Carnegie Mellon University Website Home Page
 

Quick Links

New Requirements for Your Andrew Account Password

Requirements for your Andrew account password are changing.  Action is required by 9:00 a.m. on January 27, 2010. 

If you fail to change your Andrew account password, your current password will expire and you will NOT have access to services such as email, calendar, Carnegie Mellon Web Portal, etc.

Actions You Need to Take by 9:00 a.m. on January 27, 2010

  1. Before you change your Andrew account password, make sure your password is NOT saved within your email client.  Refer to the appropriate steps below for your client:
    • Outlook 2007 - Select Tools > Account Settings and then double-click your Andrew email account.  Confirm Remember Password is NOT checked.
    • Entourage 2008 - Select Tools > Accounts and then double-click your Andrew email account.  Confirm Save Password is NOT checked.
    Important Note for DSP Customers:
    • If you change your Andrew account password while on campus, log out and then log back into your laptop once your password has been changed.  It is important to do this before you disconnect the laptop from
      the campus network.
    • If you change your Andrew account password while off campus, use your old password to log into your laptop until you return to campus.
  2. Change your Andrew account password adhering to the following password requirements:
Must Contain
  • At least 8-characters.
  • At least one uppercase alphabetic character (e.g., A-Z).
  • At least one lowercase alphabetic character (e.g., a-z).
  • At least one number (e.g., 0-9).
  • At least one special character (e.g., ~!@#$%^&*()_-+=).
Cannot Contain
  • Known information (i.e., first name, last name, Andrew userID, date of birth, 9-digit Carnegie Mellon ID number, SSN, job title).
  • Four or more occurrences of the same character (e.g., aaaa, 2222, a123a345a678a).*
  • Spell a word that can be found in a standard dictionary.*

*This requirement does not apply to Andrew account passwords that are more than 19 characters in length (e.g., passphrase).

Additional Policies

  • Expires within one year.
  • Last five passwords cannot be used.
  • Cannot be changed more than four times in a day.
  1. If you use a mobile device (e.g., iPhone, Blackberry, Windows Mobile) to connect to your Andrew email, follow the appropriate Mobile Device Configuring Email steps to update your Andrew account password information. 

If You Need Help

For questions about this email or help changing your Andrew account password, contact the Computing Services Help Center (412-268-HELP or advisor@andrew.cmu.edu) or your departmental administrator or DSP consultant.  You may also refer to the Managing Your Andrew Account Password document.

Reason for This Change

Carnegie Mellon will join other universities, government organizations and companies as a member of the InCommon Federation.  Membership is an essential step in allowing Carnegie Mellon students, faculty and staff to use their Andrew userID and password to access services provided by other federation members.  Similarly, Carnegie Mellon will be able to offer reciprocal services to constituents of federation members.

The continued use of National Student Clearing House, Internet2 and TeraGrid are drivers for Carnegie Mellon to become a member of InCommon, but other efforts are already underway to extend membership and value of the InCommon federation. In particular, several U.S. government granting agencies (the National Science Foundation and National Institutes of Health chiefly among them) will likely adopt InCommon as the authentication mechanism for access to grant administration sites, which is of critical importance to the mission of our university.

Membership in a federation such as InCommon means abiding by a specific set of identity management practices.  To meet these compliance requirements, all Andrew account holders MUST create a new Andrew account password.

Last Updated: 11/23/09