If you access your HDM email account using applications such as Microsoft Outlook, Apple Mail, or the Mail app on your smartphone, app-specific passwords can provide an additional layer of account security.
An app-specific password is a unique, randomly generated password assigned to one particular application or device.
Instead of entering your primary email password into every device you use, each application can receive its own password.
Using a different password for individual email applications provides several security advantages.
For example, imagine you have your email configured on:
If your smartphone is lost, you can revoke only the password assigned to that phone. Your office computer and laptop can continue accessing your email normally.
App-specific passwords can also help protect your primary email password. If an application or device is compromised, your main account password has not necessarily been exposed.
App-specific passwords and two-factor authentication are separate security features.
Two-factor authentication (2FA) adds a verification code when accessing webmail through a browser.
App-specific passwords control access from applications such as Outlook, Apple Mail, and mobile email clients.
You can use either feature by itself or use both together for additional account protection.
You can create up to four app-specific passwords per email account.
Whenever possible, use a separate password for each important device or application.
Give each password a descriptive name such as:
This makes it much easier to identify which password should be removed if a device is lost, replaced, or no longer used.
An app-specific password is displayed only once, immediately after it is generated.
You should enter the password directly into the email application you are configuring.
If you need to temporarily copy it somewhere, store it securely.
If the password is lost, it cannot be displayed again. You will need to delete the existing app-specific password and generate a new one.
To create a new password:
Remember that the generated password will not be displayed again after you leave the screen.
Enter the generated password wherever your email application normally asks for your email account password.
For example, if you are configuring your email on a smartphone, use:
Username: Your full email address
Password: The newly generated app-specific password
Do not substitute your normal webmail password when the application has been assigned an app-specific password.
You should remove an app-specific password when:
To remove one:
The application associated with that password will no longer be able to access your email.
You can generate a replacement app-specific password whenever needed.
If your email application is requesting a password or repeatedly reports an authentication error, confirm that it is using the correct app-specific password.
If you no longer have the password that was originally generated, remove the old app-specific password from webmail and create a new one.
Then update the password stored in your email application.
Ideally, enter the password directly into the application when it is generated.
If you must retain it, use an appropriate password manager rather than storing it in an unsecured document, note, email, or text message.
Never send app-specific passwords or your primary email password through unsecured communication channels.
One of the major advantages of app-specific passwords is the ability to revoke access to an individual device.
If a phone, tablet, or computer containing your email account is lost:
The missing device will no longer be able to authenticate using that app-specific password.
You can then create a new password when configuring your email on a replacement device.
If you aren't sure whether you need an app-specific password or are having difficulty configuring your email application, contact Hazel Digital Media (HDM) for assistance.
HDM can help determine whether the issue involves your primary password, two-factor authentication, an app-specific password, or your email application's account configuration.
For your security, never send HDM your password or temporary authentication code unless you are following a verified support procedure specifically requiring it.