麻豆精品

麻豆精品 Account and Password Guidelines

Purpose

These guidelines specify 麻豆精品-N account and password usage requirements. Please see the Acceptable Use Guidelines for the definition of 麻豆精品-N.

Overview

An 麻豆精品-N account is both a part of, and a key to, resources encompassed by 麻豆精品-N, and is covered by the Acceptable Use Guidelines. The granting of an 麻豆精品-N account is a privilege that carries with it numerous responsibilities, not the least of which is maintaining the security of 麻豆精品-N.

Scope

These guidelines apply to all 麻豆精品-N accounts. This includes but is not limited to

  • all categories of employee accounts (such as faculty, instructors, staff, extra help, temporary, contract, civil service, SPS etc),
  • all categories of student accounts,
  • all categories of student employee accounts,
  • all categories of accounts used for training, or in labs
  • all categories of sponsored accounts, and
  • all categories of accounts used directly by, or for the administration of, technology that compose 麻豆精品-N including but not limited to
    • application and software accounts
    • automation and service accounts
    • device and hardware accounts
    • third party support accounts

Guidelines

No Default Logins or Passwords

It is prohibited to use a default login and password combination with any application, system, or service. All default credentials delivered with an application, software, system, or service must be changed from the default, and must meet the elevated credential password requirements as described below.

No Password Re-Use

It is prohibited to re-use any password that provides access to any 麻豆精品-N account or resource, with any other account, system, service, or resource which requires authentication different from an individual’s official 麻豆精品-N account. This includes systems, applications, or services used for work duties or any personally consumed online services, applications, or games.

Third Party Support Account Access to 麻豆精品-N

It is prohibited for third party vendors, third party support, or contractors to have direct unsupervised access to 麻豆精品-N. All third-party access to 麻豆精品-N resources must be supervised by the employee responsible for the resource unless the entire resource resides outside of the 麻豆精品-N campus network and contains only public 麻豆精品 data, or no 麻豆精品 data.

Minimum Required Permissions for Accounts

In all cases where access or permissions are assigned to accounts for access to applications, data, or services, the minimum necessary permissions to achieve necessary outcomes should be assigned.

Minimum Password Complexity Requirements

All accounts must follow the minimum password complexity requirements defined by 麻豆精品 DoIT and found at password.niu.edu.

Passwordless Authentication

Passwordless authentication such as certificate, authenticator app, or biometric based authentication is permitted where supported, and in certain cases preferred.

Multifactor Authentication

All accounts assigned to individuals must have multifactor authentication enabled, configured, and enforced for use on 麻豆精品-N systems that contain non-public data. Use of the Microsoft Authenticator app for MFA is strongly recommended and may be required in certain instances.

Employee + Student

A student who is also an employee, or an employee who is also a student, will receive a Z-ID and an A-ID. That individual must use a different password for each account. The employee account is intended to be used exclusively for employment duties.

System Administration or Management Duties

An employee may have certain job duties that require elevated permissions in an application or system for administrative or system management purposes. Authentication to those systems should be integrated with 麻豆精品 DoIT’s central authentication, and those employees must be assigned a separate administrative account that is only to be used for system administration or management functions. That elevated account must have a different password from their normal user account and requires stricter password and account controls than 麻豆精品’s minimum requirements as defined by 麻豆精品 DoIT.

  • Such employees must request the separate elevated administrative account at 

Regulatory Duties

An employee may have certain job duties that fall under regulatory controls requiring the use of a separate account strictly for those regulatory duties. Those employees must be assigned a separate account that is only to be used for those regulatory duties, and that account must have a different password from their normal user account and may require stricter password and account controls than 麻豆精品’s minimum requirements as defined by 麻豆精品 DoIT.

  • Such employees must request the separate regulatory duties account at 

System and Software Accounts

All categories of “built in” local administration accounts, application, service, or automation accounts must have a password that is unique from any other 麻豆精品 account and requires stricter password and account controls than 麻豆精品’s minimum requirements as defined by 麻豆精品 DoIT. Those accounts should be integrated with 麻豆精品 DoIT’s central authentication and account management where possible and are not intended for direct employee use. Use of tools like Local Administrator Password Solution (LAPS), or use of managed service accounts or group managed service accounts shall be used when possible, for these types of accounts.

  • Such accounts must be requested at 

Contact Us

Division of Information Technology
815-753-8100
ServiceDesk@niu.edu