Skip to main content

Password Policies

Staff Password Policy Updates

Staff Password Policy Update -Frequently Asked Questions 

Effective August 3, 2026 • Clovis Unified School District, Technology Services 


Starting August 3rd, your district password rules are getting an upgrade. No action is needed right now — changes apply to any password change on or after August 3rd. Here's what you need to know. 

 

 

 

  • Why are we changing the password rules? 

    Security guidance has evolved. The old rules like complex characters and frequent resets were meant to help, but research has shown they often made things worse. People ended up with passwords that were hard to remember but easy to guess. The new standard focuses on length over complexity, which is both easier on you and harder for attackers. 

     

    Why 15 characters long? 

    A longer password is exponentially harder to crack, even without symbols or capital letters. The trick is thinking of it as a passphrase instead of a password — a phrase or sentence that's meaningful and easy to picture. Something like April is my favorite month or my cat loves lasagna is long, memorable, and genuinely secure. 

     

    Won't a longer password take forever to type? 

    It might feel that way at first — but think about how quickly you can type a password you've had for years. Your new password doesn't expire, so you'll have time to make it second nature. Most people find a passphrase they chose themselves becomes surprisingly fast to type. 

     

    Do I need to change my password right now? 

    No. If you have not changed your password since August 2nd, 2026, it will expire 120 days after the last time you set it. When you are prompted after August 3rd, you'll need to set your new passphrase under the updated requirements — and hopefully won't need to change it again for a very long time. 

     

    What if I forget my new password? 

    If you have Multifactor Authentication (MFA) set up for your account, like the Authenticator app, you can reset it yourself anytime using the Microsoft Self Service Password Reset (SSPR) Portal.

    If you don't have MFA set up, or run into trouble, Technology Services is still here to help — just give us a call at ext. 79595 or 559-327-9595. 

     

    Can I keep my current password? 

    When your password expires, you'll need to set a new one under the new rules. You cannot reuse your current password. If your current password already meets the 15-character minimum, you can keep using it until it expires — but when it does, you'll need to choose something new. 

     

    Why did my password get rejected even though it meets the requirements? 

    The system automatically checks every new password against a list of known weak and compromised passwords — and it's smarter than it looks. It catches common substitutions (Cl0v1s = Clovis), repeated characters (111111111111111), and predictable patterns like sequential numbers or common words. 

    A few things may also cause a password change to fail: your first or last name, and district-specific words like Clovis, CUSD, school names, and mascots. 

    The error message won't tell you exactly why it failed — that's intentional. The fix is almost always the same: make it more personal and unique. Something meaningful to you that a computer wouldn't find on a list. 

     

    What if my account is hacked, or I click something I shouldn't have? 

    If your account is ever compromised — whether through phishing, malware, or anything else — you will need to change your password as a protective step. This is for the safety of your account and of the district itself; compromised accounts can lead to stolen data, including student information. 

    Technology Services will walk you through it if that ever happens. 


    Questions? Contact the Technology Service Center at ext. 79595 

    Password Policy FAQ

Student Password Policy Updates

Student Password Policy Update - Frequently Asked Questions 

Effective August 3, 2026  •  Clovis Unified School District, Technology Services 


Starting August 3rd, student password requirements are being updated. Here's what you need to know - and why the Clever badge plus MFA makes most of this a non-issue for your classroom. 

 

 

  • Why are student password requirements changing? 

    Security guidance has evolved, and student accounts are being brought up to the same standard as staff. Stronger passwords unlock stronger security features - including MFA through Clever, which makes the login experience on Chromebooks significantly better for students and teachers alike. 

     

    Why 12 characters? That seems like a big jump. 

    It is, and we know it. Modern security guidance tells us that longer passwords are exponentially harder to crack, even without complexity requirements. The good news is that student passwords won't expire under the new rules, and the Clever badge plus MFA means many of your students may not need to type their password at all when logging into Chromebooks. 

     

    Do student passwords expire? 

    No. Once a student sets a password on or after August 3rd, it doesn't expire. In theory, a student could set a password in kindergarten and keep it through graduation - as long as they remember it and their account is never compromised. That's exactly why helping students choose something meaningful and memorable matters, especially early on. 

     

    This password is going to take my students forever to type. 

    For older students, a passphrase - a short sentence or phrase they can picture - becomes surprisingly fast to type with practice. For younger students especially, we strongly recommend the Clever badge plus MFA instead. It's faster, it keeps your class moving, and it removes the password from the equation entirely. 

     

    What is the Clever badge and why does it matter here? 

