How-To Guides — IT Admin

Multi-Factor Authentication

Multi-factor authentication is mandatory for every APBnet user and enforced automatically — there's no agency-level setting to turn on. Here's what that means day to day, and what to do when a user gets stuck.

IT Admin

MFA is built in, not something you configure

CJIS Security Policy requires multi-factor authentication for anyone accessing Criminal Justice Information Services data, and APBnet enforces it platform-wide by default. There's no IT Admin toggle to enable or waive it — every user completes MFA enrollment the first time they log in, as part of account onboarding, before they can reach any bulletin data.

What to expect

  • Each new user sets up MFA themselves during onboarding — there's nothing for IT Admin to enable in advance.
  • Users set up an authenticator app (TOTP) — SMS isn't an available option. Nobody can skip enrollment or defer it to later.
  • Let new users know MFA enrollment is coming as part of their first login, so it doesn't catch them off guard.

How enrollment works

  1. 1

    A new user logs in for the first time and is prompted to set up MFA.

    This happens automatically as part of onboarding — there's no separate step for IT Admin to trigger it.

  2. 2

    The user sets up an authenticator app.

    Authenticator app (TOTP) — generates time-based codes using apps like Google Authenticator, Authy, or Microsoft Authenticator. This is the only supported method — APBnet™ does not offer SMS-based verification.

  3. 3

    The user completes enrollment and MFA applies to every login from then on.

    There's no exception list and no way for a user to opt out once they're enrolled — by design, given the CJIS requirement above.

Tips

Give new users a heads-up before their first login

MFA enrollment happens the moment a new user first logs in, with no warning built into the flow itself. Telling people ahead of time — and pointing them to an authenticator app like Google Authenticator or Authy — heads off most support requests before they start.

Lost device process

If a user loses their MFA device and can't log in, contact APBnet™ support to reset their MFA enrollment. The user will need to re-enroll with their new device. There is no self-service bypass — this is by design for security.

Related guides