Password Reset for Site Administrators
InCommon Operations supports automated two-factor password reset for site administrators. The first factor involves an email account (“something you know”) while the second factor involves a phone (“something you have”). Watch a video demo of two-factor password reset in action.
In the future, InCommon will also require two-factor authentication on your login account itself. Together, two-factor authentication and two-factor password reset make it very difficult for a bad guy to gain control of your login credentials.
Two-factor password reset and two-factor authentication are being deployed in phases. Two-factor password reset is available now. Two-factor authentication will be available early in 2015.
As a new site administrator, InCommon Operations verified your email address and your phone number, both of which were obtained from your Executive when your organization joined InCommon. This information is used for the purposes of two-factor password reset as well. It is all you need to reset your password.
If your verified email address or verified phone number changes, talk to your Executive. Only your InCommon Executive may change your contact information.
To reset your login password, sit at your verified phone location and follow these steps:
- To begin the password reset process, click the link in the upper righthand corner of this document.
- Perform two-step identity verification:
- Request an email invitation by entering your email address at the prompt and pressing the button (screen shot)
- Click the link in the email to launch a secure landing page in a browser window (screen shot)
- Request an one-time PIN by pressing a button that sends a PIN via an automated voice message to your phone number (screen shot)
- Verify the one-time PIN by entering it on the web page and pressing the button (screen shot)
- Create a new password: (screen shot)
- Enter a new password at the prompt
- Confirm the new password at the second prompt
- Submit the new password by pressing a button
That's it! You are now ready to log into the Federation Manager.
Please report any problems or make suggestions for improvement by contacting admin at incommon dot org
Currently, every site administrator is issued a strong password for authentication purposes. If you forget or lose your login password, you can reset it yourself using the above automated process. If you are unable to reset your password for any reason, please contact us at admin at incommon dot org.
The level of assurance associated with your email password is unknown and so we have the following policy regarding your login password:
InCommon Operations Password Policy
- Your login password SHOULD be different than your email password.