⚡ computertouchers

Bill the after-hours password reset, or do it in the morning

Single-user password resets can wait until morning unless a named job is stopped tonight or the client accepts the after-hours rate first.

The phone rings at 11:40 p.m. on a Sunday. A salesperson at a forty-person distributor you support wants a password reset that expired on Friday. They noticed because they wanted to read email from the couch before a customer call on Monday, and they called it an emergency while a television played behind them. Nobody else at the company is locked out, and both mail and the file server are answering. One person cannot read a thread that will still be sitting in the inbox at 8 a.m.

Most of the after-hours pages I have worked were this call. A real outage shows up sometimes, and so does a production line that cannot start a shift, but you usually get one expired password from someone who wants it fixed before they sleep. The agreement taught them to treat that as your problem. It says 24/7, or it says after-hours support, and it never names which problems are worth waking a person. The client heard "call anytime." The tech heard "answer, or the owner hears about a missed call on Monday." A year of that and you are running a free overnight desk for forgotten passwords. The client has learned that the number works.

Say the rate before you open the portal

A password reset for one user is a request. An emergency stops the business, or it stops someone whose work tonight cannot move to morning without a cost you can name. Payroll has to reach the bank before a 6 a.m. cutoff. The on-call provider at a clinic cannot open a chart. A line sits idle until someone signs into the control panel. Entra ID is down for the whole tenant, so nobody can reset a password at all. That salesperson does not belong on that list.

The caller is worried about a meeting, and the last shop they paid would have reset the password and gone back to bed. Bark at them and you can lose the agreement over a five-minute unlock. Take the ticket, tell them when it will be done, and tell them what tonight costs if they insist on tonight.

If the agreement bills after-hours time at time and a half with a one-hour minimum, say that before you open the admin portal. You can reset it tonight at the after-hours rate, one-hour minimum, or you can put a temporary password on the ticket before the 9 a.m. call and bill the daytime rate. Once that choice is spoken, most callers take the morning. The ones who still want it tonight can usually name a deadline, and the hour goes on the invoice.

Say it while they are on the phone. A line in the ticket the next afternoon lands after they have decided the bill is unfair. The tech who changes the password and mentions the rate later has given the work away. The client disputes the charge, you delete it to keep the account calm, and the tech sees you do it. After a few of those, nobody mentions the rate. The after-hours clause stops meaning anything.

The password is often fine

Ask what they are trying to open, and ask what the screen says, before you change a password. Plenty of these calls are a lockout after repeated bad guesses, a prompt still pointed at a phone they replaced in March, or the laptop refusing the password from the payroll site. Reset a password that was never wrong and they call back when the laptop still fails. The next half hour goes to the authenticator app, which they could have read to you at the start.

The laptop's location matters as much as the error text. A domain-joined machine in a hotel may not see a domain controller until they reach a VPN or get back to the office. If password writeback is not in place, a reset in Entra ID opens webmail and leaves the laptop on the old password. You used the after-hours call on a reset that did not let them work, and they are angrier than if you had put the ticket on the morning queue. Ask whether that laptop can see a domain controller before you touch the account.

Changing a sign-in prompt after hours is how a tired tech agrees to something they would refuse on a Tuesday morning. The caller says they are the owner and wants the prompt turned off, or pointed at a number they are reading aloud. Do not do that from the inbound call alone. Hang up and dial the mobile number stored on the account, or the number on the client contact sheet. If a known person does not answer, the change waits for morning. Making a real owner wait once is cheaper than a sign-in change for someone you have not verified. I have heard the Sunday message that came from a former employee who still had the after-hours number on an old invoice.

When you do reset the password, deliver the temporary one on a channel you already trust. Reading it on the callback is fine, and so is putting it on the ticket if they can already sign into the portal. A text to a number they dictated on the first call repeats the check you refused. If the account must set a new password at the next sign-in, tell them before you hang up. On a phone browser they miss that second prompt, fail it, lock the account again, and call back certain you mistyped the temporary password.

Self-service password reset in Entra ID covers this call when a person finished the setup. The user registered a method with someone sitting there, password writeback reaches the on-prem directory for domain laptops, and a normal user was tested rather than the admin account. If hardly any accounts have a method on file, self-service helps people who were already getting by. The owner never sat still for registration, and the bookkeeper has one PC and refused the phone prompt, so catch both of them on a daytime ticket while they are at the machine. New hires should leave onboarding with a method on the account. A welcome email that says IT always picks up works against you.

Give the on-call tech a list they can read

The person holding the phone should not invent the rule while the caller waits. Write it in the on-call note they already have open. Wake someone when Entra ID is down for the company, when a named job with a same-night deadline is blocked, or when a contact on the escalation list wants the reset and accepts the after-hours rate before you click anything. Other password requests get a ticket and a morning owner.

Shared mailboxes, vendor portals, the copier admin password, and personal email can wait until morning. So can a new number on a sign-in prompt, unless the callback worked and they already accepted the rate. A password that expired on a known date can wait too. The change prompts sat on screen for two weeks, and they dismissed them until sign-in failed. That is weekday work that showed up on Sunday.

Notice which calls you answer without billing. The on-call tech would rather reset the password than argue, so the time never hits an invoice, and people at the client tell each other that someone answers at night. The salesperson tries again next month, a coworker tries an hour later, and the senior holding the phone either leaves or stops answering. Then a line is down on a Saturday and the number rings out.

At the quarterly review, put the after-hours tickets on the table and skip the speech. Pull out the single-account password resets and show the hours billed for them. If you billed nothing, show a zero. Note which of those users had no self-service method on the account. Offer to turn the feature on and register the people who skipped it. Keep the night number for work that has stopped. If they want every password reset inside the monthly fee at any hour, put a cap in the agreement and the after-hours rate after the cap. An unlimited block of overnight password resets inside a flat fee is how that forty-person contract uses up a weekend a tech was supposed to have off.

Use this wording in the welcome note and in the agreement, so the on-call tech can read it back. "If you are the only person locked out and the business is still running, open a ticket and the reset will be done in the morning. If you want it tonight, the after-hours rate applies, and we confirm who you are by calling a number already on the account."