Your email account is often connected to many of the other services you use. Password-reset messages, billing notifications, business applications, cloud services, and other sensitive information frequently pass through email, making strong email security especially important.
HDM-hosted email accounts provide two useful security features: two-factor authentication (2FA) and app-specific passwords.
This FAQ explains what each feature does and answers some of the most common questions about using them.
Two-factor authentication adds a second verification step when signing in to webmail.
Instead of relying only on your email address and password, 2FA also requires a temporary six-digit security code generated by an authenticator app or delivered to your phone.
Even if someone obtains your password, they would still need access to your second authentication method to sign in through webmail.
An app-specific password is a randomly generated password used by an individual email application, such as:
Instead of giving the application your primary email password, you give it its own unique password.
This allows access for an individual application to be removed without changing your main email password everywhere else.
No.
They protect different methods of accessing your email account.
Two-factor authentication protects webmail access.
When signing in through a web browser, you'll enter your regular password followed by a temporary authentication code.
App-specific passwords protect access from email applications.
An email application such as Outlook or Apple Mail can be assigned its own unique password rather than using your primary account password.
The two security features can be used independently or together.
Not necessarily.
You can use either feature independently. However, using both provides additional control over how your email account can be accessed.
For example, you might use:
Each method protects a different access point.
An authenticator app is generally recommended over SMS.
Authenticator apps generate temporary security codes directly on your trusted device and do not rely on the cellular text-message network.
Compatible apps include Google Authenticator, Microsoft Authenticator, FreeOTP, and many other applications supporting the TOTP authentication standard.
SMS is still available for users who prefer receiving their authentication code by text message.
If you are replacing your phone or want to move authentication to another device, make the change before erasing or giving up access to your current phone.
The simplest process is:
This also applies when changing the mobile phone number used for SMS authentication.
If your phone contains your authenticator app, disable or transfer your 2FA configuration before performing a factory reset.
Resetting a phone can remove the authentication information required to generate your login codes.
Depending on the authenticator app you use, cloud backup or account-transfer features may also be available. Review the documentation for your authentication application before resetting or replacing your device.
If you lose your phone, reset it unexpectedly, or otherwise lose access to your authentication codes, you may be unable to complete the webmail login process.
Contact Hazel Digital Media (HDM) for assistance.
For security reasons, HDM may need to verify your identity or authorization before making changes to the security configuration of an email account.
Once access has been restored, you should configure 2FA again using your current device.
An email application configured to use an app-specific password must use the password generated specifically for that application.
If your phone, tablet, Outlook, Apple Mail, or another email client stops authenticating, check whether an app-specific password needs to be created or updated.
You can generate one by signing in to webmail and navigating to:
Settings → Password → App Password
Once the new password has been generated, enter it into the password field of the corresponding email application.
It is better to give each application its own app-specific password whenever possible.
For example:
Giving each application a recognizable name makes it easier to identify and revoke access later.
If you lose a device, you can remove the password assigned to that device without disrupting the others.
Password changes may not take effect properly while 2FA is active.
If you need to change your primary email password, first disable 2FA, update the password, and then configure 2FA again.
Make sure you have access to your authentication device before beginning this process.
App-specific passwords are displayed only when they are first generated.
If you no longer have the password, you cannot display the existing password again. Instead:
Each HDM-hosted email account can have up to four app-specific passwords.
Using descriptive names for each password makes them easier to manage.
If you're unable to access your email because of two-factor authentication, a device change, or an app-specific password issue, contact Hazel Digital Media (HDM).
Please do not send your password or authentication codes through unsecured messages. HDM will provide appropriate instructions based on your situation.