Chunks (3)
Workforce MFA baseline
~49 tokAll workforce users must enroll MFA for SSO, email, and VPN. Acceptable factors include hardware security keys (preferred), authenticator apps, and number matching push. SMS OTP is allowed only as a temporary break-glass method with ISSO approval.
Remote admin MFA requirements
~68 tokMFA requirements for remote admins are stricter: remote privileged access requires phishing-resistant MFA using FIDO2 / WebAuthn hardware keys. Password-only remote admin login is forbidden. Admin sessions through the privileged access workstation (PAW) require re-authentication every 8 hours and step-up MFA for production changes. Session recording is enabled for SEV-impacting administrative actions.
Exceptions
~34 tokTemporary MFA exceptions require written ISSO approval, expire within 7 days, and are tracked in the GRC system. Compensating controls include IP allowlisting and heightened monitoring.