Kean University DG – Multi‑Factor Authentication (MFA) & Password Enforcement (SOP) 3


Kean University – Multi‑Factor Authentication (MFA) & Password Enforcement (SOP)

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines how Kean University enforces strong authentication through Multi‑Factor Authentication (MFA) and secure password requirements across University systems.

This SOP operationalizes requirements from KU DG 02 – Data Access & Privacy Policy and supports secure identity controls mandated by KU DG 01 – Data Governance & Protection Policy.

Scope

This SOP applies to:

  • All users, including employees, contractors, and vendors
  • All systems storing or accessing Internal, Confidential, or Restricted data
  • Authentication methods including single sign‑on (SSO), VPN, cloud applications, and privileged accounts

This SOP covers MFA enrollment, password standards, enforcement, monitoring, and exceptions.

Definitions

  • Multi‑Factor Authentication (MFA) – Authentication using two or more factors (something you know, have, or are).
  • Password Complexity – Requirements defining minimum password strength.
  • Privileged Account – An account with elevated permissions requiring enhanced protection.
  • Sensitive Data – Confidential or Restricted data requiring additional security controls.

Roles & Responsibilities

Users

  • Maintain compliant passwords
  • Enroll in MFA when required
  • Report authentication issues or suspected compromise immediately

Managers

  • Ensure staff comply with authentication requirements
  • Notify IAM of role changes or separations

Identity & Access Management (IAM)

  • Configure and enforce MFA
  • Enforce password standards across identity platforms
  • Verify identity during recovery actions

IT Security

  • Monitor authentication activity
  • Investigate anomalous login behavior
  • Approve exceptions involving sensitive systems

Procedure

Step 1 — MFA Enrollment

MFA enrollment is required when a user account is created or when access to sensitive systems is granted. Approved factors include authenticator applications and hardware tokens. SMS may be used only as a backup factor.

Step 2 — Password Creation
  • Minimum of 12 characters
  • Combination of uppercase, lowercase, numbers, and symbols
  • No personal identifiers or reused passwords
Step 3 — MFA Enforcement

MFA is enforced for all cloud systems, VPN access, privileged accounts, and systems containing Confidential or Restricted data. Bypass is not permitted except through approved exceptions.

Step 4 — Password Reset & Recovery

Users may reset passwords through self‑service when MFA is enabled. Identity verification is required when MFA recovery is needed.

Step 5 — Authentication Monitoring

Authentication logs are monitored for failed attempts, geographic anomalies, and high‑volume login failures. Alerts are generated for suspicious activity.

Step 6 — Deprovisioning

Upon termination or role change, IAM immediately revokes access and disables MFA tokens. Actions are logged for audit.

Step 7 — Exceptions

Exceptions must follow the Exception Management Policy, include a documented risk analysis, and receive CISO and GRC approval. Exceptions are time‑limited.

  • KU DG 02 – Data Access & Privacy Policy
  • KU DG 01 – Data Governance & Protection Policy
  • KU ID 01 – Identity & Authentication
  • KU ID 02 – Access Control
  • KU ID 04 – Privileged Access
  • KU SEC 05 – Exception Management

Compliance Mapping

NIST CSF Function Category Subcategory
Protect PR.AA – Authentication PR.AA01, PR.AA02
Protect PR.AC – Access Control PR.AC02
Detect DE.CM – Monitoring DE.CM01

Metrics & KPIs

  • Percentage of users enrolled in MFA
  • Percentage of systems enforcing MFA
  • Number of failed MFA attempts per month
  • Time to revoke access after separation

Required Records & Storage

  • MFA enrollment logs (identity platform)
  • Authentication and access logs (SIEM)
  • Password reset and recovery records
  • Exception approvals (GRC repository)

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release Identity & Access Management Lead Chief Information Security Officer

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.