More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
docs
betterdocs_faq

Use User Mobile – Phone number as First Time Password instead of the random number

Updated on July 8, 2026

6 min to read

 

Overview

This article explains the application setting that controls whether a newly created user’s mobile or home phone number is used as their very first login password, instead of a password that the system generates automatically. It describes what the setting does, where it applies, the business rules behind it, and guidance on when to turn it on or off.

 

What This Setting Does

When a new online account is created in the system – for example when a new Student, Teacher, or Parent record is registered – the system must assign that person an initial password so they can log in for the first time. This setting decides how that initial password is created.

  • When this setting is turned ON, the system uses the person’s mobile phone number (the one entered on their record) as their first-time password.
  • If no mobile phone number was entered, the system uses the home phone number instead, if one is available.
  • If neither a mobile nor a home phone number is on file, the system automatically falls back to a randomly generated password, so no account is ever left without a password.
  • When this setting is turned OFF (the default), the system always assigns a randomly generated password to new accounts, regardless of whether a phone number is available.

 

Where It Is Used

This setting is found at: Core Settings > Security Settings > Basic Settings.

It is applied automatically, in the background, at the exact moment a new online account is created for the following types of people:

  • Students
  • Teachers
  • Parents / Guardians
  • Other contacts such as Agents, Employees, or partner Companies who are given portal access

This setting only affects the password given out when an account is first created. It does not apply to:

  • Existing accounts that already have a password
  • The Forgot Password process
  • A password change made later by the user themselves
  • Accounts that log in using Microsoft 365 / Office 365 or Google Sign-In – for these accounts, this setting has no effect, since login is handled by the external sign-in provider rather than by a password issued by the system.

 

Business Logic / Behavior

The following business rules apply when this setting is enabled:

  • Mobile number takes priority over home number. If both are on file, the mobile number is always the one used as the password.
  • The phone number is used exactly as entered (only extra blank spaces at the beginning or end are removed). It is not reformatted, shortened, or checked for a minimum length.
  • If no phone number is available at all, the system automatically issues a randomly generated password instead, following its normal password rules. No account is created without a usable password.
  • This setting does not force the user to change their password on their first login. That is a separate behavior, controlled by the related setting described in the Notes section below.
  • Any password strength requirements the institution has configured (for example, requiring a minimum length or a mix of letters and numbers) do not apply to this system-generated first password, whether it comes from a phone number or from the random generator. Strength requirements only apply when a person chooses or changes their own password afterwards.
  • This behavior is identical in both K-12 mode and Higher Education mode. Enabling or disabling Higher Education mode does not change how this setting works.

The following are reasonable conclusions based on how this setting behaves, rather than rules stated directly in the system:

  • Because a phone number can be shared by more than one person (for example, several children of the same family sharing a parent’s mobile number, or a guardian’s number appearing on more than one student record), it is possible for more than one account to be issued the same first-time password when this setting is enabled.
  • Because the phone number itself is often already known to relatives, classmates, or colleagues, this option favors convenience and a quick first login over the unpredictability of a random password.

 

Example(s)

 

Example 1 – Mobile number available: At Alpha Institute, this setting is turned ON. A new student, Anna K., is registered with mobile phone number 6971234567 and no home phone. When her account is created, her first-time password is set to 6971234567. The front desk simply tells Anna: her first password is her mobile number.

Example 2 – Only a home phone on file: At Beta College, this setting is turned ON. A new teacher, George S., is registered without a mobile number but with a home phone number of 2101234567. Since no mobile number exists, the system uses the home phone number instead, so George’s first password becomes 2101234567.

Example 3 – No phone number on file: At Alpha Institute, a new parent, Maria P., is registered but no phone number was entered on her record. Even though the setting is turned ON, the system cannot use a phone number, so it automatically generates a random password for Maria instead, following its usual random password rules.

Example 4 – Choosing to turn the setting off: Gamma Academy prefers not to use phone numbers as passwords, since several siblings in the same family often share their parents’ mobile number. Gamma Academy leaves this setting OFF, so every new account – student, teacher, or parent – always receives its own unique, randomly generated first password.

Example 5 – Let’s create new student with phone number e.g., 6971595815

 

 

Pupil’s first password is 6971595815

 

 

Setting -> Inactive

First password contains random characters

 

 

When to use

 

When to Enable

  • The institution wants a simple, easy-to-remember first password for new users, so new Students, Teachers, or parents can log in immediately using a number they already know.
  • Front-desk or admissions staff need a fast way to communicate login credentials to a large number of new users at once (for example, during bulk enrollment or the start of a new academic year), without generating and distributing separate passwords individually.
  • Mobile (or at least home) phone numbers are consistently and accurately collected for every person during registration or admission.

When to Disable

  • Phone numbers are often missing, optional, or not reliably collected, which would cause many accounts to fall back to random passwords anyway, creating an inconsistent experience.
  • More than one person may share the same phone number (for example, a shared family or guardian number), which could result in more than one account having the same first password.
  • The institution wants to enforce a strong password policy from the very first login, since a phone number will not comply with typical password strength rules.
  • The institution prefers to rely on the related first-logon password change setting together with a randomly generated password, so every new user is required to set their own private password before using the system.

 

Notes

For this setting to take effect, mobile or home phone numbers need to be collected as part of registering each Student, Teacher, Parent, or other contact. If no phone number is on file for a person, the system automatically issues a random password instead, regardless of this setting.

The following settings are related to, or can affect, this one:

  • “Password Strength Policy” (“Core Settings > Security Settings > Basic Settings” – Password_Strength_Policy) – defines password strength rules for user-chosen passwords; it does not apply to the first password generated by this setting.
  • “Change password at first logon for new Portal users” (“Core Settings > Security Settings > Basic Settings” – Allagi_Password_Sto_Proto_LogOn_Gia_Neous_Xristes_Sto_Portal) – controls whether new users must set a new password the first time they log in; this is independent of how the first password itself was generated.
  • “Show first password to staff” (“Core Settings > Security Settings > Basic Settings” – Show_FirstPassword_to_Staff) – allows staff to view a new user’s first password directly on their profile; when this setting is enabled, that first password will be the person’s phone number.
  • Welcome / invitation notification settings (“Core Settings > Security Settings > Invitation Letters – New Account”) – control whether new students, parents, and teachers automatically receive a notification containing their new account details, including their first password.
  • “Enable Configuration for Higher Education” (“Core Settings > Higher Education Customization > Basic Settings” – Xrisi_parametropoihshs_kolegiou) – switches the system between K-12 and Higher Education mode; it does not change how this setting behaves.

If the institution uses Microsoft 365 / Office 365 or Google Sign-In for user logins, this setting has no practical effect, since those accounts authenticate through the external sign-in provider rather than through a password issued by the system.

 

 

 

Was this article helpful?