Authentication & Authorization Policy FAQ
  1. What is the password expiration standard for Purdue?
  2. How do I determine my roles in the OnePurdue system?
  3. I have a mobile device that I am using to access my Purdue email account. Should I have a password on this device?
  4. Does Purdue policy allow me to use a password vault application to store my Purdue passwords?
  5. Why is the PIN expiration for the TFA token different from the regular password expiration period?
  6. How to I get a TFA Token?
  7. Are Group passwords subject to University policy?
  8. Are BIOS passwords subject to University policy?
  9. I have more questions about the Authentication and Authorization or wish to apply for a policy exception, who should I contact?
What is the password expiration standard for Purdue?

All University IT Resource passwords must be changed at least every 120 days. Faculty, staff, student-employees, and other affiliates having privileges elevated in excess of the base roles listed in the User Credentials Standard will be assigned a 30-day password expiration cycle in the OnePurdue System.  In no event will a password older than 120 days be usable for access of any type to any University IT Resources.

Authentication and Authorization Policy:  http://www.purdue.edu/policies/pages/information_technology/v_1_2.html

User Credentials Standard:  http://www.purdue.edu/securepurdue/bestPractices/passStandards.cfm

  Print  top Top

How do I determine my roles in the OnePurdue system?
Please see the ITAP knowledgebase article at https://help.itap.purdue.edu/onepurdue/viewarticle.php?articleid=2418

  Print  top Top

I have a mobile device that I am using to access my Purdue email account. Should I have a password on this device?

If you are accessing Purdue IT Resources, then the Authentication and Authorization policy and the related standards require that the device be password protected.  Purdue University employees should be sure that they are following the University Data Handling Guidelines when accessing or storing Purdue University data on a mobile device.

University Data Handling Guidelines:  http://www.itap.purdue.edu/security/procedures/dataHandling.cfm

  Print  top Top

Does Purdue policy allow me to use a password vault application to store my Purdue passwords?
The use of a password vault application to store your passwords is considered an acceptable secure storage mechanism for passwords and PINs. A review of several password vault applications (for Windows machines) is available from the SecurePurdue site at http://www.purdue.edu/securepurdue/pswdManager.cfm

  Print  top Top

Why is the PIN expiration for the TFA token different from the regular password expiration period?

Because a two-factor authentication (TFA) token requires two factors to authenticate you, something you know and something you have, it is a much stronger authentication method. Frequent PIN changes are not needed in this case.  The User Credentials Standard discusses PIN requirements.

User Credentials Standard:  http://www.purdue.edu/securepurdue/bestPractices/passStandards.cfm

  Print  top Top

How to I get a TFA Token?

The Identity and Access Management Office (IAMO) has launched a two-factor authentication project using the RSA SecurID® product. The pilot project is an exploration of ways to improve security for accessing the OnePurdue portal.   Information on the pilot project can be found at:  http://www.purdue.edu/securepurdue/careeraccount/token.cfm

Upon completion of the pilot project, the IAMO will assess the feasibility of providing TFA tokens to the university at large.

  Print  top Top

Are Group passwords subject to University policy?

Yes, the use of group passwords to University IT Resources is controlled by the Authentication and Authorization policy and related standards.  The use of group accounts should be minimized. Group accounts are subject to policy, and the password should be changed every 30 days and whenever there is a personnel change in the group.

User Credentials Standard:  http://www.purdue.edu/securepurdue/bestPractices/passStandards.cfm

  Print  top Top

Are BIOS passwords subject to University policy?

The Identity and Access Management Office (IAMO) recognizes that BIOS passwords may be difficult to change on a regular basis.  System administrators are encouraged to submit policy exception requests to the IAMO for BIOS passwords.

Security Policy Exception information:
http://www.purdue.edu/securepurdue/bestPractices/deviationProcedure.cfm 

  Print  top Top

I have more questions about the Authentication and Authorization or wish to apply for a policy exception, who should I contact?
Questions regarding the Authentication and Authorization policy and related standards are handled by the Identity and Access Management Office.  You can contact them at iamo@purdue.edu

  Print  top Top