Security Tools & Resources at Pitt

The University of Pittsburgh provides a layered set of security tools at no cost to students, faculty, and staff. No single tool is sufficient on its own — antivirus catches what reaches the endpoint, VPN protects the connection, encryption protects data at rest, and multifactor authentication protects the account. Use this article to find the right tool for what you're trying to protect, who it's available to, and where to get it.

For University-managed computers, most of this is already done for you.
University-managed Windows and Mac computers come with Microsoft Defender for Endpoint and the recommended baseline configuration preinstalled. The tools below are the ones individuals install themselves on personal devices, plus the discovery and encryption tools available through the Software Download Service.

At a Glance

Pitt-provided security tools by category, audience, and access point
Category Tool Who Can Use It Where to Get It
Multifactor Auth Duo Students, Faculty, Staff Pitt Passport & Duo
Antivirus Microsoft Defender / Defender for Endpoint Students, Faculty, Staff Antivirus for Personal Devices
Secure Connection PittNet VPN (GlobalProtect) Students, Faculty, Staff PittNet VPN service page
OS & Software Updates Windows Update / macOS Software Update Students, Faculty, Staff Built into the operating system
File Encryption SecureZIP (Windows) Students, Faculty, Staff Getting Started with SecureZIP — Windows
Full-Disk Encryption BitLocker (Windows) / FileVault (macOS) Faculty, Staff Departmental IT or Technology Help Desk
Email Encryption Outlook message encryption Students, Faculty, Staff Outlook Email Encryption Security Guide
Sensitive Data Discovery Spirion Identity Finder Faculty, Staff, Dept. IT Software Download Service
Vulnerability Scans Departmental security consultation Departmental IT staff Security Vulnerability Assessment service
Email Threat Protection Exchange Online Protection, Safe Links Students, Faculty, Staff Threat Protection service

Multifactor Authentication (Duo)

Duo is required for any service that authenticates through Pitt Passport — my.pitt.edu, Microsoft 365 (Outlook, Teams, OneDrive), Canvas, PeopleSoft, Pitt Worx, Box, DocuSign, EZproxy, PittNet VPN, and the rest of the single sign-on ecosystem. A stolen password alone does not give an attacker access to a Duo-protected account.

Phishing-resistant methods are recommended for new enrollments.
Pitt Digital recommends platform authenticators (Touch ID, Windows Hello, Face ID) and hardware security keys for new Duo enrollments. These resist the credential-phishing attacks that target push-notification approval.

Enroll in Pitt Passport & Duo

Antivirus and Anti-spyware

Antivirus is the endpoint layer — it protects the device itself against malware that gets past mail filtering or arrives over the web or removable media. Pitt provides antivirus at no cost for personal Windows and Mac computers, and University-managed computers receive Microsoft Defender for Endpoint centrally.

PERSONAL DEVICES

Antivirus for Personal Devices

Step-by-step guidance for Windows and Mac, including the built-in Microsoft Defender on Windows and recommended options for macOS.

Antivirus for Personal Devices

UNIVERSITY-OWNED

Antivirus on University Systems

How Microsoft Defender for Endpoint is managed on University-owned computers and what to expect from centralized monitoring.

Antivirus for University Owned Systems

Secure Connection

PittNet VPN (GlobalProtect) lets students, faculty, and staff connect to restricted University resources when off campus or when on the PittNet wireless network. The VPN encrypts traffic between your device and Pitt's network and is required for some administrative systems and library resources from off-campus.

Duo is required to authenticate to the VPN.
GlobalProtect uses Pitt Passport, so you will be prompted for a Duo second factor each time you connect. Enroll in Duo before installing GlobalProtect if you have not already.

PittNet VPN (GlobalProtect)

Software & Operating System Updates

Every operating system and application carries software bugs, and some of those bugs are security flaws that attackers actively exploit. Keeping your operating system and applications current — and configured to update automatically — is the single highest-leverage security practice for a personal device.

WINDOWS

Windows Update

Microsoft releases security updates for Windows and other Microsoft products through Windows Update. Configure it to download and install updates automatically.

