Protecting Your UM Accounts: Best Practices

Summary

Protecting all accounts is essential to safeguard your personal information and UM’s data.

Body

Doing your part to protect your UM accounts is essential to safeguard your personal information and UM’s data.


1. Use Strong Passphrases

  • Length matters. Your passphrase should be at least 13 characters.

  • Keep each one unique. Never reuse your UM passphrases across multiple UM accounts, or between UM and personal accounts.

  • Make them memorable. Memorable but not guessable.

    • CorrectHorseStapleBattery

    • SnowbaccaTheChicken

    • PastaFriday ForBreakfast

  • Use a password manager. A password manager can help create and manage strong, unique passphrases for all accounts.

  • Only you should know your password. If you suspect your passphrase has been compromised, reset it immediately and report the incident via email to infosec@umontana.edu.


2. Protect with Multi-Factor Authentication (MFA)

UM currently uses Duo as the primary MFA solution for user accounts. With Duo, you can choose between:

  • Duo Mobile push notifications (recommended)

  • Phone calls

  • Hardware tokens

Tips for using Duo safely:

  • Always approve only the requests you initiated. If you receive an unexpected push or call, deny it — this may be an attack attempt.

  • Avoid MFA fatigue. Don’t approve repeated requests if you’re not logging in yourself.


3. Account Safety at UM

  • Think before you click. Be cautious with email links and attachments.

  • Keep an eye on Duo. Never approve a login you didn’t initiate.

  • Report issues quickly. If anything seems unusual with any of your UM accounts, contact UM IT for help.

 

Details

Details

Article ID: 168602
Created
Fri 9/5/25 12:48 PM
Modified
Tue 9/30/25 10:41 AM