|
New Password Security Implementation
by Tom Cherubino, Director Information Technologies Dept.
A new Windows computer account password must be selected by each user, as part of the password security conversion process.
Each faculty/staff member will be individually contacted when their Windows computer account is scheduled for conversion to the new password system.
All Windows computer account passwords must abide by the following six "best practices" password rules:
1- Minimum password length: 8 characters
- Note: The "space" and "underscore" special character symbols DO count towards the password length requirement.
2- Minimum password age: 7 days - Once you change your password, you cannot change it again for 7 days.
3- Maximum password age: 6 months - You are required to change your password every 6 months.
4- Password history: 5 previous - When changing your password, you cannot change it to any of your previous five passwords.
5- Account lockout: 6 attempts/30 minutes - After 6 unsuccessful login attempts in a row, the account is locked out for 30 minutes.
6- Password complexity:
- ALL passwords must contain at least 3 out of the following 4 password complexity rules:
a - At least one upper case character
b - At least one lower case character
c - At least one numeric character
d - At least one special character symbol (see table below)
- Note: The "space" and "underscore" special character symbols DO NOT count towards the special character requirement.
- For example, the following would be a valid password under the new system: I like cats!
-This password contains rules a, b, and d, from above. Therefore it complies with the required 3 out of 4 password complexity rules. This password has at least one upper case character, at least one lower case character, and at least one special character (exclamation point). It also complies with the minimum password length rule (at least 8 characters), because this password is 12 characters long.
- Another example of a valid password would be: Alaska44
-This password contains rules a, b, and c, from above. Therefore it complies with the required 3 out of 4 password complexity rules. This password has at least one upper case character, at least one lower case character, and at least one numeric character. It also complies with the minimum password length rule (at least 8 characters), because this password is 8 characters long.
The following table lists the 31 special character symbols that are valid for password use:
|