IT-02 Password and MFA Standard
Revision 3 · Effective 2024-02-05
1 Purpose
This standard sets the password and multi-factor authentication (MFA) requirements for Tallgrass accounts so that a stolen or guessed password alone cannot be used to reach company email, files or systems.
2 Scope
This standard applies to every Tallgrass Microsoft 365 account (employees and contractors), every administrator account, and the shared shop-floor kiosk accounts in section 5.6. Account creation and removal are covered by IT-04.
3 Definitions
- MFA: a second check at sign-in in addition to the password.
- Password history: the record of previous passwords that the system will not accept again.
- adm- account: a separate administrator account used only for administrative tasks.
4 Responsibilities
- Users choose a compliant password, change it when required, register MFA, and never share credentials.
- IT enforces these settings in Microsoft Entra ID and Intune and verifies identity before any reset.
- Managers make sure new staff complete MFA registration on their first day.
5 Requirements
5.1 Password length and content
Passwords must be at least 10 characters. Passwords are checked against the Microsoft Entra banned password list, which rejects common passwords and variations of "Tallgrass". Do not reuse a Tallgrass password on any other website or service.
5.2 Password changes and reuse
Passwords must be changed every 90 days. Users receive a reminder in Windows and Outlook 14 days before expiry. The last 12 passwords cannot be reused. Change your password immediately if you believe it has been disclosed, and report it to the help desk (ext. 2210).
5.3 Multi-factor authentication
MFA is required for every account. Allowed methods are the Microsoft Authenticator app or an SMS text message to a registered mobile number. The Authenticator app is preferred. Never approve a sign-in request you did not start.
5.4 Administrator accounts
Administrative work is done only with a separate "adm-" account, never with the everyday account used for email and web browsing. adm- accounts follow the same password and MFA rules as user accounts in this standard, have no mailbox, and must not be used to read email or browse the internet.
5.5 Account lockout
An account locks after 5 failed sign-in attempts and unlocks automatically after 30 minutes. If you are locked out repeatedly without having mistyped your password, contact the help desk.
5.6 Shared shop-floor kiosk accounts
Shop-floor kiosks in the production bays sign in automatically with a shared kiosk account. Kiosk accounts are not personal Microsoft 365 user accounts: they have no mailbox, no email, no Teams and no OneDrive. They are locked down so that only the ERP shop-floor client and a read-only viewer for released work instructions can run. Each person then signs in to the ERP shop-floor client with their own badge and personal PIN, so all labor and inspection entries are attributed to an individual. Badge PINs must not be shared. A kiosk session returns to the start screen after 10 minutes without use.
5.7 Resets and lost MFA devices
Users reset a forgotten password with self-service password reset, verified through Microsoft Authenticator or an SMS code. If a registered phone is lost or replaced, the help desk re-registers MFA only after verifying identity in person or by a call back to the number on file with HR.
6 Records
Sign-in logs, password change events and MFA registration are kept in Microsoft Entra ID.
7 Revision history
| Rev | Date | Change | Approved by |
|---|---|---|---|
| 2 | 2021-06-14 | MFA required for remote and email access. | Sam Kettering |
| 3 | 2024-02-05 | Required MFA for all accounts; added kiosk account rules. | Sam Kettering |