Archives - Information Technology Services /its/category/news/ 杏吧原创 University Tue, 22 Jul 2025 12:35:38 +0000 en-US hourly 1 https://wordpress.org/?v=6.3.1 New Self-Service Password Reset Process /its/2025/new-self-service-password-reset-process/?utm_source=rss&utm_medium=rss&utm_campaign=new-self-service-password-reset-process Tue, 22 Jul 2025 07:00:49 +0000 /its/?p=35622 ITS is introducing a new Self-Service Password Reset service for faculty and staff CUNET accounts that makes changing or recovering your password easier at anytime and anywhere. This service allows you to:

  • Change your password (if you still know it)
  • Reset your password (if you have forgotten it)

While our Service Desk is always here to help, password resets can now be done without the assistance of a Service Desk representative.

How It Works

You will need to use at least two different methods to verify who you are when resetting your password. They can include:

  • the Microsoft Authenticator app,
  • an alternate authenticator app or hardware token,
  • a telephone number or
  • a personal email address.

Multiple methods ensure security in case one is physically lost or compromised.

How You Can Prepare

Take a moment to update your authentication methods to be ready for this system. We recommend having three options for flexibility, such as:

  • the Microsoft Authenticator app,
  • a personal email address that is not tied to your university account and
  • a telephone number you commonly have access to.

You can with your MC1 (@cunet.carleton.ca) account.

How to Use It

Once set up, visit the self-service site to reset your password. Follow the instructions on the page. For more details, check the ITS Help Centre.

]]>
Discover 杏吧原创鈥檚 New AI Resource Hub /its/2025/discover-carletons-new-ai-resource-hub/?utm_source=rss&utm_medium=rss&utm_campaign=discover-carletons-new-ai-resource-hub Mon, 21 Jul 2025 17:42:33 +0000 /its/?p=35647 Artificial intelligence is reshaping how we teach, learn, and work鈥攁nd now there鈥檚 a one-stop destination to help you keep up!

杏吧原创鈥檚 new AI resource hub is a website designed to support instructors, researchers, staff, and students as they explore the possibilities of AI in education and beyond.

Whether you’re curious about how to use AI in your course, looking for sample syllabus language, or searching for creative ways to enhance student learning, the hub has you covered. It offers a growing collection of tools, tips, and professional development resources to help you get started鈥攐r to go further.

The site will be updated regularly with new content, so check back often. Have a great resource to share or a question about AI in teaching and learning? !

]]>
OneDrive Storage Limits Are Coming /its/onedrive-storage-limits-are-coming/?utm_source=rss&utm_medium=rss&utm_campaign=onedrive-storage-limits-are-coming Wed, 09 Apr 2025 15:08:26 +0000 /its/?p=35228 In response to Microsoft鈥檚 changes in global storage limits for universities and colleges, 杏吧原创 University is putting Microsoft 365 storage limits in place. Over the next few weeks, we will focus on reducing the university’s OneDrive storage.

We need your help to reduce our Microsoft storage footprint and better optimize our Microsoft environment ahead of this change.

]]>
Maintain the Microsoft Authenticator: Disable Features that Auto-Offload Apps /its/2025/disable-features-that-auto-offload-apps-to-maintain-the-microsoft-authenticator/?utm_source=rss&utm_medium=rss&utm_campaign=disable-features-that-auto-offload-apps-to-maintain-the-microsoft-authenticator Thu, 06 Mar 2025 20:56:26 +0000 /its/?p=35117 All students, faculty and staff members should be informed of an important step they may need to take to ensure seamless access to our university’s systems using Multi-Factor Authentication (MFA).

Why is this important?

The Microsoft Authenticator app is a vital tool for verifying your identity when accessing university services. If this app is offloaded by your phone’s automatic offloading feature for seldom-used apps, you may encounter difficulties when trying to authenticate.

To prevent this from happening, we urge you to turn off the automatic offloading feature on your devices.

Steps for iOS Users:

  1. Open the Settings app on your iPhone or iPad.
  2. Scroll down and tap on Apps, then App Store.
  3. Under the Offload Unused Apps section, toggle the switch to off.

