Blackbaud ID for Parents, Candidates and Parents of Candidates

Received the news in the update newsletter regarding forcing all users to update their legacy password and/or move to Blackbaud ID>

Question - Last word was this would not be forced until BBID was ready (meaning had our school's branding). Candidates and Parents do not know who Blackbaud is and we want to keep their attention on us to get them to apply and enroll. When will the branding for BBID be ready?

Thanks for the update!

Comments

  • Bryna Gleich
    Bryna Gleich Blackbaud Employee
    Tenth Anniversary Kudos 3 Name Dropper Participant
    The April 20th update does not require you to move to BBID.

    BBID is not affected by the April 20th updates.

    In general, we recommend BBID.

    At this time, I do not have a specific date for when BBID will have the additional branding functionality.

    If you do move to BBID, then the April 20th password updates won't affect you, because BBID's parameters take over instead.
  • I knew that the April 20th date does not require a move to BBID BUT, we will be moving our incoming parents to BBID the 3rd week of April, so it would be great if you could bump back the new login parameters to summer so our new parents do not have to get 2 separate emails from us, explaining the new parameters and then asking them to BBID authenticate.


    Just simplifies a process already complicated for new parents with all the information we send their way (school forms, new student email address, a laundry list of new things for them).


    Thank you,


    Coco Parham
  • Exactly Coco, why have to make Parents transition twice if we can do it in one move. We are all working to get our NEW parents connected at this time of year. Changing these dates at the drop of a hat is killing us as we make plans and then have to pivot to change those again.
  • Thanks for the demo - very helpful when communicating with our parents.
  • We will be working on the branding implementation in the upcoming month. Thanks for your patience.
  • Can you confirm or update the statements from the now locked thread Legacy password policy updates - Angry parents - Blackbaud Community (never had a thread locked before) that we cannot choose to maintain the 0 option or unenforced. We have to change to a maximum of 365. Further once this change happens anyone with a password of more than that age will immediately require it to be changed on next login.


    As I mentioned in the other thread forcing password changes doesn't increase security in any way, often exactly the opposite. That advice is 5 years out of date - Time to rethink mandatory password changes | Federal Trade Commission (ftc.gov).


    The timing of this change and the forced nature of it is not ideal.
  • Bryna Gleich
    Bryna Gleich Blackbaud Employee
    Tenth Anniversary Kudos 3 Name Dropper Participant
    Hi Brian,


    As mentioned in today's blog post and in a comment earlier in this thread, the timing of this change is necessary due to security for the summer.


    The older studies about not changing passwords mention a phenomenon where users sometimes choose easily guessed patterns.


    Thus, an additional recommendation (which we're including in this week's release letter and blog post) is to avoid easily predictable patterns.


    For example, avoid using this series of 6 passwords changed every 90 days:


    Turtle01


    Turtle02


    Turtle03


    Turtle04


    Turtle05


    Turtle06


    Since that pattern is easily recognized and easily guessed.


    When users change passwords, they should be encouraged to choose strong passwords that are not related in predictable ways to their previous passwords.


    Thank you.
  • Agreed on this - frequent password changes (every 90 days !?) is definitely not best practice unless paired with a password manager (even if this article is five years old). Forcing users to frequently change passwords that they have to remember and can't be based on a similar pattern is just inviting mental chaos and constant password resets. Of course if they just change it six times they can re-use it again - woohoo. :) [not serious ... just noticed that will happen]


    Do we have the list of BBID password requirements, so we know what our non-SSO folks would be held to? Or is it the same as the legacy list?

    Brian Hoyt:

    As I mentioned in the other thread forcing password changes doesn't increase security in any way, often exactly the opposite. That advice is 5 years out of date - Time to rethink mandatory password changes | Federal Trade Commission (ftc.gov).

  • Bryna Gleich:

    Hi Brian,


    As mentioned in today's blog post and in a comment earlier in this thread, the timing of this change is necessary due to security for the summer.


    Can you link to this new blog, not sure which one you are referencing? Is something happening this summer that will affect security? I don't understand the references to "summer" and security? Can you confirm that we are unable to use the 0 setting? It is still shown in the options will it not actually work?

  • Is there a way to run an advanced list that will report on the last password change date. This will allow us to understand the impact on our community better.
  • I went to https://k12hub.blackbaud.com/blog and most recent blog was from Feb 25 is there someplace else to look for recent blogs?
  • Bryna Gleich
    Bryna Gleich Blackbaud Employee
    Tenth Anniversary Kudos 3 Name Dropper Participant
    It's the Tips and Tricks blog in this user community. You can access the Tips and Tricks blog from the top of this user community forum navigation.


    You can subscribe to Tips and Tricks to get notified when a new entry is posted.


    The blog with "hub" in the URL is more public facing than the user community one, so they tend to have slightly different topics. The Tips and Tricks one is more often written by technical writers.
  • Hi Brian,
    Last password change is a filter and an output column on the SKY User list in Core. Core>Users> User list. I can run this list and export to excel, then filter on who has not changed their password in the last year. We all use legacy passwords. We are trying to get our faculty and students to update their passwords this week so when April 20th hits, it will just be parents/parents of candidates/alums/trustees, etc.. I agree this is very poor timing and would much rather allow our community to end the year with the same password if desired. It's a massive ask for our tech and communications departments to navigate all of this right now.

  • So will this be a requirement for candidate parents, incoming parents, and others not necessarily enrolled yet? I am unsure.
  • Bryna Gleich
    Bryna Gleich Blackbaud Employee
    Tenth Anniversary Kudos 3 Name Dropper Participant
    Hi Bill,


    New users who use "legacy" passwords will need to meet the stronger password requirements, as of April 20.


    This update doesn't force new users to immediately convert to BBID.


    Thank you.
  • Can anyone confirm the fact that the setting of 0 to disable password expiration shown in the options currently will no longer work after April 20? If so can the screen be updated to remove the description of the option? What is shown in screenshot of this post https://community.blackbaud.com/forums/viewtopic/296/54530#p212812
  • Bryna Gleich
    Bryna Gleich Blackbaud Employee
    Tenth Anniversary Kudos 3 Name Dropper Participant
    Brian,


    As of April 20, passwords must be changed every 365 days. That is the minimum required default.


    Passwords will expire. It will not be possible to have passwords that never expire.


    You can set passwords to change more frequently. We recommend more frequently. We recommend every 90 days.


    You can't make them change less frequently than 365 days.


    The full details of password requirements is in the blog, the release notes, and the online help (and help panel).


    Thank you.
  • Bryna,

    Do we have to manually change the number of days to 365 by April 20th or will it automatically change to 365 days on April 20th?
  • Bryna Gleich
    Bryna Gleich Blackbaud Employee
    Tenth Anniversary Kudos 3 Name Dropper Participant
    Hi Coco,


    The changes will be automatic on April 20.


    You can change them sooner if you would prefer a closer date. It can't be delayed though.


    Thank you.
  • Thank you Bryna!
  • Hi Brian,

    The screen will look like this when it goes out. There will be no disable option anymore.