Topics Map > AccessStout > Access
Topics Map > Service Catalog > Accounts, passwords and security services > System Security
Topics Map > Service Catalog > Accounts, passwords and security services > Campus account > Password services

Password security requirements (and LOA explained)

Requirements for Passwords for Campus Credentials


Accounts on campus have been broken up into three categories.  These categories differentiate between the different levels of assurance we require to prove the person logging into the system is the person associated with the account.  These three categories are LOA1, LOA2, and LOA3.  In addition to these requirements some UW-System applications require users to use multifactor authentication using a device with a randomly generated number. The password requirements for the 3 categories are:

Level of Assurance (LOA) Password Security Requirements

Passwords must meet the following requirements for all levels

Passwords must not contain all or part of the user's account name
Passwords must contain characters from at least three of the following four categories

  1. Uppercase letters (English characters, A through Z)
  2. Lowercase letters (English characters, a through z)
  3. At least one number (0-9)
  4. Non-alphanumeric characters (example: $, #, %,^)

Students (LOA1) additional security measures include

    • Password must have a minimum of eight (8) characters
    • 30 minute lockout after 20 login failed attempts applies to all levels
    • Change of password every 365 days

Faculty and staff (LOA1) additional security measures include

    • Password must have a minimum of ten (12) characters
    • 30 minute lockout after 7 login failed attempts applies to all levels
    • Change of password every 180 days 

LOA2 additional security measures include

    • Password must have a minimum of fifteen (15) characters
    • Change of password every 90 days
    • Idle system lockout after 10 minutes

LOA3 additional security measures include

    • Password must have a minimum of fifteen (15) characters
    • Change of password every 45 days
    • Idle system lockout after 5 minutes



Keywords:LOA   Doc ID:48508
Owner:Mike D.Group:UW Stout
Created:2015-03-06 17:01 CDTUpdated:2017-06-19 08:22 CDT
Sites:UW Stout
Feedback:  2   0