Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

Logon Policy

This policy defines the security controls, authentication standards, and session boundaries required to access anDREa B.V. (anDREa) systems and infrastructure. This framework aligns directly with ISO 27001:2023 (A.08.05 - Secure Authentication, A.08.19 - Access Rights) and NIS 2 (Access Control & Identity Management), ensuring comprehensive access management across our decentralized cloud environments.

This policy undergoes mandatory evaluation and revision at least annually, or immediately following significant structural or identity infrastructure updates.


1. Scope of Enforcement

This policy applies universally to all personnel, contractors, and administrators who hold or manage an identity credential granting access to any anDREa asset, platform component, or internal service.

Enforced Domains

  • All internal corporate accounts issued under the andrea-cloud.com domain space.
  • All environment administration identities managed within the platform's mydre.org domain space.
  • External guest accounts provisioned within the anDREa Microsoft Entra ID (formerly Azure Active Directory).
  • Federated tenant domain accounts, where technically and contractually enforceable.
note

Scope Exclusion: This policy does not govern the independent local account settings of end-user researchers inside their isolated project environments; however, their external guest identities utilized to bridge access into the anDREa Entra ID are fully bound by these controls.


2. Core Authentication & Identity Controls

Standard Credential Requirements

Access to anDREa information systems requires a unique, non-shared identity consisting of a designated username and a strong password managed in strict compliance with the formal Password Policy.

Multi-Factor Authentication (MFA)

Multi-Factor Authentication is universally mandatory across all scoped identity environments.

  • Advanced Contextual Prompts: App-based authentication utilizing the Microsoft Authenticator app enforces advanced verification safety nets, including mandatory two-digit Number Matching, geographic location validation, and explicit application context naming.
  • Hardware Tokens & Passwordless Authentication: The use of FIDO2-compliant physical hardware security keys (e.g., YubiKeys) or passwordless verification paths is supported and highly recommended.
  • Personnel Mandate: The use of physical hardware security keys is strictly mandatory for all core anDREa staff members.
  • Policy Exemptions: Any deviation from the hardware key requirement for staff requires formal, recorded sign-off from the Director or the Operations Manager and must be archived within the Policy Exceptions Log.

Session Lifecycles

To minimize session hijacking vulnerabilities, the maximum authorized lifespan of any active authentication token is restricted to 24 hours. Users must re-authenticate and clear MFA validation challenges at least once every 24 hours to maintain access continuity.


3. Session Security, Idle Timeouts, & Auditing

Device Inactivity and Session Locks

  • Virtual Machine Safeguards: Inactivity within an active myDRE Virtual Machine automatically triggers a localized system session lock. Resuming the workstation requires re-entering the user's password.
  • Endpoint Stewardship: Users must operate from secure, properly managed host devices. Physical workstations must never be left unattended without actively engaging a biometric or password-protected system lock.

Self-Service Identity Auditing

Users can proactively monitor their active sign-in footprints and account security histories to detect anomalous access attempts.

  • Audit Pathways: Platform participants can audit access history by navigating to the Manage your Account section located adjacent to their profile name on the myDRE dashboard, or by securely authenticating directly to mysignins.microsoft.com.

Governance Reference: Administrative entitlements and group memberships are periodically verified and managed in strict accordance with the Access Review Policy.