Steps for Android Users:

  1. Open the Google Play Store app.
  2. Tap the three lines in the top left corner of the screen.
  3. Tap “Settings.”
  4. Tap “Auto-manage apps.”
  5. Toggle on the switch next to “Archive unused apps.”

NOTE: Steps may vary by device and operating system version. .

By following these steps, you will ensure that the Microsoft Authenticator app remains active on your device, allowing you to authenticate without any interruptions.

Thank you for your attention to this matter. If you have any questions or need further assistance, please do not hesitate to contact the ITS Service Desk.

]]>
Phishing Scams to Watch Out For During the Holiday Break /its/2024/phishing-scams-to-watch-out-for-during-the-holiday-break/?utm_source=rss&utm_medium=rss&utm_campaign=phishing-scams-to-watch-out-for-during-the-holiday-break Tue, 17 Dec 2024 16:41:09 +0000 /its/?p=34888 As we approach the holiday break, ITS encourages the 杏吧原创 University community to be on the lookout for phishing scams.

What are the Various Kinds of Phishing?

Phishing can take many forms including some of the following:

Email phishing: The most commonly used and known kind of phishing is email phishing. The culprits that send these malevolent emails usually claim to be members of respected organizations. Said emails frequently contain urgent warnings of an account being compromised and state that to recover the lost account, the receiver must click on a suspicious looking link to enter their credentials. Email phishing attempts are easier to recognize due to a number of unusual clues that you can learn about by reading our post on What to Do If You Get Phished.

Quishing: Quishing is a new form of phishing that has become more prominent since the start of the pandemic. Scammers have taken advantage of 鈥渜uick response鈥 (QR) codes becoming a more prevalent method of processing data to commit their crimes. Quishing involves cybercriminals sending fake or altered QR codes instead of links. When scanned, victims are sent to malicious websites where their sensitive information may be stolen.

Spear phishing: Most phishing attempts are imprecise attacks sent out to a widespread audience with the goal of catching as many victims as possible. But spear phishing attacks, a kind of attack pinpointed to a select target, are more precise. In order to catch their prey, these attacks are personalized to the individual, with messages containing distinct information about their target鈥檚 interests, family members, friends, experiences, and online activity. Spear phishing is less commonly encountered, as extensive research about targets must be done to execute the attack.

Whaling: Whaling is an even more specific kind of spear phishing attack that narrows its focus towards someone of high influence, such as the CEO of a company. Because of their high standing, these targets often have greater access to libraries of rich, confidential information. In order to accomplish such a feat, cybercriminals often pose as senior members of the organization, making it increasingly difficult for subordinates to deny a request from someone they believe to be of great importance.

SMiShing: Cybercriminals perform SMiShing attacks using Short Message Service (SMS) to create fake profiles disguised as family members needing financial aid, or service providers claiming something is wrong with their accounts. The goal of these scammers is to gain the trust of their target so they can reveal their sensitive information, which can be leveraged for money.

Vishing: Similar to SMiShing, vishing鈥攕hort for voice phishing鈥攊s an over-the-phone scam involving the impersonation of a trustworthy person or service provider (colleague, technical support person, etc.) to fool their victims into revealing sensitive information.

New Trends in Phishing

Social Engineering:

Social engineers are not computer masters who can hijack into systems to steal information. Instead, they are professional manipulators who use their victims鈥 innate desire to help people into deceiving them into giving up their own secretive information. While normal email phishing campaigns can be more easily prevented using AI security measures, no technology can defend against social engineering.

To these kinds of criminals, sensitive information is gold. Personal and financial information such as confidential business files, user IDs and passwords, as well as bank account and credit card info can grant them access to an organization鈥檚 network and enable them to commit fraud.

To defend against these attacks, remember that vigilance is key. Be careful about who you trust online and use your best judgement before passing along any of your information.

WhatsApp:

WhatsApp is a popular messaging app that offers a fast and easy way for families and friends to chat online. Unfortunately, it is also becoming an increasingly more common place for cybercriminals to use for nefarious purposes. Now that people are generally more aware of email phishing scams, cybercriminals are adapting their tactics towards instant communication methods like text messaging and WhatsApp. According to the , there has been a 2,000 per cent increase in WhatsApp scams in the past year.