    The Clever badge lets students scan a QR code and authenticate with MFA instead of typing a password when logging into a Chromebook. Once they're in, they're signed into their account and Clever apps automatically - no typing, no "I forgot my password," no lost instructional time. If you're not set up with Clever badges yet, information on getting started is included in this package. 

     

    What changes on Windows devices? 

    Nothing about the Windows login process has changed. Students log in the same way they always have. The new password requirements apply - so when a student's password expires, they'll need to set a new 12-character passphrase - but there's nothing new to learn about how to get into a Windows device. 

     

    What changes on iPads? 

    Very little. The only change on iPads is that students can log into the Clever app using either their username and password or their Clever badge. Everything else stays the same. 

     

    I've been setting the same password for all my students. Is that a problem? 

    We strongly discourage it going forward. A shared password means one compromised account puts every account at risk. For older students, setting a personal passphrase is actually a skill they'll use outside of school - most accounts they'll create as adults expect exactly this. For younger students, the Clever badge is the better answer anyway: no passwords to manage, no binders, no resets because someone forgot what you set for them. 

     

    Should I reset a student's password if they're struggling? 

    Only if they truly cannot log in and have no other way to recover access. If a student has set a passphrase they can remember, resetting it takes that away from them - and you'll be the one coming up with a new 12-character replacement. It's worth taking a minute to help them remember first. When a reset is necessary, you can do it through the teacher portal. 

     

    Can a student keep their current password? 

    When a student's password expires, they'll need to set a new one under the new rules. They cannot reuse their current password.  

     

    Why did a student's password get rejected even though it meets the 12-character requirement? 

    The same rules that apply to staff apply to students. The system automatically checks every new password against a list of known weak and compromised passwords - and it's smarter than it looks. It catches common substitutions (Cl0v1s = Clovis), repeated characters, sequential patterns, and district-specific words like Clovis, CUSD, school names, and mascots. It also blocks the student's own first or last name. The error message won't explain exactly why - that's intentional. If a student's password keeps getting rejected, the fix is the same: make it more personal and unique. A short phrase or sentence that means something to them is usually the answer. 

     

    What if a student account is compromised? 

    In most cases, Technology Services will reach out if we detect something. If you or a student notice anything unusual - unexpected lockouts, apps or files being accessed that the student didn't open, or signs that someone else knows their password - let us know right away. A password reset will be required, and the sooner it happens the better. 

     

    If I reset a student's password, do I need to create a new Clever badge for them? 

    No. Student passwords and Clever badges are independent of each other. While a badge allows a student to sign into their device without typing a password, it is not actually their password — it is a separate login method. Resetting a student's password has no effect on their badge, and no new badge is needed. 

     

    I am a kindergarten teacher.  What are my first steps getting passwords set up for the first time.  Does it require a reset and then create their badges?  What is the best practice for a Kinder teacher? 

    Badges are literally designed for this use case - students where typing may be challenge. Best practice: 

    • Don't worry about passwords at all upfront. Kinder students aren't typing username and password anyway. 

    • Get your Badges generated and printed right away (Clever Dashboard > Classes > Download Class Set of Badges) 

    • That's it. The Badge is their login. While it takes the place of a password for signing into Clever, it is not their password in a literal sense. 

    The only reason passwords matter for Kinder is the backend sync - Clever needs valid credentials in the system to map the Badge, but that's the technical setup side, not something the student ever touches. 

     

    I am a teacher and I want to use badges.  Should I reset all of my students' passwords the first day and then create badges for them, or should just get the badges created and let the password expire on the expiry date?  What is the best practice? 

    Just generate the Badges. No need to do a mass password reset first. The Badge works independently of whatever password state the student is in, so there's no reason to force a reset just to set up Badges. 

    Let passwords follow their normal expiry cycle on their own schedule. Teachers don't need to make passwords their problem when Badges are in use. 

     

    I am a teacher not using badges.  What are my first steps getting passwords changed to the new requirements?  Should I reset all at the start of the year to meet the new requirement or let them expire on the expiry? 

    Since student passwords expire annually, most of your students will likely be prompted to reset their password the first time they log in at the start of the year anyway. You do not need to do anything in advance - just follow the regular password reset process through Portal when they are prompted. Any password reset after August 3rd will automatically meet the new password requirements. 

     

    Questions? Contact the Technology Service Center at ext. 79595  |  559-327-9595 

    Student Password Policy FAQ
    Student Password Flyer - Presentations
    Student Password Flyer V2
    Student Password Policy FAQ Flyer – PDF