, Duo MFA authentication flow, and Kandji Passport authentication services.

Target State / Goal

A functional authentication into IRU-managed macOS devices.

Root Cause Analysis

Changes to Microsoft’s Conditional Access methods, effective as of Jun 15, 2026:

The changes outlined above now require DUO to be set as the default login method on a user’s account in M365.

Develop Countermeasures

Immediate countermeasure developed by adding users to Entra group that enabled the newer DUO authentication method.

Implementation of Countermeasures

IT staff completed a change that added all users to receive this fix.

Follow Up / Review

Regularly review progress of long term solution implementation.

Posted Sep 18, 2026 - 14:05 AKDT

Update

UAF NTS has resolved a recent issue caused by an unexpected change with Duo authentication that impacted managed macOS computer logins across campus.

If you use a university-managed Mac, your login experience is now restored to normal operations. However, the first time you log back into your computer following this fix, you may see one or two additional Duo authentication prompts.

When signing into your managed Mac for the first time today:
1. Enter your usual account credentials at the primary macOS login screen.
2. Complete the Duo prompt(s): You may be prompted to authenticate through Duo an extra time as system permissions refresh and re-sync with your account.
3. Approve the request on your Duo mobile app, hardware token, or via your preferred MFA method as normal.
4. Select Next at the Let’s keep your account secure prompt.
5. Select Next at the Set up a sign-in method prompt.

If you continue to encounter login errors, repeated prompts to sync passwords on login, or any other issues logging into your Mac, please reach out the Technical Support Center.
Posted Aug 03, 2026 - 15:46 AKDT

Monitoring

We have resolved a recent issue caused by an unexpected change with Duo authentication that impacted managed macOS computer logins across campus.

If you use a university-managed Mac, your login experience is now restored to normal operations. However, the first time you log back into your computer following this fix, you may see one or two additional Duo authentication prompts.

When signing into your managed Mac for the first time today:
1. Enter your usual account credentials at the primary macOS login screen.
2. Complete the Duo prompt(s): You may be prompted to authenticate through Duo an extra time as system permissions refresh and re-sync with your account.
3. Approve the request on your Duo mobile app, hardware token, or via your preferred MFA method as normal.
4. Select Next at the Let’s keep your account secure prompt.
5. Select Next at the Set up a sign-in method prompt.

If you continue to encounter login errors, repeated prompts to sync passwords on login, or any other issues logging into your Mac, please reach out to your campus IT Helpdesk.
Posted Aug 03, 2026 - 14:45 AKDT

Update

NTS TSS team is continuing to investigate the cause of this issues. There are no further updates at this time.

The Iru prompt to sync your passwords is safe to ignore as best that you are able while we investigate why it is being prompted.

If unable to log into your UA Mac, they try switching to Local login. To switch to local login:

1. Click the profile icon (the person inside a circle) in the upper-right corner of the screen.
2. Select Switch to Local Login.
3. Enter your University login credentials in the username and password fields that appear near the bottom center of the screen.
4. Click Sign In to log in.
If you are still unable to log in, please contact your local IT Help Desk for further assistance.

Thank you for your continued patience as we work towards a full resolution; we will make further updates at 1 hour intervals and as new information becomes available.
Posted Aug 03, 2026 - 11:45 AKDT

Update

UAF NTS TSS team is currently investigating the cause of this issue.

The Iru prompt to sync your passwords is safe to ignore as best that you are able while we investigate why it is being prompted.

If unable to log into your UAA Mac, then try switching to Local login. To switch to local login:

1. Click the profile icon (the person inside a circle) in the upper-right corner of the screen.
2. Select Switch to Local Login.
3. Enter your University login credentials in the username and password fields that appear near the bottom center of the screen.
4. Click Sign In to log in.

If you are still unable to log in, please contact the UAA Technical Support Center for further assistance.

Thank you for your continued patience as we work towards a full resolution; we will make further updates at 3 hour intervals and as new information becomes available.
Posted Aug 03, 2026 - 10:30 AKDT

Update

We are continuing to investigate this issue.
Posted Aug 03, 2026 - 10:28 AKDT

Investigating

NTS TSS team is currently investigating the cause of this issues.

The Iru prompt to sync your passwords is safe to ignore as best that you are able while we investigate why it is being prompted.

If unable to log into your UA Mac, they try switching to Local login. To switch to local login:

1. Click the profile icon (the person inside a circle) in the upper-right corner of the screen.
2. Select Switch to Local Login.
3. Enter your University login credentials in the username and password fields that appear near the bottom center of the screen.
4. Click Sign In to log in.
If you are still unable to log in, please contact your local IT Help Desk for further assistance.

Thank you for your continued patience as we work towards a full resolution; we will make further updates at 3 hour intervals and as new information becomes available.
Posted Aug 03, 2026 - 10:15 AKDT
This incident affected: Other IT Services.