Verifying UAlbany Students’ Identities for Online Learning
Online courses at the University at Albany are delivered through the University's learning management system, Brightspace. Students, faculty and staff access Brightspace using their UAlbany NetID and password.
NetIDs are assigned through established University identity and access management processes. Student enrollment information is maintained in UAlbany systems and is used to ensure students have access only to the courses in which they are officially enrolled.
For UAlbany users, Brightspace access requires Multi-Factor Authentication (MFA) through the University's 2-Step with Duo service. In addition to a username and password, Duo requires users to verify their identity using a second method of authentication, such as the Duo Mobile application, a hardware token or another approved authentication option.
This additional layer of security helps protect University accounts and information from unauthorized access.
Students who choose not to use a smartphone, do not have access to a smartphone or are otherwise unable to use the Duo Mobile application may request a hardware token through Information Technology Services (ITS).
Student Identity Verification
Access to Brightspace is managed through University-issued credentials and, where applicable, MFA through 2-Step with Duo. Official course-related communications are conducted through University-approved systems and communication channels.
For UAlbany students, faculty and staff, identity verification is supported through all the following:
- A unique UAlbany NetID and password assigned to each user
- Authentication through the University's identity management systems
- Required use of 2-Step with Duo when accessing Brightspace and other protected University services
- Alternative authentication options, including University-issued hardware tokens for users who cannot use the Duo Mobile application
- Enrollment and course access controls that limit access to authorized users
UAlbany accounts are created and managed through established institutional processes. Individuals cannot self-enroll for University credentials or independently obtain access to credit-bearing courses outside of approved registration and enrollment procedures.
Protection of Student Privacy
The University uses established information security and privacy practices to protect student information and support identity verification efforts. These practices comply with applicable federal and state laws, including the Family Educational Rights and Privacy Act (FERPA).
Security measures include:
- Secure authentication processes
- Password management requirements
- Multi-Factor Authentication (MFA)
- Encrypted communications
- Other safeguards designed to protect student records and University information
Information collected for authentication and identity verification is used only for legitimate educational, administrative and security purposes.
Charges Associated with Identity Verification
There are no additional fees associated with student identity verification for University-supported online courses.
Students may use the Duo Mobile application on a personal device, or they may request a hardware token from ITS if they prefer not to use a smartphone or are unable to do so.
Hardware tokens are provided by the University to support secure access to UAlbany systems and services.
Responsibility for Identity Verification
Information Technology Services (ITS) is responsible for maintaining the technical systems that support identity verification, including University authentication services such as 2-Step with Duo.
Academic units are responsible for ensuring that online courses are delivered in accordance with applicable academic integrity, distance education and instructional requirements.
Student Responsibility for Safeguarding Credentials
Students play an important role in protecting the security of their accounts. Students are responsible for safeguarding their NetID and password, Duo devices, authentication codes, hardware tokens, and any other credentials used to access University systems.
Credentials must not be shared or used by anyone other than the account holder. Students are responsible for all activities conducted through their accounts.
Allowing another individual to access a course, complete coursework, submit assignments, participate in discussions or assessments, or otherwise represent themselves as the enrolled student is a violation of University policy, including:
Students are expected to take reasonable steps to protect their account information and promptly report any suspected unauthorized access or compromised credentials.