Passwords: Everything You Need to Know
Overview
Passwords are one of the cornerstones of keeping your information secure. Per the University's Computer and Network Responsible Usage Policy, passwords must conform to IT’s published complexity and length requirements, and must not be shared with any other person, used in non-University accounts, or otherwise disclosed.
When in doubt, follow these four guidelines:

Keep It Strong
Use a unique, strong password with 15+ characters for each website, preferably a passphrase.

Protect It with a Password Manager
Use a recommended password manager to generate and store your passwords. They're secure, and some are free!

Don't Reuse It
Do NOT reuse your Pepperdine NetworkID password on any site that doesn't use Pepperdine single sign-on.

Don't Share It
Do NOT share your Pepperdine NetworkID password with anyone or any technology other than a supported password manager.
Keep Your Password Secure
Technical Requirements
Information Technology implements technical controls to enforce strong password requirements. Pepperdine NetworkID passwords (for Pepperdine user accounts) have different requirements than PGP system passwords (for encrypted devices).
Avoid Pepperdine Account Lockouts!
If you have saved your Pepperdine NetworkID password in mobile devices or email apps that periodically log in with that password, you may be locked out of your Pepperdine account if you forget to update the password after changing or resetting it! Be sure to update your password on any mobile device app, such as:
- Mobile device email app
- Computer email app (e.g., Outlook, Thunderbird) that uses IMAP to send/receive messages
- Calendar apps
- Password manager (if a password manager auto-populates your password in a web browser)
Note: Use official Google apps or Gmail to minimize account lockouts!
Change or Reset Your Password with MyID
Whether you are setting your password for the first time or you need to change your password, use MyID to manage your Pepperdine NetworkID password.
Third-Party Websites Not Using Pepperdine Single Sign-on
When Creating an Account or Logging In
If your school or department licenses or provides a third-party web application, but it does not participate in Pepperdine CAS/SSO login, you must:
- Create a separate password for the third-party application (do not reuse your Pepperdine NetworkID password on a third-party website).
Information for Managers or Owners of Third-Party Applications
If you have licensed a third-party application for your school or department that will be used by students, faculty, and/or staff, you must:
- Double-check with the vendor whether they support CAS or SAML integration, and license the product accordingly.
- If the vendor does not support CAS or SAML, configure the application to require strong passwords. Match the Password Technical Requirements above.
- If the vendor does not support CAS or SAML, you must inform your users that they must not reuse their Pepperdine NetworkID password on this third-party service. They must create a new and unique password that is not a derivative of their Pepperdine NetworkID password.
If you have any questions about this, please contact the Information Security Office and speak to a security operations analyst.
Why All of This Matters
If you use your Pepperdine University email address to create an account on a third-party website, and that outside website is hacked and the passwords exposed, you do not want to hand the hackers access to your official Pepperdine University account (or any of your other accounts!). Your Pepperdine account includes access to services that can expose your home address, your financial information (direct deposit, financial aid, retirement), grades, and more! Never reuse your Pepperdine password on any other website to protect your own information and to protect the University from cybercriminals.
If you have bad password habits, it's time to adopt healthy ones by:
- Following our 4 Guidelines.
- Making strong passwords that meet our Technical Requirements.
- Creating unique passwords for every website and using a recommended password manager to keep them straight.
- Protecting your mobile and tablet devices with a PIN/passphrase and auto-lock (see the Technical Requirements).
- Changing your University password if you suspect your account has been compromised.
- Reporting any information breach immediately, including a compromised password.