3.26 – Systems Password Policy and Procedure

All IESBVI personnel use Windows Active Directory accounts for access to school issued PCs, the network and printers, e-mail, and CRM student system. This includes off campus personnel. Account names follow the format of firstname.lastname. A password must be maintained for every account.

1.  Password Expiration

Personnel with access to sensitive data will be required to change their passwords every 90 days. This includes personnel with access to payroll, HR information, medical information and employee personally identifiable information such as SSI numbers.

All other personnel will be required to change their password every 180 days. This applies to the majority of faculty and staff.

Personnel who work on the Vinton campus or who are connected to the Vinton campus network (DOTS domain) by VPN will receive a 14-day warning that their password is about to expire. If the password is not changed within 14 days, it will expire, lock you out, and require a call Information to Information Technology for a password re-set. (This is Standard Microsoft Windows Protocol).

Personnel who are not connected to the Vinton Campus may not receive an automatic prompt, and should set calendar reminders to reset their password prior to expiration.

2.  Procedure for Resetting Password

The steps to reset your password depend on your location and your PC.

3.  On-Campus Personnel

While on the Vinton campus and connected to the network, passwords may be changed by pressing CTRL-ALT-DELETE from your school-issued computer, and entering the old and new password as prompted. This updates the password on the PC as well as for email, CRM, and network access. The new password becomes your new PC password for the next time you are off campus.

4.  Off-Campus Personnel with and IESBVI PC

Launch Cisco Systems VPN Client and connect to the IBS Vinton campus network. Then follow the directions above for on-campus personnel. Contact Information Technology if you do not have VPN.

5.  Off-Campus Personnel with an AEA PC

Your passwords may be changed by logging into Outlook Web Access, https://webmail.iabvi.org/owa and selecting Options, Change Password, and following the prompts. If your password has already expired, contact Information Technology to have it reset.

6.  Additional Password Reset Information

Multiple failed attempts to enter your password (6 times in a row or more) will result in an automatic 30 minute account lockout. The account will automatically unlock after 30 minutes.

Passwords are encrypted and cannot be looked up, they can only be reset. Passwords must be at least 8 characters, contain at least one upper case, lower case, and number or special character, not contain part of your username, not contain common words such as “password” and not be used for 12 months.

Approved 08/2013