UTS Standard: Oakland Passwords

Overview 

This standard establishes the minimum password requirements for protecting Oakland University Information Resources. The requirements align with industry best practices and the National Institute of Standards and Technology (NIST) Special Publication 800-63, Revision 4.

Effective password management is essential to safeguarding the confidentiality, integrity, and availability of University Data and IT Resources.

Scope

This standard applies to all faculty, staff, students, post-docs, contractors, and third-party partners who access Oakland University systems, applications, and networks. It encompasses all authentication methods that use passwords, including but not limited to NetID, administrative systems, IT infrastructure, and research computing resources.

Standard

Oakland University uses access controls and other security measures to protect the confidentiality, integrity, and availability of IT resources and information assets. 

Non-compliance with this standard may result in disciplinary action, including suspension of access privileges.

Password Types

User Account (Faculty, Staff, Students, Post-Docs, Contractors, and Third-Party partners)

  • Minimum length: 12 characters
  • Composition: Up to 64 characters long, must include mixed case letters, numbers, or special characters.
  • Prohibited passwords: Compromised or publicly disclosed, commonly used, and easily guessable.
  • Password Reset: Not required unless:
    • Evidence of a compromise
    • Policy violation occurs,
    • To align with specific compliance standard such as PCI
    • If existing password fails to satisfy current standards
  • Reuse: Passwords used for University systems must not be used for non-University accounts.
  • Sharing/Storage: User account passwords must not be shared. Oakland University encourages the use of the enterprise password manager (faculty/staff).

Administrator Account (IT staff with elevated privileges, such as system administrators, network admins, or database admins)

  • Minimum length: 16 characters
  • Composition: Up to 64 characters long, must include mixed case letters, numbers, or special characters.
  • Prohibited passwords: Compromised or publicly disclosed, commonly used, and easily guessable.
  • Password Reset: Not required unless evidence of a compromise, policy violation, or based on risk assessment (e.g., personnel departure).
  • Reuse: Administrators must not reuse passwords across systems, particularly between administrative and regular user accounts.
  • Sharing/Storage: User specific admin accounts must not be shared. Generic admin accounts like "root" or "administrator" must only be stored and shared through an enterprise password manager.

Service Account (Non-human accounts used by applications or services)

  • Minimum length: 16 characters or more.
  • Composition: Must include mixed case letters, numbers, or special characters.
  • Password Reset: The modification to service-account passwords must be communicated in advance to all service and system owners impacted (per inventory below). Passwords must be stored and shared using an enterprise password manager. The standard, change-management process, i.e. scheduled time, fallback plan, etc. should be observed. 
  • Reuse: Must be unique and not reused across systems or applications for alternate purposes. (i.e. a database service account should be re-used for general scripting)
  • Sharing/Storage: Service account credentials must only be stored and shared through an enterprise password manager. 
  • Inventory: The Service Account creator\owner is responsible for keeping an inventory of account usage, including:
    • Systems or Applications where the account is utilized
    • Account usage (i.e. database connection, automation, etc.)

Enterprise Standards for Passwords:

Multi-Factor Authentication (MFA): Password authentication will be supported by a second factor for all user accounts and when accessing systems and applications that process or store sensitive data.

  • A second authentication factor is required for remote access to any system.
  • Supported methods: Multi-factor Authentication, tokens, and biometrics (Uses unique biological characteristics (fingerprint, face, iris) for identity verification.), etc.
  • Exception(s):
    • Accessing one’s own data.  
    • Systems that do not yet support SSO
      • Compensating controls for non SSO
      • Complex long passwords
      • Block common passwords
      • No password reuse 
      • Passwordless Authentication
      • Biometrics

Password Storage:

Passwords must be hashed using a suitable hashing scheme.

  • The System “save password” feature is disabled.

Visibility: 

Passwords must not be displayed in clear text when being typed.

Default Passwords:

Pre-installed authentication methods (e.g., passwords, certificates, keys, SNMP strings) are changed immediately following the installation of an IT Resource.  

  • Periodic audits must be performed to ensure default passwords are not reinstated (e.g., the result of a reboot or maintenance work). 

Reporting

Users and Administrators must immediately report any known or suspected compromised passwords or unauthorized access attempts.

Account Lock-out

User accounts will be locked out for 10 minutes after 10 failed login attempts.

Password Expiration

Password expiration may be enforced under the following conditions:

  • Security incident response.
  • Organizations may impose more stringent expiration requirements.
  • Other compliance requirements.

Password Resets:

  • Users will be trained on good password practices.
  • If an OU password has been compromised, the user must complete Security Awareness Training within seven (7) days to retain network/account access.
  • The self-service password reset mechanism may use security methods (e.g., MFA, token, biometrics) to verify the identity of the user requesting a password reset.

Incident Response for Compromised Credentials

The Information Security Office will respond to suspected or confirmed incidents involving compromised passwords or unauthorized access attempts.

  • Detected unauthorized access will result in account lockout and require a password change.
  • Incident response procedures, such as forensic analysis, containment, and mitigation measures, will be initiated when evidence of an administrator or service account is compromised.
  • Regular reviews and audits of administrator accounts will be conducted to identify security anomalies and respond to potential threats.
  • Logging and analysis of service account activities will be used to detect and respond to unauthorized or abnormal behaviors.

Roles and Responsibilities

Chief Information Officer

  • The Chief Information Officer is responsible for approving this standard

Chief Information Security Officer (CISO)

  • The Chief Information Security Officer is responsible for providing interpretation of this policy and other related policies, as well as disseminating relevant information.

Information Security Office (Identity Lead)

  • The Identity Lead, in partnership with other subject matter experts (SMEs), will review and update this standard annually to align with regulatory requirements and organizational changes. The Identity Lead will partner with the CISO and University stakeholders to support implementation and adoption of this standard.

Users

  • Must comply with this standard and protect their credentials
  • Must report suspected compromise immediately

Definitions

Capitalized terms used in this standard are defined in the UTS Standard: IT Terminology.

Related Documents, Forms, and Tools

Additional Support

  • OU Technology Center
  • 44 Oakland Center
  • Rochester, MI 48309-4479
  • Phone: (248) 370-4357
  • Email: support@oakland.edu
  • Office Hours: M-F 8:00am - 5:00pm

Last Modified: 4/20/2026
Authority:  CIO
Category: Standard
Status: Awaiting CIO approval