Protecting Your UM Accounts: Best Practices

Doing your part to protect your UM accounts is essential to safeguard your personal information and UM’s data.


1. Use Strong Passphrases

  • Length matters. Your passphrase should be at least 13 characters.

  • Keep each one unique. Never reuse your UM passphrases across multiple UM accounts, or between UM and personal accounts.

  • Make them memorable. Memorable but not guessable.

    • CorrectHorseStapleBattery

    • SnowbaccaTheChicken

    • PastaFriday ForBreakfast

  • Use a password manager. A password manager can help create and manage strong, unique passphrases for all accounts.

  • Only you should know your password. If you suspect your passphrase has been compromised, reset it immediately and report the incident via email to infosec@umontana.edu.


2. Protect with Multi-Factor Authentication (MFA)

UM currently uses Duo as the primary MFA solution for user accounts. With Duo, you can choose between:

  • Duo Mobile push notifications (recommended)

  • Phone calls

  • Hardware tokens

Tips for using Duo safely:

  • Always approve only the requests you initiated. If you receive an unexpected push or call, deny it — this may be an attack attempt.

  • Avoid MFA fatigue. Don’t approve repeated requests if you’re not logging in yourself.


3. Account Safety at UM

  • Think before you click. Be cautious with email links and attachments.

  • Keep an eye on Duo. Never approve a login you didn’t initiate.

  • Report issues quickly. If anything seems unusual with any of your UM accounts, contact UM IT for help.

 

Was this helpful?
0 reviews