Account Update

From Network for Advanced NMR
Revision as of 19:02, 14 September 2026 by Mmaciejewski (talk | contribs)
Jump to navigationJump to search

Starting Tuesday, September 22, 2026, all NMRhub users will be required to use two-factor authentication (2FA) to log in to NMRhub services. This includes the NMRhub, NMRbox, and NAN websites, SSH and RealVNC connections to NMRbox servers, and FileZilla file transfers to and from NMRbox servers.

As part of this change, NMRhub accounts are being migrated to a new account management system. Every account requires a one-time password reset, so all users must complete the setup below.

Before you start, install an authenticator app on your phone. The process takes about five minutes and has three parts: resetting your password, setting security questions, and adding NMRhub to your authenticator app.

A note on phishing: this process starts with you. You will only receive a password reset email from support@nmrhub.org after you begin logging in at NMRhub. If you receive a reset email you did not request, do not click the link. Forward it to support@nmrhub.org instead.

Step 1: Start the login process

Go to the NMRhub User Dashboard and begin logging in with your current NMRhub username and password. You will not be able to finish logging in yet. Instead, the system sends a password reset email to the institutional email address associated with your NMRhub account.

The email comes from support@nmrhub.org and looks like this:

Dear <user>,

We received a request to reset your password for NMRhub username: <username>

Please click here and follow the prompts to update your password.

If you did not request a password reset, please contact us at: support@nmrhub.org

Thank you,

NMRhub Support Team

UConn Health

The magic link in this email expires after 24 hours. If the link expires, return to the login page and start again to receive a new one.

If the email does not arrive

  • Allow a few minutes for delivery, then check your spam or junk folder.
  • If you no longer have access to the institutional email address on your NMRhub account, head to NMRhub Forgot Password page and login with your ORCID iD to follow the same recovery/upgrade worflow.

Step 2: Reset your password and set security questions

Click the link in the email. You will be guided through two screens.

Reset your password. Enter a new password that meets the NMRhub password complexity rules. Note: If you have reset your password recently, this screen is skipped and you go straight to the security questions.

Set your security questions. Create and answer the security questions. These are used to verify your identity if you are locked out , so create questions and answers that you will not forget and which are secure.

Record your answers somewhere safe, such as your password manager. Answers are case sensitive.

Step 3: Add NMRhub to your authenticator app

You will be shown a QR code. Open your authenticator app, choose the option to add a new account, and scan the code.

Scan this QR code with your authenticator app.

Most TOTP authenticators work, including Google Authenticator, Authy, Duo Mobile, Okta Verify, Microsoft Authenticator, and FreeOTP. Some password managers, such as 1Password, can also store TOTP codes. If you cannot scan the code, most apps let you type in the setup key shown beneath it instead.

Once added, your app will display a six digit code for NMRhub that changes every 30 seconds.

If the QR code setup goes wrong, click the link in your email again. It is valid for 24 hours, and if it has expired you can start the login process again to get a new one. You will not be asked to reset your password a second time, only to confirm your security questions, and then you can scan a new QR code. You can also add additional authenticators later.

Step 4: Log in

After you finish setting up the 2FA authenticator, log into NMRhub - You will be required to enter a One-Time-Password (OTP) generated in your phone authenticator app.

While you may save your password in a password manager, the OTP will be generated in real time and need to be entered after the previous 2FA authentication expires.