Medicine Domain Accounts
The following policies apply to "Medicine Domain Accounts." These are the accounts that are used to log onto computers on the Kensington campus, access the faculty file server files1-med, access faculty network printers, or upload school/unit web pages to the faculty IIS web server web-med. It does not currently apply to Unipass.
Password Policy
The Medicine password policy is now a lot stricter than it used to be. Passwords must now meet complexity requirements (as defined by Microsoft windows).
More information...
Common Account Policy
The University Security Policy discourages the use of "common" accounts - that is, accounts that are used by more than one person. As such, we will only set them up if there is a very good reason to do so. Even if a staff member or student is temporary, it is still recommended that they have their own account to use. For common accounts that currently exist, the account will automatically be expired at the end of each year, and will need to be reactivated each year and their passwords reset for them to continue to be used.
Student Account Policy
Any student accounts that are created will be set to expire at the end of each calendar year, unless a specific finishing date is indicated when creating the user. We will require confirmation from the student's supervisor that the student is still current before extending the expiry date of an account for another year.
Inactive Account Policy
Any accounts that have not been logged into within the past three months will be disabled. An email will be sent to the email contact for the account (and also the file server coordinator if appropriate) informing them that their account has been disabled. A user may log a call with the helpdesk to get it reenabled.
Any accounts that have been disabled for three months will be deleted. An email will be sent to the user two weeks prior to deletion with the final warning. If the user wishes to reactivate the account, they must log a call with the helpdesk. If no contact is received within two weeks, the account will be deleted. If the account is a "file server" account, the file server coordinator will be informed of the account deletion.
If an account has been disabled or expired, the password must be reset when reenabling it.
Web Server Account Policy
If someone requires a "password protected" area on their school/unit's website, hosted on the IIS server web-med, we will now create the account locally on web-med, rather than on the domain. This process is transparent to the user, but it means that the account cannot be used to access domain-wide resources.