Skip to content
BCN-T2-IAM-001Tier 2 · RegulatoryIdentity & Access Management

Non-Compliant Authentication Policy

Password and authentication settings that do not meet the applicable regulatory standard.

Remediation SLA
30 days
Tier
2 · Regulatory
Domain
Identity
Escalation
Security manager review at 14 days

What this finding is

Authentication policy diverges from the requirements of an applicable framework — password length or complexity below the mandated minimum, absent lockout thresholds, missing session timeouts, or MFA not extended to the full population the standard names. The finding concerns the general user population; privileged accounts without MFA are BCN-T1-IAM-001.

Why it is Tier 2

Authentication settings are among the first items an assessor tests, because they are objectively verifiable from a configuration export. Deficiencies are cited reliably and are usually straightforward to remediate. Note that frameworks have diverged: NIST SP 800-63B now discourages mandatory periodic rotation and composition rules, while PCI DSS v4.0 continues to specify minimums — where a policy must satisfy both, the stricter applies.

Most common misclassification

Frequently over-escalated to Tier 1 because it concerns authentication. Weak policy on non-privileged accounts is a compliance deficiency; missing MFA on privileged accounts is the Tier 1 case.

How to detect it

  1. 1Export the effective authentication policy from every identity provider and compare against each applicable framework's requirement.
  2. 2Check for policy exceptions and exempted groups, which is where non-compliance concentrates.
  3. 3Confirm the policy applies to federated and guest identities, not only to accounts created locally.
  4. 4Verify session timeout and re-authentication settings, which are commonly overlooked and explicitly required.

How to remediate it

Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.

  1. 1Set policy to the strictest applicable requirement across frameworks in scope and apply it uniformly.
  2. 2Prefer length and breach-corpus screening over composition rules, which is both current guidance and more effective.
  3. 3Remove standing exemptions; where one is genuinely required, record it as a formal, time-bounded exception with compensating controls.
  4. 4Extend MFA coverage to the full population once privileged accounts are complete.
  5. 5Retain the policy export as evidence, since assessors ask for the configuration rather than the intent.

How to verify the fix

A configuration export from each identity provider satisfies every applicable requirement with no unexplained exemptions, and a test account confirms enforcement in practice.

Mappings

Attacker techniques

Weakness

Compliance mappings

  • PCI DSS v4.0
    8.3.6 — minimum password strength
  • NIST SP 800-63B
    5.1.1 — memorized secret requirements
  • ISO/IEC 27001:2022
    A.5.17 — authentication information
  • SOC 2
    CC6.1 — logical access

Tools that surface this

PROWLERScoutSuiteidentity provider configuration export