A university campus scene showcases students using digital tools, with a laptop displaying a password reset screen.
Michigan State University has told its entire community to reset passwords after what it calls a "potential credential compromise." That means every student, faculty member and staff member. It is a useful case study for anyone who runs identity systems tied to Microsoft 365, and for anyone who is about to be locked out of Teams.

What MSU has said so far​

MSU IT is requiring all MSU users to reset their MSU NetID password while suspicious cybersecurity activity is investigated. The State News reported that the school became aware of suspicious cybersecurity activity and began investigating right away. The newspaper dated its story October 5. The university's own advisory says the reset began October 1.

Spokesperson Amber McCann gave the most specific description. She told the Detroit Free Press, via Yahoo, that the activity appears to be a potential credential compromise event, meaning the cyber event was focused on accessing user login information. The State News adds her statement that the event did not "indicate a successful compromise" of the university's Active Directory. She also said there was no evidence that other MSU data had been accessed, changed or stolen.

MSU IT's advisory adds that, currently, there is no evidence of malware, data corruption, or unauthorized activity within individual MSU accounts. It also says the university's security measures continue to function as designed.

What MSU has not said​

"No evidence" is not the same as "did not happen," and MSU describes the investigation as ongoing. The public statements I found do not name any of the following:

  • How the activity occurred.
  • Who is behind it.
  • How many credentials were targeted.
  • Whether any credentials were actually obtained.
  • How long the activity lasted.

The advisory says additional details regarding the activity will be shared as appropriate through established university channels. It gives no timetable.

This is not a reported Microsoft breach. Microsoft 365 shows up in MSU's notice only because those services depend on the NetID password.

What MSU users need to do​

MSU's instructions are short:

  1. Do nothing until prompted. Please do not change your password until you are prompted.
  2. The next time you sign in using your MSU account, you will be prompted to reset your password.
  3. Follow the instructions to create a new password with at least 15 characters.
  4. Expect to sign in again everywhere. After your password is reset, you will need to sign in again to MSU services and applications, including Microsoft 365, Outlook email, Teams and VPN services. Campus systems such as EBS, D2L and SIS are also on the list.
  5. Expect it on every device. You may be prompted to sign in again on multiple devices, including computers, phones, and tablets.

MSU also said the reset is unrelated to recent power plant, utility, or mechanical system issues on campus.

Practical tips for the reset​

A forced reset often fails on stale saved passwords. These points are general IT experience, plus one older MSU help article. They are not guidance written for this incident.

  • Update saved passwords on phones and tablets. Old credentials left in mail apps or Wi-Fi profiles can keep retrying and trigger lockouts. Other universities' NetID guides warn about exactly this.
  • Remote Windows users: lock and unlock after the reset. An older MSU IT knowledge-base article about changing a known password says remote users should connect to the MSU VPN, lock the computer, and then unlock it with the new password. Otherwise the cached password does not update. That article predates this incident, so check whether MSU IT has current advice.
  • Stuck? MSU's IT knowledge base says users who cannot reset should call the MSU IT Service Desk at 517-432-6200 for assistance.
  • Be wary of "reset help" messages. A mass reset is exactly when phishers pose as IT. MSU's advisory says the reset prompt appears at sign-in, so don't act on unsolicited links.

Why this matters beyond East Lansing​

A "credential-focused" event usually means attackers are after logins rather than malware or direct data theft. That is general industry context, not a confirmed finding about MSU. A university-wide reset is a blunt tool that costs a lot of help-desk time. It makes sense when you can't say which accounts are exposed. A 15-character minimum also suggests MSU is tightening its baseline, though it hasn't said so.

Admins of Entra ID or on-premises Active Directory environments can draw some lessons from the rollout:

  • Prompt-at-sign-in resets keep users from changing passwords early or late.
  • Tell users in advance which services will ask them to sign in again.
  • Publish one clear help channel.
  • Be honest about what is and isn't known.

Whether the investigation finds a successful credential theft is the open question. For now, MSU users should wait for the prompt and then choose a long password they haven't used anywhere else.

 

References

  1. MSU examines 'potential credential compromise' after cyber event - The State News The State News Tue, 06 Oct 2026 02:53:02 GMT
  2. Why Michigan State is making students, employees reset passwords yahoo.com
  3. NetID - How To Reset a NetID Password tdx.msu.edu