Multi-Factor Authentication Policy
This Multi-Factor Authentication Policy ("Policy") describes multi-factor authentication ("MFA") requirements for the Services, MiseCentral staff Support Mode, and Partner Support Mode. This Policy supplements the Authentication Policy and Access Control Policy.
Capitalized terms not defined herein have the meanings set forth in the MiseCentral Legal Library Defined Terms or the applicable Agreement.
1. Purpose
1.1. MFA reduces the risk of unauthorized access resulting from compromised passwords or stolen credentials. MiseCentral supports organization-configurable MFA mandates for Customer organizations and enforces platform-level MFA for privileged assistance activities.
1.2. This Policy describes available organization MFA modes, enrollment and enforcement mechanics, Service Account exemptions, lockout prevention, and Support Mode MFA requirements.
2. Supported MFA Methods
2.1. MiseCentral supports time-based one-time password ("TOTP") authenticator applications compatible with standard TOTP protocols, as described in Documentation.
2.2. MiseCentral may add additional MFA methods over time. Documentation identifies supported methods available to Customer organizations, staff, and Partners.
2.3. SMS-based MFA may be offered where supported and appropriate; TOTP is the primary recommended method for interactive users.
3. Organization MFA Policy Modes
3.1. Customer administrators configure an organization MFA policy selecting one of the following modes:
(a) Optional — MFA is available but not required for any member. This is the default for new organizations unless otherwise stated in an Order Form.
(b) Administrators Required — Organization owners and administrators must enroll and use MFA. Non-administrative Authorized Users may use MFA voluntarily but are not mandated unless the organization later selects a broader mode.
(c) All Required — All active organization members must enroll and use MFA, except Service Accounts explicitly exempted under Section 4.
3.2. Organization MFA policy is managed through organization administration settings and recorded in audit logs.
3.3. Organization MFA policy applies to interactive login and session establishment for Authorized Users within the Customer organization. It does not replace platform MFA requirements for MiseCentral Support Mode or Partner Support Mode.
4. Service Account Exemption
4.1. When enabled in organization settings, Service Accounts used for non-interactive system-to-system access may be exempt from organization MFA mandates.
4.2. Exempt Service Accounts remain subject to credential protection, scope limitation, monitoring, and prompt revocation requirements. Exemption does not reduce Customer responsibility for securing integration credentials.
4.3. Customer administrators should enable Service Account exemption only where MFA is impractical for automated workflows and compensating controls are in place.
5. Enforcement Schedule and Grace Period
5.1. Customer administrators may configure an enforcement date on which the selected MFA mode becomes mandatory. Before the enforcement date, the mode is advisory and users may enroll voluntarily.
5.2. Customer administrators may configure a grace period following the enforcement date during which members who have not enrolled may still authenticate with warnings indicating pending MFA requirement. Grace period length is configurable within limits described in Documentation.
5.3. After expiration of the grace period, members subject to the mandate must complete MFA enrollment and verification to establish a session, except where lockout prevention in Section 6 applies.
5.4. Changes to organization MFA policy, enforcement date, or grace period generate audit events and may include an impact preview describing affected members.
6. Lockout Prevention
6.1. Administrative Lockout Prevention on Policy Change. MiseCentral prevents configuration changes that would immediately mandate MFA for all administrators when no administrator has enrolled MFA and no grace period or future enforcement date provides a recovery path. Customer administrators must enroll at least one administrator in MFA, or configure a future enforcement date or grace period, before enabling a restrictive mandate without protection.
6.2. Login Lockout Prevention. If an organization MFA mandate is active and an administrator subject to the mandate has not enrolled MFA, but no administrator in the organization has enrolled MFA, login is not hard-blocked without a recovery path. The affected administrator receives guidance to enroll MFA or contact organization recovery procedures. This prevents total administrative lockout of the organization.
6.3. Support Recovery. Where organizational recovery requires MiseCentral assistance, MiseCentral verifies authority through procedures designed to protect Customer security and may require Support Mode coordination with Customer administrators.
6.4. Lockout prevention does not weaken MFA requirements once at least one administrator has enrolled and grace periods have expired for members subject to the mandate.
7. Platform Support Mode MFA
7.1. MiseCentral requires platform MFA for Support Mode sessions initiated by MiseCentral staff in sensitive roles, including Founder, Platform Operations, Security, Finance, and Support roles, independent of Customer organization MFA settings.
7.2. Staff must have MFA enabled and verified on their MiseCentral identity before initiating or continuing Support Mode. This requirement is enforced separately from Customer organization MFA policy.
7.3. Platform Support Mode MFA ensures that privileged assistance to Customer organizations is protected by strong staff authentication even when the Customer organization uses Optional MFA mode.
8. Partner Support Mode MFA
8.1. MiseCentral requires platform MFA for Partner Support Mode sessions initiated by Partner Users, independent of Customer organization MFA settings.
8.2. Partner Users must have MFA enabled and verified on their Partner identity before initiating or continuing Partner Support Mode under an active Customer delegation.
8.3. Partner Support Mode MFA applies in addition to Partner RBAC and Customer delegation scope limits.
9. MFA Lifecycle
9.1. Enrollment. Users enroll MFA through organization security settings by registering a TOTP authenticator application and verifying a generated code.
9.2. Verification at Login. When MFA is required, users enter a valid second factor after primary authentication. Sessions may record MFA verification status for the session lifetime according to security settings.
9.3. Recovery Codes. Where offered, single-use recovery codes may be generated at enrollment. Users must store recovery codes securely. Compromised recovery codes must be regenerated promptly.
9.4. Reset and Re-enrollment. MFA devices may be reset by administrators or through verified self-service flows. Resets generate audit events.
9.5. Loss of Device. Users who lose MFA devices must follow administrator or support recovery procedures. MiseCentral does not bypass MFA based on unverified requests.
10. Customer Responsibilities
10.1. Customer administrators select the appropriate organization MFA mode for their risk profile and regulatory context.
10.2. Customer administrators communicate enrollment expectations to Authorized Users and monitor compliance before and after enforcement dates.
10.3. Customer administrators maintain at least one MFA-enrolled administrator or a documented recovery plan before enabling Administrators Required or All Required modes.
11. Audit and Transparency
11.1. Organization MFA policy changes, enrollments, resets, and enforcement events are recorded in audit logs available to Customer administrators as described in the Logging and Audit Policy.
11.2. Support Mode and Partner Support Mode session records indicate that platform MFA requirements were satisfied for the assisting actor where applicable.
12. Policy Updates
12.1. MiseCentral may update MFA methods, enforcement mechanics, or platform Support Mode MFA role lists by updating this Policy and Documentation.
13. Contact
MiseCentral LLC Attn: Security 8 The Green, Suite A Dover, DE 19901 United States security@misecentral.com
Version history
| Version | Effective | Summary |
|---|---|---|
| 1.0 | August 1, 2026 | Initial publication of the Legal Library (LEGAL-01). |
Previous versions remain available for reference and are never overwritten.