Passwords, Password managers, and 2FA best practices


Updating your password
 

1.  Log in to the WatIAM portal to update your password.

2.  Use a long password or passphrase

Password complexity rules (e.g., requiring uppercase letters, numbers, or symbols) are no longer required. Waterloo password standards now focus on longer passphrases (15+ characters), which are more secure and easier to remember.

Passwords should be long, unique, and easy to remember.

  • Use a passphrase (a combination of words) instead of a single word.
  • Aim for at least 15 characters to align with University password standards.
    • Maximum length for WatIAM account passwords is 64 characters
  • Use four or more unrelated words, with numbers or punctuation if helpful.
  • Avoid using your name, username, or identifiable information.

Example: GrandMorning- RiverCoffee!

Privileged accounts: Current password complexity rules for privileged accounts in NEXUS (e.g., !) will remain in force with the minimum length adjusted to 15 characters

3.  Do not reuse or recycle

Using the same password across multiple accounts increases your risk.

Avoid reusing passwords

If one site is compromised, attackers will try the same password on other services (a technique known as credential stuffing. Always use a unique password for each account, especially for:

  • Applications that do not use University of Waterloo Single Sign-On (SSO)
  • Vendor-managed accounts
  • Personal accounts (e.g., email, banking, social media)

Be different

If your previous password was compromised, simply adding a digit or character is not enough. Always create a completely new password that is not related to your previous one.

4.  Enable two-factor authentication (2FA)

Passwords alone are not enough to protect your accounts.

Two-factor authentication (2FA) adds a second layer of protection by requiring something you know (your password) and something you have (such as a device or security key). This helps prevent unauthorized access, even if your password is compromised.

For University accounts (SSO / WatIAM)

  • Ensure Duo 2FA is enabled
  • Use the Duo Mobile app (push) where possible (recommended option)
  • Do not approve unexpected login prompts

For vendor or non-Single Sign-On accounts

  • Enable multi-factor authentication (MFA) in the application settings wherever it is available
  • Choose the strongest available method (not all methods provide the same level of security):
    • Authenticator app (e.g., Duo Mobile, Microsoft Authenticator)
    • Hardware token or security key
    • Push notification
    • SMS text message or email code (least secure — more vulnerable to phishing and interception)

If multi-factor authentication is not enabled or available for a system that stores University or personal information, contact your department administrator or Information Security Services for guidance before using the service.

5.  Store and manage your passwords securely

Managing multiple strong passwords is difficult without a tool.

A password manager can help you:

  • Generate strong, unique passwords
  • Store them securely in an encrypted vault
  • Autofill credentials safely

Important

  • The University of Waterloo does not currently provide a centrally supported password manager.
  • Before using a password manager for work or institutional accounts, check with your department or administrator to confirm what is appropriate.
  • There are many reputable password manager options available. Tools such as 1Password and Bitwarden are commonly used examples, but their mention here does not constitute an official endorsement.

Low-tech alternative

  • If you are not using a password manager, consider storing passwords in a secure physical notebook.
  • Keep this notebook in a safe and private location and never share it.

Avoid storing passwords in your browser

  • Browser-stored passwords can be extracted if your device or browser is compromised.
  • Browser storage is designed for convenience, not security.

After updating your password

  • Update saved credentials on all devices and applications.
  • Ensure MFA is still enabled and working.
  • Watch for unexpected login attempts or activity.

Did you know?

Cybersecurity awareness training is mandatory on an annual basis for University of Waterloo employees. You can self-register for information security courses through LEARN.

Questions? 

For questions about cybersecurity, best practices, or awareness training, contact: dl-ist-securityawareness@uwaterloo.ca

Report a security incident

If you suspect a security incident (e.g., phishing, suspicious activity, or account compromise), contact the Security Operations Centre (SOC).


Get informed, stay safe.

Sign up for the cybersecurity newsletter to receive updates, tips, and important security information.