There are different account types used by different systems across the university. This article will outline the different account types, how they should be used, and detailed information on how they should be managed.
2 Hour Public Access
Risk Approval:
- No
Use Case:
- Libraries
Naming Standard:
- <unit>-pa-<description>
Managed By:
- Pam.osu.edu
Single User or Shared:
- Single User
Check In Check Out Required:
- Yes
Auto Check In:
- Yes
Password Duration:
- 2 hours
Auto Rotate Password:
- Yes
Password Length:
- Variable 8-12, Min 8
Password Complexity:
- Yes
- Minimum 1 lowercase
- Minimum 2 uppercase
- Minimum 1 number
- Minimum 1 special from !@#$%^&*()
Auto Generated:
- Yes
Editor Allowed to Set Password:
- No
PAM Secret Template:
- AD User
PAM Secret Policy:
- Guest User Checkout (2hr)
12 Hour Public Access
Risk Approval:
- No
Use Case:
- Libraries open 24 hours or extended use
Naming Standard:
- <unit>-pa-<description>
Managed By:
- Pam.osu.edu
Single User or Shared:
- Single User
Check In Check Out Required:
- Yes
Auto Check In:
- Yes
Password Duration:
- 12 hours
Auto Rotate Password:
- Yes
Password Length:
- Variable: 8-12, Min 8
Password Complexity:
- Yes
- Minimum 1 lowercase
- Minimum 2 uppercase
- Minimum 1 number
- Minimum 1 special from !@#$%^&*(
Auto Generated:
- Yes
Editor Allowed to Set Password:
- No
PAM Secret Template:
- AD User
PAM Secret Policy:
- Guest User Checkout (12hr) - BCD
72 Hour Public Access
Risk Approval:
- No
Use Case:
- Event Hosting
- Conference Space Rental
Naming Standard:
- <unit>-pa-<description>
Managed By:
- Pam.osu.edu
Single User or Shared:
- Shared or Single
Check In Check Out Required:
- Yes
Auto Check In:
- Yes
Password Duration:
- 72 hours
Auto Rotate Password:
- Yes
Password Length:
- Variable: 8-12, Min 8
Password Complexity:
- Yes
- Minimum 1 lowercase
- Minimum 2 uppercase
- Minimum 1 number
- Minimum 1 special from !@#$%^&*(
Auto Generated:
- Yes
Editor Allowed to Set Password:
- Yes
PAM Secret Template:
- AD User
PAM Secret Policy:
- Guest User Checkout (72hr)
90/180 Day Public or Shared Access
Risk Approval:
- Yes
Use Case:
- Testing Centers (Pearson, Clep, FAES labs, etc)
Naming Standard:
- <unit>-sh-<description>
Managed By:
- Pam.osu.edu
Single User or Shared:
- Shared
Check In Check Out Required:
- No
Auto Check In:
- No
Password Duration:
- 90 days or 180 days (default)
Auto Rotate Password:
- Yes
Password Length:
- Variable: 8-12, Min 8
Password Complexity:
- Yes
- Minimum 1 lowercase
- Minimum 2 uppercase
- Minimum 1 number
- Minimum 1 special from !@#$%^&*(
Auto Generated:
- Yes
Editor Allowed to Set Password:
- Yes
PAM Secret Template:
- AD User
PAM Secret Policy:
- Enforced - BCD Managed Account auto-rotation on
Sponsored Guests
Risk Approval:
- No
Use Case:
- Vendors
- Guest Instructors
- Anyone who will be onsite for repeat or fixed lengths
- Anyone needing access to email, cloud storage, file share, printing, etc.
Naming Standard:
- lastname.#
Managed By:
- my.osu.edu
Single User or Shared:
- Single
Check In Check Out Required:
- N/A
Auto Check In:
- N/A
Password Duration:
- 180 days
Auto Rotate Password:
- N/A
Password Length:
- Min 8
Password Complexity:
- Yes
Auto Generated:
- N/A
Editor Allowed to Set Password:
- N/A
PAM Secret Template:
PAM Secret Policy:
- N/A
Autologon
Risk Approval:
- Yes
Use Case:
- Public Access Kiosks
- Lima Library
Naming Standard:
- <unit>-svc-<description>
Managed By:
- Pam.osu.edu
Single User or Shared:
- Shared
Check In Check Out Required:
- N/A
Auto Check In:
- N/A
Password Duration:
- 365 days
Auto Rotate Password:
- N/A
Password Length:
- Variable 32-48
- Min 32
Password Complexity:
- Yes
- Minimum 1 lowercase
- Minimum 2 uppercase
- Minimum 1 number
- Minimum 1 special from !@#$%^&*(
Auto Generated:
- Yes
Editor Allowed to Set Password:
- N/A
PAM Secret Template:
PAM Secret Policy:
- Active Directory Service Account
Administrative
Risk Approval:
- No
Use Case:
- Server Admin
- ITSD/lab Admin
Naming Standard:
- Lastname.#a
Managed By:
- Pam.osu.edu
Single User or Shared:
- Single
Check In Check Out Required:
- N/A
Auto Check In:
- N/A
Password Duration:
- 90 days
Auto Rotate Password:
- N/A
Password Length:
- Variable 15-21
- Min 15
Password Complexity:
- Minimum 1 lowercase
- Minimum 2 uppercase
- Minimum 1 number
- Minimum 1 special from !@#$%^&*(
Auto Generated:
- N/A
Editor Allowed to Set Password:
- N/A
PAM Secret Template:
PAM Secret Policy:
- Active Directory Administrative Account
Service
Risk Approval:
- No
Use Case:
- Non-human account used to run applications & services
Naming Standard:
- <unit>-svc-<description>
Managed By:
- Pam.osu.edu
Single User or Shared:
- Single
Check In Check Out Required:
- N/A
Auto Check In:
- N/A
Password Duration:
- 365 days
Auto Rotate Password:
- N/A
Password Length:
- Variable 32-48
- Min 32
Password Complexity:
- Yes
- Minimum 1 lowercase
- Minimum 2 uppercase
- Minimum 1 number
- Minimum 1 special from !@#$%^&*(
Auto Generated:
- N/A
Editor Allowed to Set Password:
- N/A
PAM Secret Template:
PAM Secret Policy:
- Active Directory Service Account