A.8.5 Secure Authentication
Control Objective
Secure authentication technologies and procedures shall be implemented based on information access restrictions and the topic-specific policy on access control.
Policy Statement
anDREa enforces enterprise-grade, cryptographically secure authentication mechanisms across all cloud environments, infrastructure layers, and operational SaaS utilities. To defend against identity-based threat vectors, access to anDREa assets requires mandatory Multi-Factor Authentication (MFA) tailored to the classification and perceived risk of the underlying information system.
1. Microsoft Ecosystem & myDRE Platform Authentication
Authentication for the core myDRE infrastructure and integrated Microsoft cloud environments is centralized within anDREa's Entra ID tenant under strict technical enforcement rules:
- Mandatory Multi-Factor Authentication: All accounts—including internal employees, external contractors, and primary myDRE research end users—require MFA activation immediately upon onboarding via a secure, time-limited activation link.
- Context-Aware Authentication Policies: Text message (SMS) or basic voice call codes are prohibited for the Microsoft ecosystem. All users must authenticate using the Microsoft Authenticator App with the following conditional security controls actively enforced:
- Number Matching: The user must enter the exact numerical string displayed on the login screen into their authenticator application.
- Application Context: The app displays the identity of the specific application requesting access.
- Geolocation Context: The app displays the map coordinates and location of the authentication request.
- Logon Policy: Broad behavioral requirements for passwords, passphrases, and tokens (Logon policy)
- PIM/PAM verification: Real-time activation timestamps and justification logs for MFA resets and periodic reviews (Azure PIM Review).
MFA Reset and Lifecycle Governance
To prevent account-takeover attacks through social engineering, user self-service MFA resets are strictly disabled:
- Standard Platform Users: If an end user loses their authentication token, they must log a support ticket with their local Research Support Team (RST). The ticket is then escalated to the internal anDREa Support Team.
- Support Elevation Constraints: To execute an MFA reset, an anDREa Support Team member must dynamically activate the Authentication Administrator role using Azure Privileged Identity Management (PIM) (see A.08.02 - Privileged access rights).
- Privileged Identity Escalation: MFA resets for high-clearance personas (RST members, internal engineers, or system administrators) require the activation of a separate, high-severity PIM role: Privileged Authentication Administrator.
2. Non-Microsoft & Corporate SaaS Applications
For corporate and business utilities operating outside the primary Microsoft tenant, authentication baselines are determined by risk profile:
- Medium to High-Risk Systems: For all non-Microsoft business architectures that handle company or privacy-sensitive data (e.g., our corporate Google Workspace domains, core financial applications, and 1Password enterprise vaulting), MFA is strictly mandatory. Users may leverage alternative industry-accepted authenticator software (such as Google Authenticator or 1Password) where Microsoft Authenticator integration is unavailable.
- Low-Risk Systems: For any secondary utility classified as Low / Public, enabling MFA remains highly recommended if the software provider supports it natively.