Some of the methods cybercriminals are using on WhatsApp to deceive victims include:

  • Impersonating loved ones in need of money
  • Sending malicious links that could lead to malware infections
  • Compromising an account and then prompting the victim with a verification code to complete the login
]]>
New VPN Requirement for Gravity Forms /webservices/2024/new-vpn-requirement-for-gravity-forms/#new_tab?utm_source=rss&utm_medium=rss&utm_campaign=new-vpn-requirement-for-gravity-forms Thu, 05 Dec 2024 17:38:05 +0000 /its/?p=34844 Effective today, all web administrators who wish to access files uploaded via Gravity Forms, or to export entries from a form, will be required to be on VPN. This applies to all administrators, including those who are physically located on campus when attempting to access or export form information.

]]>
Cybersecurity Month: Four Ways to Protect Yourself from Phishing Attacks /its/2024/cybersecurity-month-four-ways-to-protect-yourself-from-phishing-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=cybersecurity-month-four-ways-to-protect-yourself-from-phishing-attacks Thu, 24 Oct 2024 17:32:39 +0000 /its/?p=34645 Cybersecurity Month takes place each October, and this year ITS is sharing tips to help keep the 杏吧原创 University community cyber safe.

One of the most widely observed kinds of cyberattacks is phishing, a type of cyberattack where attackers use fraudulent emails, SMS texts and phone calls to solicit sensitive information or deploy malicious software.

Four Ways to Protect Yourself from Phishing Attacks

Learn How to Spot Phishing Attacks

Attackers might send emails, text messages or phone calls, and these messages may ask you to log in to fake websites to steal your username and password. Only open attachments that you are expecting to receive.
It might be a phishing if:

  • It appears to come from someone at the university, but has an [External Email]
  • The subject line is in all caps.
  • It uses a generic greeting, or uses your email address in the greeting. e.g. Dear user, or Dear username@carleton.ca.
  • It asks you to send money, Bitcoin, gift cards etc.
  • It asks you for your password or directs you to a website asking for your password or personal information
  • It includes a call for immediate action like download this now, confirm your email identity now or click on the link below.
  • It tries to invoke an emotional response to get you to take an action without thinking.
  • It includes spelling or grammatical errors.

Use the Report Phishing Button

The Report Phishing button, available in both the Outlook desktop app and Outlook on the web, makes it easy for users to report phishing emails to Microsoft and the ITS Security team. Click the Report Phishing button anytime you believe you have received a phishing email or any potentially dangerous email. Any emails you report using the Report Phishing button will be automatically deleted from your inbox聽and moved to the deleted items folder. They will also be forwarded鈥痶o the ITS Security team聽for analysis聽and to Microsoft to improve filtering rules.

Use Strong and Unique Passwords

Strong, unique passwords can help keep your user accounts safe. When creating a password, use a mix of characters or a phrase, and avoid common passwords like password or 123456.

Enable Multi-Factor Authentication (MFA)

MFA adds an extra layer of protection by requiring at least two forms of authentication. Microsoft MFA is mandatory for all 杏吧原创 faculty and staff members. It is currently being rolled out to students.
MFA is based on:

  1. What you know: Security questions, passwords or PINs. For your 杏吧原创 account, this is your My杏吧原创One password.
  2. What you own: Authentication apps, hardware tokens, or a phone number. For your 杏吧原创 account, this is the Microsoft Authenticator app, or an MFA app of your choosing.

By taking a few important steps, individuals can significantly enhance their cybersecurity posture.
Cyber security doesn鈥檛 end after October, so watch the ITS website for information about new security campaigns, tips and tricks as they become available.

]]>
Communications Hub Provides a Strategic Lens in Support of Finance and Administration Goals /its/2024/communications-hub-provides-a-strategic-lens-in-support-of-finance-and-administration-goals/?utm_source=rss&utm_medium=rss&utm_campaign=communications-hub-provides-a-strategic-lens-in-support-of-finance-and-administration-goals Tue, 08 Oct 2024 16:56:29 +0000 /its/?p=34279 With the goal of supporting the Finance and Administration Strategic Plan, ITS developed and launched its internal Communications Hub in early 2024.

