Multi-Factor Authentication (MFA) Procedure
DU-2-PRO-717-017 · owner: Operations · QMS clause: 07.01.07
Confidential Business Information (CBI) — do not distribute. This document contains proprietary information of DroneUp, LLC. It is intended solely for the information and use of parties operating on behalf of DroneUp, LLC and its affiliates. Such proprietary information may not be used, reproduced, or disclosed to any other parties for any other purpose without express written permission. The information contained in this document is effective as of the revision date in the document control record.
Revision History
| Version | Date | Description | Updated by |
| 1 | 2026-06-19 | Initial publication. Operationalizes the multi-factor authentication requirements of the Multi-Factor Authentication (MFA) Subpolicy [DU-2-SUB-717-007] for NIST SP 800-171 Rev. 3 control 03.05.03. | Irina Prozhoha |
1. Purpose
This procedure defines the step-by-step process by which DroneUp implements and maintains multi-factor authentication (MFA) for access to all privileged and non-privileged accounts. It operationalizes the multi-factor authentication requirements established in the Multi-Factor Authentication (MFA) Subpolicy [DU-2-SUB-717-007]. Information Systems Personnel, with enrollment performed by All Personnel, shall execute this procedure.
2. Scope
This procedure operates under the authority of the Multi-Factor Authentication (MFA) Subpolicy [DU-2-SUB-717-007] and, through it, the Identification and Authentication Policy [DU-1-POL-717-002] and the Information Security Program Policy [DU-1-POL-521-001], which governs DroneUp’s Information Compliance Program.
Who this applies to: all DroneUp employees, contractors, consultants, and sponsored vendor accounts that authenticate to DroneUp systems, and the Information Systems Personnel who configure and administer the centrally managed identity provider.
What this covers: all DroneUp information systems, applications, and accounts that authenticate through the centrally managed identity provider, regardless of hosting model.
Review and update this procedure at least annually and upon Significant Change, in accordance with the document control record. Non-compliance may result in disciplinary action up to and including termination, as defined in Section 6. Direct questions to the Information Security team through designated support channels.
Compliance and control framework alignment
This procedure is designed to address the Identification and Authentication control family (03.05) of NIST SP 800-171 Rev. 3 — specifically 03.05.03 (Multi-Factor Authentication). It directly implements the requirement to enforce multi-factor authentication for access to both privileged and non-privileged accounts through the centrally managed identity provider, as established in the MFA Subpolicy [DU-2-SUB-717-007]. Permitted authentication factors and their handling are governed by the Authenticator Management Subpolicy [DU-2-SUB-717-009].
3. Objective
This section directly answers the assessment objectives established in NIST SP 800-171A for control 03.05.03. Successful execution of this procedure produces evidence satisfying each objective.
- Multi-factor authentication for access to privileged accounts is implemented. The procedure produces an enforced identity provider MFA policy applied to all privileged account groups, with single-factor paths disabled, and a dated verification record confirming enforcement remains active.
- Multi-factor authentication for access to non-privileged accounts is implemented. The procedure produces the same enforced identity provider MFA policy applied to all non-privileged account groups, together with per-account enrollment records confirming required factors are registered before account use is permitted.
4. Procedure Definition
4.1 Inputs, outputs, and prerequisites
Information Systems Personnel shall confirm the following inputs before starting:
- Approved identity provider MFA policy baseline
- The permitted authentication factor set defined in the Authenticator Management Subpolicy [DU-2-SUB-717-009]
- An active account record from the HR-driven provisioning integration for each account in scope
Outputs produced:
- An enforced identity provider MFA policy covering all privileged and non-privileged accounts
- Per-account factor enrollment records
- A dated verification record confirming enforcement is active
Prerequisites: the account exists and is uniquely identified in accordance with the User Identification and Authentication Procedure [DU-2-PRO-717-023]; the user holds a device compliant with the Acceptable Use Policy [DU-2-POL-710-001] and the Connectivity and Mobility Subpolicy [DU-2-SUB-717-004].
