/
Password Sharing Using LastPass

Password Sharing Using LastPass

SMT has approved LastPass as the password sharing location for Libraries shared accounts. All shared Libraries accounts will be expected to be saved and shared in LastPass according to OU IT policy.

Shared Accounts Overview

Per the Shared Accounts article from OU IT:

  • A Shared Account, with a password, is an enterprise system account which is accessed independent of an individuals personal account and allows multiple users to share the same identity. Extra care must be taken to secure Shared Accounts because of the significant risks to systems, applications, and services that could result from misuse, creating or exposing vulnerabilities, and/or facilitating unauthorized access.

  • Shared Accounts, which are accessed with a password, will be subject to the OU Password Policy. The policy requires a password change every 30 days.

  • Shared Accounts must have a designated sponsor and co-sponsor. These sponsors are are expected to:

    • Only grant access to the shared account to those with a job-related need.

    • Avoid saving passwords in scripts and configuration files that can be read by non-authorized individuals.

    • Develop internal processes to facilitate the changing of shared account passwords when

      • Anyone with knowledge of the password leaves the unit

      • Anyone with knowledge of the password changes responsibilities and no longer requires access to the account

      • The password is required to change due to the 30-day policy.

    • Ensure Shared Accounts do not access prohibited data.

    • Audit and attest, on a semi-annual basis, that the Shared Account is not accessing prohibited data. These audits and attestations will be shared with the Chief Information Security Officer (CISO) and Board of Regents.

    • Notify OU IT to disable the account when it is no longer in use.

LastPass Overview

Per the LastPass service page from OU IT:

The LastPass password manager allows you to automatically save all your credentials in a secure vault and automatically fill in those usernames and passwords as you visit sites across the web.

In addition, you'll be able to use:

  • Team Password Sharing: Share one or more passwords securely between coworkers.

  • Access Anywhere: Whether on a desktop, laptop, smartphone or tablet, your account is backed up and synced everywhere you need to work.

  • Linked Personal Accounts: Manage personal and work passwords by simply linking them together. And don’t worry...personal passwords are private and remain accessible only to you.

 

UL LastPass Guide: https://intranet.libraries.ou.edu/docs/content/lastpass-guide

How to activate LastPass: https://itsupport.ou.edu/TDClient/30/Unified/KB/ArticleDet?ID=1707

 

If you have any questions about setting up LastPass, please submit a ticket through the OU IT LastPass service page.

If you would like assistance with setting up and using LastPass in your department/teams, don’t hesitate to reach out to the UL IT team at https://itsupport.ou.edu/TDClient/105/library-IT/Requests/TicketRequests/NewForm?ID=aT8k0rwQjE4_&RequestorType=Service.