The hub adds a strategic lens to any communication that leaves ITS and provides a consistent communications approach, ensuring our partners and colleagues experience ITS as professional, innovative, collaborative and transformational.

“It鈥檚 important that we align with the commitments as laid out in the Finance and Administration Strategic Plan,” said Chris Cline, ITS Communications Advisor. “We can do that by keeping the commitments at the heart of our work, and incorporating a strategic lens when we communicate with the campus community.”

Building on Successful Communications Initiatives

“The hub builds on recent communications wins for ITS,” said Cline. “We have enhanced our outage notification process, and built a process that better informs the university executive about important IT developments. We have also been able to roll out many successful communications campaigns to promote initiatives such as security awareness, the M365 deployment and the launch of our Digital Strategy.”

The hub will continue to ensure the community has up-to-date information about system availability, software upgrades and changes to ITS’s service offerings. It will continue to build communications campaigns and workshops around digital workplace applications and innovative AI tools, and it will also promote upcoming engagement opportunities with ITS’s CIO and leadership team.

Continuously Improving

In 2024-2025 the hub will work to migrate the ITS website to cuTheme, the university’s new web template with an enhanced design, feel and functionality, and will revamp the site’s information architecture to better serve the university community.

“We’re just getting started,” said Cline. “The 杏吧原创 community will hear much more frequently from ITS going forward, and we are excited to continuously improve the way we communicate our service offerings.”

]]>
IT Policies Streamlined to Provide Practicable Guidance to Stakeholders /its/2024/it-policies-streamlined-to-provide-practicable-guidance-to-stakeholders/?utm_source=rss&utm_medium=rss&utm_campaign=it-policies-streamlined-to-provide-practicable-guidance-to-stakeholders Mon, 07 Oct 2024 13:01:35 +0000 /its/?p=34277 Following recommendations from the 2020 Distributed Computing Audit, the university committed to significantly reduce and streamline IT policies to provide practicable guidance to all 杏吧原创 IT stakeholders.

To achieve this outcome, consultations with key stakeholders were undertaken between 2021 and 2022, with policy development and approval concluding in late-2023.

A joint effort between the Office of the General Counsel, the Privacy Office, the Office of Risk Management and Information Technology Services, this process successfully condensed 15 policies into four and is assisting ITS in operationalize its governance.

These policies were presented to SMC and approved.

More to Come

More work is to come. Detailed technical information will be added to in appendices of the four main policies, and technical requirements will be consistently updated in alignment as necessary.

“With the rapid adoption of AI, we are seeing the most significant change in information technology since the introduction of the World Wide Web in 1993,” said Steve Fraser, Director of Information Security. “This is accompanied by significant changes in the legal, regulatory and insurance compliance requirements for information technology. The university will continue to proactively improve its policies, governance and cybersecurity posture to meet these changes.”

]]>
Digital Steering Committee Launched, Total Cost of Ownership Lens Adopted /its/2024/digital-steering-committee-launched-total-cost-of-ownership-lens-adopted/?utm_source=rss&utm_medium=rss&utm_campaign=digital-steering-committee-launched-total-cost-of-ownership-lens-adopted Fri, 04 Oct 2024 13:00:54 +0000 /its/?p=34273 Following the launch of our Digital Strategy and Roadmap in 2023, the first meeting of the renewed Digital Steering Committee (DSC) was held in Fall 2023 with representation from senior leaders across campus.

During the initial meeting, DSC members received a governance update before learning more about cybersecurity and the Enterprise Resource Planner (ERP) Roadmap.

A subsequent DSC meeting was held in Spring 2024, with more to come in the near future.

Total Cost of Ownership Informs Budget Cycles

Additionally, to help inform budget cycles and understand the financial impact of each project throughout its lifetime, the total cost of ownership (TCO) lens was added to all ITS-managed projects in spring 2024.

“Understanding the TCO for each project is key to our success as an organization,” said Valerie Turner, Chief Information Officer.

“Going forward, the TCO will be a part of all projects brought forward through the Digital Governance process.”

]]>