IA-2 Multi-Factor Authentication: Same Policy, Different Scope
Two agencies. Same checklist answer: multi-factor authentication is required for access to CJI systems. Both had MFA deployed. Both rated IA-2 compliant.
The auditor asked how privileged accounts authenticate.
Agency A confirmed MFA on the primary login portal — the one patrol officers use to access the records system. The IT administrator's account also required MFA for that portal. When the auditor asked about administrative access to the underlying servers and network equipment, the answer was different: those sessions used a shared administrative account with a password. MFA had not been extended to privileged access paths.
Agency B had mapped every access path to CJI: the records system portal, remote sessions, administrative interfaces, the network equipment management console, and the help desk tool. MFA was enforced on each. A shared account did not exist. Each privileged session required individual authentication with MFA.
The auditor noted Agency A's finding: IA-2 is Priority 1, sanctionable since October 1, 2024. The control requires MFA for all accounts with access to CJI systems — not all accounts on the primary portal. Privileged access to infrastructure that processes or stores CJI is within scope.
What the control actually requires
IA-2 requires MFA for local and network access to privileged and non-privileged accounts. IA-2(1) extends the requirement to network access specifically. IA-2(12) requires that PIV credentials or derived PIV credentials are used where applicable.
The scope is not limited to the application layer. An account that can access the database directly, modify network configurations that affect CJI traffic, or administer the systems on which CJI is stored is within the control's scope regardless of whether that account goes through the same portal as end users.
What the auditor is looking for
A complete inventory of accounts with access to CJI systems, including privileged and administrative accounts. Authentication configuration for each account type. Evidence that MFA is enforced on every access path, not just the primary one. A process for removing or modifying access when personnel change roles.
MFA on one door does not satisfy the requirement if other doors are open.
The common failure mode
MFA was deployed for the end-user portal when the records system was configured. Privileged accounts were handled separately by IT, on a different schedule, with different tooling. The two implementations were never reconciled against the full scope of what IA-2 covers. The primary access path is strong. The administrative access paths were never evaluated against the same standard.
Written by Dr. Alexis W. Perdereaux-Weekes
DBA · CISA · CISM · CRISC · CDPSE
Founder, CJIS360 LLC
Sources: CJIS Security Policy v6.1, 06/25/2026 — IA-2 Identification and Authentication (Organizational Users); IA-2(1) Multi-Factor Authentication to Privileged Accounts; IA-2(2) Multi-Factor Authentication to Non-Privileged Accounts; §1.4 Terminology Used in This Document.