Cybersecurity Awareness Resources

Overview

This article highlights the role of the IT Solutions Information Security team in promoting cybersecurity awareness and protecting university data. It offers practical tips for students and employees on avoiding phishing, keeping software updated, using strong passwords, and securing personal devices. The goal is to encourage shared responsibility for staying safe online.

About the Information Security Team

The IT Solutions Information Security team helps protect student and employee information, keep the University safe online, and spread awareness of cybersecurity best practices. While the team works to prevent, investigate, and remediate cybersecurity issues, it's everyone's responsibility to know best practices and remain vigilant.

Recent Cybersecurity Updates

Protecting student and employee accounts and data from security threats while keeping you connected remains a top priority. Here are few important security updates you should know about.

New StarID Password Requirements Begin October 1, 2026

The next time you change your password, it must meet the new requirements: 

  • Be 15–128 characters long. 
  • Include at least three of the following: uppercase letters, lowercase letters, numbers, or special characters. 
  • Not have been used previously. 
  • Not contain your first or last name if the name is longer than two characters. 
  • After that, regularly scheduled password changes will no longer be required, unless a password reset is needed for another reason. 

Multi-Factor Authentication Text and Call Ending February 1, 2027

On February 1, 2027, Microsoft is ending support for text and phone call authentication methods on all accounts. These methods are less secure and more vulnerable to phishing attacks.  Going forward, the Microsoft Authenticator app will be the supported authentication method for University accounts. Those who currently use text messages or phone calls to authenticate sign-ins must:

  • Switch to the Microsoft Authenticator app before February 1, 2027. Your account will continue to prompt you until you do. 
  • If you don't switch by the deadline, you'll be unable to sign in.  

Cybersecurity Tips

Phishing

Phishing, also known as scams, includes any fraudulent activity like malicious emails, websites, text messages, and phone calls that try to steal your info.

What You Can Do

  • Make sure the sender is legit.
  • Don’t open suspicious attachments or links.
  • Don’t share personal information.

Patching

A patch is a software update that provides fixes and improvements, protecting devices from security threats. Old apps and operating systems are easy to take advantage of.

What You Can Do

  • Turn on auto-updates to keep software up to date.
  • Use only official app stores to download apps.
  • Be careful of free apps and check permissions.

Passwords

Your passwords are the keys to your devices and accounts, which contain your personal information. You can be at risk if your passwords are not secure and protected.

What You Can Do

  • Enable multi-factor (or two-factor) authentication for extra security.
  • Don’t share, write down, or reuse your passwords.
  • Use passwords or phrases with at least 12 characters and a mix of letters, numbers, and symbols.

Protect Your Devices

Computers and smart devices contain personal information, so keep them accounted for. Smart phones are usually the least protected of all devices, which makes them a target.

What You Can Do

  • Keep track of your devices and lock them with passwords.
  • Old devices may still be storing info – don't leave them laying around.
  • Correctly dispose of University technology no longer in use by contacting IT Solutions for device recycling.

Still Need Help?

Visit the IT Solutions Center page to view current hours, locations, and contact information.

Print Article

Related Articles (6)

Learn how to change or reset your StarID password quickly and securely.
Explains how to recognize and report spam or phishing emails by checking for suspicious senders, errors, unusual links, and unsafe attachments.
Explains how to report spam or phishing emails in Outlook (on desktop or web) using the Report Message button or by sending the message to spam@mnsu.edu.
How to view employee technology assets and report changes.
Follow these instructions if you accidentally click on a phishing link.
Follow these steps if you believe your account is compromised.