Library / IT-02

IT-02 Password and MFA Standard

IT-02 Password and MFA Standard

Revision 4 · Effective 2026-01-12

1 Purpose

This standard sets the password and multi-factor authentication (MFA) requirements for Tallgrass accounts. It applies the current guidance that long passphrases and phishing-resistant MFA protect accounts better than frequent forced password changes.

2 Scope

This standard applies to every Tallgrass Microsoft 365 account (employees and contractors), every administrator account, and the shared shop-floor kiosk accounts in section 5.6. Account creation and removal are covered by IT-04.

3 Definitions

  • Passphrase: a password made of several words or a long phrase, for example four unrelated words with spaces.
  • Number matching: the Microsoft Authenticator sign-in check where the user types the two-digit number shown on the sign-in screen into the app.
  • FIDO2 security key: a physical USB or NFC key that proves identity without a password being typed.
  • adm- account: a separate administrator account used only for administrative tasks.

4 Responsibilities

  • Users choose a compliant passphrase, register MFA, and never share credentials or approve sign-ins they did not start.
  • IT enforces these settings in Microsoft Entra ID and Intune, issues security keys, and verifies identity before any reset.
  • Managers make sure new staff complete MFA registration on their first day.

5 Requirements

5.1 Passphrase length and content

Passwords must be at least 14 characters. A passphrase of several words is recommended. Passwords are checked against the Microsoft Entra banned password list, which rejects common passwords and variations of "Tallgrass". Do not reuse a Tallgrass password on any other website or service.

5.2 Password changes

There is no scheduled password expiry. Change your password only when compromise is suspected: if you entered it on a phishing page, saw an unexpected MFA prompt, or IT asks you to. Report any suspected compromise under IT-06 at the same time.

5.3 Multi-factor authentication

MFA is required for every account. The approved method is Microsoft Authenticator with number matching. SMS text messages and voice calls are not allowed MFA methods. Never approve a sign-in request you did not start; report unexpected prompts to the help desk (ext. 2210) as a security incident.

5.4 Administrator accounts

Administrative work is done only with a separate "adm-" account (for example, adm-skettering), never with the everyday account used for email and web browsing. adm- accounts sign in with a FIDO2 security key issued by IT. adm- accounts have no mailbox and must not be used to read email or browse the internet.

5.5 Account lockout

An account locks after 10 failed sign-in attempts and unlocks automatically after 15 minutes. If you are locked out repeatedly without having mistyped your password, contact the help desk, because this can indicate an attack.

5.6 Shared shop-floor kiosk accounts

Shop-floor kiosks in the production bays sign in automatically with a shared kiosk account. Kiosk accounts are not personal Microsoft 365 user accounts: they have no mailbox, no email, no Teams and no OneDrive. They are locked down so that only the ERP shop-floor client and a read-only viewer for released work instructions can run. Each person then signs in to the ERP shop-floor client with their own badge and personal PIN, so all labor and inspection entries are attributed to an individual. Badge PINs must not be shared. A kiosk session returns to the start screen after 10 minutes without use.

5.7 Resets and lost MFA devices

Users reset a forgotten password with self-service password reset, verified through Microsoft Authenticator. If a phone with Authenticator is lost or replaced, the help desk re-registers MFA only after verifying identity in person or by a call back to the number on file with HR. A lost phone or security key is also reported under IT-06.

6 Records

Sign-in logs, MFA registration and security key assignments are kept in Microsoft Entra ID. IT keeps the register of issued FIDO2 security keys, including the user and serial number.

7 Revision history

Rev Date Change Approved by
3 2024-02-05 Required MFA for all accounts; added kiosk account rules. Sam Kettering
4 2026-01-12 Minimum length raised from 10 to 14 characters (passphrases); removed 90-day mandatory change and 12-password reuse history; SMS removed as an MFA method, Authenticator with number matching required; adm- accounts now require FIDO2 security keys; lockout changed from 5 attempts / 30 minutes to 10 attempts / 15 minutes. Sam Kettering