LASSX
Aegis Defense Systems — Production
Demo retrieval
Sources

Multi-Factor Authentication Standard

MFA requirements for workforce, remote access, and privileged administration

Indexed
markdown
Policies & CUI
Updated Aug 4

Chunks (3)

Workforce MFA baseline

~49 tok

All workforce users must enroll MFA for SSO, email, and VPN. Acceptable factors include hardware security keys (preferred), authenticator apps, and number matching push. SMS OTP is allowed only as a temporary break-glass method with ISSO approval.

Remote admin MFA requirements

~68 tok

MFA requirements for remote admins are stricter: remote privileged access requires phishing-resistant MFA using FIDO2 / WebAuthn hardware keys. Password-only remote admin login is forbidden. Admin sessions through the privileged access workstation (PAW) require re-authentication every 8 hours and step-up MFA for production changes. Session recording is enabled for SEV-impacting administrative actions.

Exceptions

~34 tok

Temporary MFA exceptions require written ISSO approval, expire within 7 days, and are tracked in the GRC system. Compensating controls include IP allowlisting and heightened monitoring.