Learn about Sept. 1 changes to UCOP passwords
In its ongoing efforts to protect UCOP and employee data, ITS is taking steps to strengthen UCOP Active Directory (AD) passwords. The following enhancement to password filtering went into effect on Sept. 1, 2024. The next time you are prompted to update your AD password, the changes outlined below will apply.
What’s changing
ITS will be enabling Microsoft’s Entra Password Protection. This adds additional password filtering by detecting and blocking known weak passwords and their variants, or words and terms specific to UCOP; for example, university, UCOP, Oakland, etc.
What to expect
If you attempt to reset or change your password to something that is banned, one of the following messages will be displayed:
- “Unfortunately, your password contains a word, phrase or pattern that makes your password easily guessable. Please try again with a different password.”
- “We’ve seen that password too many times before. Choose something harder to guess.”
- “Choose a password that’s harder for people to guess.”
What’s staying the same
Our password requirements will stay the same:
- Passwords may not contain the user’s login account name (i.e. jdoe)
- Passwords may not contain all or part of a user’s full name (i.e. John Doe)
- Passwords must contain characters from three of the following five categories:
– Uppercase letters (A through Z)
– Lowercase letters (a through z)
– Numbers (0 through 9)
– Special characters
– Any Unicode character that is categorized as an alphabetic character but is not uppercase or lowercase. This includes Unicode characters from Asian languages.
How to change your password
If you use a UCOP-owned PC laptop, please log in to VPN prior to changing your password. Select the CTRL+ALT+DEL keys at the same time, then select “Change a password.” If you are a Mac user, please follow the instructions located in Box.
Password tips
Choosing a strong, memorable password can be challenging. Below are some tips to aid in choosing a strong password.
- Avoid using common words or phrases.
- Avoid using the names of significant people in your life.
- Avoid using birthdays or other significant dates.
- Chose a password that is significantly different from your previous passwords.
- Use different passwords for different sites/services.
- Use an online password checker to test the strength of your password, such as Last Pass.
Security tips
Keep the following reminders in mind:
- UCOP does not send passwords via text or insecure email.
- UCOP provides LastPass as a secure password manager for both business and personal/family use. For more information, visit LastPass Password Manager.
- UCOP will never ask you to provide your password for any reason.
Need help?
If you have problems changing your password or are locked out of your computer, contact the Service Desk at servicedesk@ucop.edu or 510-987-0457.
Tags: ITS, passwords