Educause Security Discussion mailing list archives

Re: Password Reset Policy?


From: Russell Fulton <r.fulton () AUCKLAND AC NZ>
Date: Sun, 19 Jan 2014 08:53:16 +1300

On 14/01/2014, at 9:24 am, Roger A Safian <r-safian () northwestern edu> wrote:

We have an annual password change requirement.  About 30 days prior to the password expiring you being to get 
messages reminding you of the date.  None the less, we still have people who don't do it, or forget their password 
after the change.  We do have a self service password change page, based on questions and a PIN.  If that fails you 
either need to come to our help desk with an ID OR have your department chair contact us on your behalf.  

We have a very similar arrangement and when we implemented the requirement we staggered the expiries so you don’t get 
everything expiring at once.

Russell


Current thread: