Kean University – Multi‑Factor Authentication (MFA) & Password Enforcement (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines how Kean University enforces strong authentication through Multi‑Factor Authentication (MFA) and secure password requirements across University systems.
This SOP operationalizes requirements from KU DG 02 – Data Access & Privacy Policy and supports secure identity controls mandated by KU DG 01 – Data Governance & Protection Policy.
Scope
This SOP applies to:
- All users, including employees, contractors, and vendors
- All systems storing or accessing Internal, Confidential, or Restricted data
- Authentication methods including single sign‑on (SSO), VPN, cloud applications, and privileged accounts
This SOP covers MFA enrollment, password standards, enforcement, monitoring, and exceptions.
Definitions
- Multi‑Factor Authentication (MFA) – Authentication using two or more factors (something you know, have, or are).
- Password Complexity – Requirements defining minimum password strength.
- Privileged Account – An account with elevated permissions requiring enhanced protection.
- Sensitive Data – Confidential or Restricted data requiring additional security controls.
Roles & Responsibilities
Users
- Maintain compliant passwords
- Enroll in MFA when required
- Report authentication issues or suspected compromise immediately
Managers
- Ensure staff comply with authentication requirements
- Notify IAM of role changes or separations
Identity & Access Management (IAM)
- Configure and enforce MFA
- Enforce password standards across identity platforms
- Verify identity during recovery actions
IT Security
- Monitor authentication activity
- Investigate anomalous login behavior
- Approve exceptions involving sensitive systems
Procedure
Step 1 — MFA Enrollment
MFA enrollment is required when a user account is created or when access to sensitive systems is granted. Approved factors include authenticator applications and hardware tokens. SMS may be used only as a backup factor.
Step 2 — Password Creation
- Minimum of 12 characters
- Combination of uppercase, lowercase, numbers, and symbols
- No personal identifiers or reused passwords
Step 3 — MFA Enforcement
MFA is enforced for all cloud systems, VPN access, privileged accounts, and systems containing Confidential or Restricted data. Bypass is not permitted except through approved exceptions.
Step 4 — Password Reset & Recovery
Users may reset passwords through self‑service when MFA is enabled. Identity verification is required when MFA recovery is needed.
Step 5 — Authentication Monitoring
Authentication logs are monitored for failed attempts, geographic anomalies, and high‑volume login failures. Alerts are generated for suspicious activity.
Step 6 — Deprovisioning
Upon termination or role change, IAM immediately revokes access and disables MFA tokens. Actions are logged for audit.
Step 7 — Exceptions
Exceptions must follow the Exception Management Policy, include a documented risk analysis, and receive CISO and GRC approval. Exceptions are time‑limited.
Related Policies & Standards
- KU DG 02 – Data Access & Privacy Policy
- KU DG 01 – Data Governance & Protection Policy
- KU ID 01 – Identity & Authentication
- KU ID 02 – Access Control
- KU ID 04 – Privileged Access
- KU SEC 05 – Exception Management
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Protect | PR.AA – Authentication | PR.AA01, PR.AA02 |
| Protect | PR.AC – Access Control | PR.AC02 |
| Detect | DE.CM – Monitoring | DE.CM01 |
Metrics & KPIs
- Percentage of users enrolled in MFA
- Percentage of systems enforcing MFA
- Number of failed MFA attempts per month
- Time to revoke access after separation
Required Records & Storage
- MFA enrollment logs (identity platform)
- Authentication and access logs (SIEM)
- Password reset and recovery records
- Exception approvals (GRC repository)
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Identity & Access Management Lead | Chief Information Security Officer |
``