Method 1: If you cannot connect to Sophos Connect VPN because your password has expired
1. Go to myaccount.microsoft.com and choose Change Password under the Password section.
2. Confirm your old password and double type your new password. use the guidelines below to set a valid, secure password. Confirm the new password.
Important please take a note of the additional information below specifically the password requirements as Office 365 will not take into account the settings of our On premises Domain controller and will allow an invalid password change to occur which will lock your account out further and require assistance from IT to resolve.
3. Once you have changed your password, connect to the Sophos Connect VPN with the new password.
4. While connected to the VPN lock your device and unlock it again with the new password or your account will lock out.
Method 2: If you can connect to Sophos Connect VPN, or are in the office
1. Press CTRL + ALT + DELETE and choose Change Password.
2. Provide your current password and double type your new password, use the guidelines below to set a valid, secure password. Confirm the new password.
3. To check, lock your device in the CTRL + ALT + DELETE menu and unlock using the new password.
4. This password will automatically sync to Office 365 so there is no need to change it there as well.
Additional information:
Passwords will expire every 365 days.
The password complexity requirements are as follows:
- Must contain at least 14 characters
- Must contain at least 1 upper case character
- Must contain at least 1 number
- Cannot contain more than two consecutive characters from your username
- Cannot be the same as a previous password
Choosing secure passwords
You should not use information about yourself that other people could find out, especially from social media, e.g. pets names, nicknames.
It is recommended to use a password that is unique and not one that you also use outside of work. This reduces the risk of your work account being compromised if any of your personal accounts are for any reason.
It is recommended to use "three random words" as a password because you are more likely to remember it, but it is still reasonably difficult to crack if you are hacking into an account. It also makes it less likely that you will feel the need to write the password down, which will compromise the security of your account.
You can generate random passwords using this method at the following sites:
Create Secure Memorable Passwords Online | Password Generator (passwordgenerators.org)
Correct Horse Battery Staple: xkcd-Style Password Generator
The best way is to keep generating new passwords until you find one that you like, as you are more likely to remember it that way.