Windows Update FAQ (Microsoft)

macOS

macOS Software Update

Apple delivers free updates through System Settings and the App Store. Configure macOS to install security responses and operating-system updates automatically.

Update macOS (Apple Support)

University-managed computers are patched centrally.
If your computer is managed by a Pitt department, OS and application updates are scheduled and deployed by your local IT — you do not need to manage Windows Update or macOS Software Update yourself.

Encryption

Encryption protects data at rest and in transit — on a hard drive, on removable media, or inside an email message. Pitt provides three complementary capabilities:

Security Vulnerability Scans

Departmental vulnerability assessments — identifying missing patches, weak configurations, and known-vulnerable software on Windows, Mac, and Linux endpoints and servers — are coordinated through Pitt Digital Security under the Security Vulnerability Assessment service. Departmental IT staff can request a consultation to scope a scan, review findings, and plan remediation.

How to request a vulnerability assessment.
Open the Security Vulnerability Assessment service page and select Request Help, or call the Technology Help Desk at 412-624-HELP (4357). Have your responsibility center, the scope of devices to be scanned, and the operational window for scanning ready when you contact us.

Sensitive Information Discovery

Spirion Identity Finder is the tool of record for sensitive data discovery at Pitt. Spirion scans workstations (and, with departmental IT, servers) for sensitive information that may be stored locally — Social Security numbers, payment card data, protected health information, and other regulated data types — and helps you remediate findings by deleting, redacting, or encrypting them in place.

Running a discovery scan periodically is the most reliable way to find data that shouldn't be on an endpoint: forgotten exports from a system of record, draft documents that were never deleted, or files inherited from a previous employee. Even if you believe no sensitive data is stored locally, run a scan — the most common Spirion finding is data the owner had genuinely forgotten was there.

Download Spirion from the Software Download Service

Act on findings promptly.
A scan that finds Restricted data on an endpoint creates a documentation trail. Move the data to an approved storage location (or delete it if it is no longer needed) before closing the scan record — and report any suspected unauthorized exposure to Pitt Digital Security immediately.

Email Threat Protection

Pitt Email (Outlook) includes Exchange Online Protection to filter spam, viruses, and phishing before messages reach your inbox, plus Safe Links to evaluate URLs in real time when you click them. Both controls are enabled by default for every Pitt mailbox — no installation required.

Threat Protection service

Key Contacts

Technology Help Desk 412-624-HELP (4357)
Installation help, tickets, general support
Pitt Digital Security Via Help Desk
Suspected incidents, account compromise
Software Download Service Open software.pitt.edu
Download SecureZIP, Spirion, and other licensed tools
Request Help Print Article

Related Articles (8)

The University of Pittsburgh relies on a layered approach to security. No single process or technology is sufficient to secure the University’s environment. Instead, we have a robust series of security controls that operate at different layers and perform different tasks. A threat that manages to circumvent one control is likely to be thwarted by a control in another layer.
How to begin using PKWARE’s SecureZIP
Pitt Passport is the University’s single sign-on service that delivers a consistent, trusted login experience across a range of University services.
Electronically stored academic, administrative, and research information is a critical University resource. All University units are required to use enterprise email, web services, and network firewalls. These Enterprise Security Controls help protect University data and significantly reduce security vulnerabilities. See the Enterprise Security Controls Policy for additional information about these requirements.
This article discusses the requirement for PittNet VPN (GlobalProtect) for end users to provide advanced data security and enhanced protection against viruses, spyware, and application vulnerabilities.
The questionnaire provides Pitt Digital Information Security with the information to understand the product or services that the vendor will provide to the University. It also defines the assessment scope, identifies the University’s potential risk, and collects the vendor’s contact information.
The steps on this page provide antivirus guidance for personal devices.
Pitt Digital Security offers University departments access to leading practices and expert guidance for ensuring network security and managing incidents. Contact us any time to discuss our offered services for proactively mitigating risks or in any instance where you think an incident has occurred.

Related Services / Offerings (1)

SECURE COMPUTING The University of Pittsburgh has a robust series of security controls to protect from threats including Enterprise Spam and Virus Filter with Exchange Online Protection and Microsoft Defender for Endpoint.