Are you using the Administration Process feature? If so, some investigation should be done to find out why it is failing. There could be any number of reasons -- too many to mention here.
Meanwhile, you can manually re-certify a user's ID if you have access to the CERT.ID (and its password) and an admin client (look in the Tools menu on the Configuration tab).
If this user was registered with an OU cert ID, then you would use the OU cert ID instead of the primary CERT.ID to recertify the expired user ID. For example, if the user's name is John Doe/Sales/Acme, then you would use the SALES.ID when prompted for the certifier.
The procedure is easy and quick to do, assuming you are in a position to have rights to use the certifier ID(s).