Rutgers Remote Password Reset Tool

Overview

With over 45,000 students registered at the University, the Office Of Information Technology (OIT) help desks and computer labs perform a large number of resets for forgotten passwords. The current procedure requires students to come to campus and present a University ID to a staff member to confirm their identity. This is viewed as an inconvenience to the students, and is further complicated by the specter of distance learning, which presents problems when servicing students who are not on a physical University campus. For this reason OIT has developed the Remote Password Reset (RPR) tool to provide a way by which University students will be able to reset their own passwords without staff interaction.

By using this tool the student population will be provided with a convenient mechanism for resetting their own passwords remotely. Students will be authenticated by a combination of private information and answers to a set of questions chosen by the student from a list of University defined questions. This provides better service to the students, especially those in the distance learning programs, who need to quickly access university resources.

Why Should I Use the Remote Password Tool

A NetID and password gives individuals access to a variety of services and personal information at Rutgers, including class schedules and grades. As such, a password is required to be a fairly secure, unusual sequence of characters that will not be shared with others. Unfortunately, people forget their password and need to visit a Help Desk or computer lab for an identity check in order for their password to be reset.

Opting in to the password recovery program is a convenience which associates a variety of questions with the account so that if it becomes necessary, the password can be reset, remotely and quickly, without a need for a visit. Users need to balance this possible convenience against the potential for less security on the account. Personal questions about people are more easily guessed than an unusual password. If a user opts to set the questions, it is important that they select answers that are not easily guessed or researchable. Users also want to make sure they never share these answers with anyone else. Remember, there are unsavory individuals who exploit social engineering tricks to find out personal information about others.

Who can use the Remote Password Reset Tool?

This tool is currently only available to the student population and is not available to the employees of the university for security reasons. (Students employed by the University in any function will be considered employees of the university for this application.) Given the large number of applications and privileges granted to the University population via their NetID, great care must be taken to ensure that the RPR tool will not reduce the level of protection currently offered to students and employees. OIT must also ensure the integrity of University data as well as the privacy of the user population as described by State and Federal laws.

These considerations are the primary reason why the RPR tools will only be available to students, given that employees are more likely to have access to sensitive data which should not be exposed.

Note that RPR is an additional method now available for students to reset their passwords. None of the already existing methods of passwords reset will be discontinued. The RPR implementation can not guarantee that students who have forgotten their password have not also forgotten the answers to the questions used by the RPR tools.

How Do I Start Using The Remote Password Reset Tool?

When first activating a NetID, students will be offered the opportunity to opt in or opt out of this service. If the students choose to opt in they will be prompted to provide answers to 3 questions of their choice from a list of proposed University predefined questions. These answers will then be stored in a database.

Students who did not previously opt in, or have created their accounts before this tool was made available may activate this feature by going to:

http://netid.rutgers.edu

and click on Manage NetID Password. The user will be asked to log in with a valid NetID and password. Students can manage their security questions and answers from this page as well.

How Do I Change My Password Using The Remote Password Reset Tool?

The tool to change the password for an account is located at:

http://netid.rutgers.edu

and click on Manage NetID Password then select Forgotten Password.

This tool will first prompt for a NetID, name, birth date, and SSN. This information is used to identify the student and retrieve the questions that were selected by the student. Assuming that a correct set of information was provided on the first page, the student will be presented with the questions they selected one at a time.

In the event that the student cannot successfully answer these questions a lock will be set preventing the user from utilizing this tool to reset their password. Once a lock has been set the user will need to come in person to an OIT Computer Help Desk or a main computer lab to have the password reset.

How to get help

For questions or assistance with remote password recovery (RPR), Please contact the Help Desk on your campus:

Rutgers, New Brunswick

Phone: (732) 445-HELP

Email: help@eden.rutgers.edu

Rutgers, Newark

Phone: (973) 353 - 5083

Email: help@newark.rutgers.edu

Rutgers, Camden

Phone: (856) 225-6274

Email: help@camden.rutgers.edu