UIS Account Password Recovery

UIS Account Password Recovery

Self-Service Password Recovery (SSPR) - What’s changed and why set it up

If you forget the password for your UIS account (formerly known as Raven), you can quickly reset it by clicking "Forgot my password" below the password prompt when signing in to your UIS account. You'll need to verify your identity using 2 sign-in methods before you can change your password.

image-20260519-093734.png

Previously, users would have set up SSPR in the form of security questions and used the UIS Password Management app to reset the password themselves, or contacted CSCS Service Desk or UIS Service Desk to obtain a reset token.

The Password Management app has been retired. SSPR is now done via additional authentication methods on your UIS account. Therefore, it is important to make sure you have a second sign-in method added as this second method will allow you to reset your password in a matter of minutes.

Without this second method, users must contact CSCS Service Desk or the UIS Service Desk to request an assisted password reset. It will require an identity check, via the UIS third-party validation service; this includes providing a photograph of your government issued photo ID, plus a “liveness” check, to confirm your identity. This check could take several hours or all day to return the validation and a failed validation would then be referred to the UIS for further checks.

This change is not in response to a specific threat or incident, but in response to continued general threats of social engineering.

Check what you have already

Login to your Microsoft account using this link https://mysignins.microsoft.com/security-info and on the Security info page, if you have two up-to-date authentication methods configured as shown below you are all set, and SSPR is configured.

sec info2.JPG
Example of SSPR setup

If you see only one method or multiple methods with some outdated ones, review the supported methods and steps on adding or amending what you have below.

Supported methods for password recovery

Register at least two reliable methods and keep them up to date (e.g., when you change phone numbers). Consider adding the authenticator app to a secondary device (e.g., tablet) for resilience. Never pay for an authentication app or “trial”.

  • Phone number(s): Receive a code via SMS, WhatsApp, or voice call to a mobile or landline. You can set both “Phone” and “Office phone”(e.g. desk phones) using two different numbers.

  • Don't use your Teams phone number (if you have one) because you need to be signed-in to use it.

  • Authenticator app: Time-based code sent to your mobile device. You can choose Microsoft Authenticator or select “I want to use a different authenticator app” (e.g., Google Authenticator). Install on multiple devices if possible.

  • UIS-provided hardware token: Only if you have been provided one. These tokens are provisioned by UIS for eligible users (e.g., certain lab environments or accessibility needs). Personal tokens will not work.

Recommended setups

  • If you have a modern mobile device: Phone + Authenticator app

  • If you do not want/cannot install an app: Two different phone numbers (e.g. Phone + Office phone, but don’t use your Teams phone number).

  • If eligible for a hardware token: Phone + UIS-provided hardware token (only issued under special circumstances).

Add or change a sign-in method

  1. Open https://mysignins.microsoft.com/security-info and sign in.

  2. Select “+ Add sign-in method” to add a new method

  3. Make sure at least two methods from the list below are added to the list.

    1. If your Teams phone number is added here, delete it, as it is not a viable option for password recovery.

    2. You can also remove old devices that you no longer use for authentication.

How to reset your password

  • If SSPR is configured, click “Forgot my password” on the Microsoft sign-in page or go to https://aka.ms/sspr to reset it yourself.

  • If SSPR is not configured or you are unable to reset, contact the CSCS Service Desk or the UIS Service Desk. However, the process will be more onerous because it will require an identity check via the UIS-selected third-party validation service.

Troubleshooting

There is no specific confirmation message. SSPR is active once you have registered at least two valid recovery methods in your Microsoft security info.

That’s ok. You can get codes via SMS on non-smartphones, or voice call to a mobile or landline.

Personal hardware tokens won't work because a UIS administrator needs to set up the hardware tokens. UIS-provided hardware tokens are available only to eligible users, such as those with special accessbility needs. Contact UIS Service Desk for more information.

Get Help

Contact the CSCS Service desk (9:00-17:00, Mon - Fri)

  • Raise a support ticket if you are able to (needs UIS account login)

  • Call the CSCS Service Desk on 01223 336261

Alternatively, contact UIS Service Desk, see UIS Service Desk for contact methods

More information on password recovery can be found here https://help.uis.cam.ac.uk/service/accounts-passwords/setting-password-recovery-microsoft