Performers: Information Systems Personnel (primary); All Personnel (factor enrollment).
4.2 Step 1: Configure the identity provider MFA policy
Information Systems Personnel shall:
- Configure the centrally managed identity provider to permit only a password combined with one approved second factor — authenticator-app push, authenticator-app TOTP, device-bound passwordless authentication, or a FIDO2/WebAuthn passkey — and disable SMS and voice-call factors, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009]. *Go criterion: SMS and voice factors confirmed disabled and only approved factors selectable.*
- Configure the identity provider to prefer phishing-resistant factors and to require that the second factor be provided by a device separate from the system gaining access. *Go criterion: policy preview shows phishing-resistant factors offered first and same-device factor satisfaction blocked.*
- Apply the MFA policy to all privileged and non-privileged account groups and disable any single-factor authentication path to DroneUp systems, in accordance with the Identification and Authentication Policy [DU-1-POL-717-002]. *Go criterion: no account group remains exempt and no single-factor sign-in path resolves successfully in test.*
- Configure applications and services to authenticate exclusively through the centrally managed identity provider and remove or disable local application accounts that bypass MFA, unless a written security exception has been approved under Section 5. *Go criterion: each in-scope application authenticates via the identity provider; any retained local account is covered by an approved, unexpired exception.*
- Configure the identity provider to block account use until all required factors are enrolled at initial account activation, applying this to employees, contractors, and sponsored vendor accounts alike, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009]. *Go criterion: a newly activated test account cannot reach protected resources until enrollment completes.*
4.3 Step 2: Enroll accounts and confirm factor registration
Information Systems Personnel shall:
- Enable factor enrollment for each newly activated account and notify the assigned All Personnel to complete enrollment. *Go criterion: enrollment enabled and notification issued for every newly activated account.*
- Confirm in the identity provider that all required factors are registered before releasing the account for use.
- If all required factors are registered: record enrollment completion and release the account for use.
- If any required factor is missing: keep the account blocked, re-notify the assigned All Personnel to complete enrollment, and do not release the account until enrollment is complete.
4.4 Step 3: Maintain and protect authentication factors
All Personnel shall:
- Enroll and maintain the required authentication factors on a device that complies with the Acceptable Use Policy [DU-2-POL-710-001], and protect those factors from loss, sharing, or unauthorized use, in accordance with the Authenticator Management Subpolicy [DU-2-SUB-717-009]. *Go criterion: required factors enrolled on a compliant device.*
- Never share authentication factors, one-time codes, or push approvals with any other person, and approve a multi-factor prompt only for a login they personally initiated. *Go criterion: no shared factors; prompts approved only for self-initiated logins.*
- Report a lost, stolen, or suspected-compromised authenticator to the Information Security team through designated support channels without delay, in accordance with the Event Response Plan [DU-3-WI-940-002]. *Go criterion: any lost or compromised authenticator reported without delay.*
4.5 Step 4: Verify and record ongoing enforcement
Information Systems Personnel shall:
- Verify, on the defined verification cadence, that MFA enforcement remains active for all privileged and non-privileged account groups and that SMS and voice factors remain disabled, and capture a dated verification record. *Go criterion: verification record captured for the period.*
- Address any configuration drift identified during verification.
- If the drift can be corrected: remediate the setting to the established configuration and record the correction.
- If the drift cannot be corrected within the verification window: raise it as an exception under Section 5 and track it to closure.
5. Exceptions
Exceptions to this procedure are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].
6. Enforcement and Sanctions
Enforcement and sanctions are handled in accordance with the Information Security Program Policy [DU-1-POL-521-001].
Document control
| Document number | DU-2-PRO-717-017 |
| Title | Multi-Factor Authentication (MFA) Procedure |
| Classification | CBI |
| Owner | VP of Operations |
| Approval authority | Accountable Security Authority |
| Effective date | 2026-06-24 |
| Revision | 1 |
| Review cycle | Annual; and upon Significant Change |
| Parent document | DU-2-SUB-717-007 |