How-To Guides — IT Admin
Multi-Factor Authentication
Multi-factor authentication is mandatory for every APBnet™ user and enforced automatically — there's no agency-level setting to turn on. Here's what that means day to day, and what to do when a user gets stuck.
MFA is built in, not something you configure
CJIS Security Policy requires multi-factor authentication for anyone accessing Criminal Justice Information Services data, and APBnet™ enforces it platform-wide by default. There's no IT Admin toggle to enable or waive it — every user completes MFA enrollment the first time they log in, as part of account onboarding, before they can reach any bulletin data.
What to expect
- Each new user sets up MFA themselves during onboarding — there's nothing for IT Admin to enable in advance.
- Users set up an authenticator app (TOTP) — SMS isn't an available option. Nobody can skip enrollment or defer it to later.
- Let new users know MFA enrollment is coming as part of their first login, so it doesn't catch them off guard.
How enrollment works
- 1
A new user logs in for the first time and is prompted to set up MFA.
This happens automatically as part of onboarding — there's no separate step for IT Admin to trigger it.
- 2
The user sets up an authenticator app.
Authenticator app (TOTP) — generates time-based codes using apps like Google Authenticator, Authy, or Microsoft Authenticator. This is the only supported method — APBnet™ does not offer SMS-based verification.
- 3
The user completes enrollment and MFA applies to every login from then on.
There's no exception list and no way for a user to opt out once they're enrolled — by design, given the CJIS requirement above.
Tips
Give new users a heads-up before their first login
MFA enrollment happens the moment a new user first logs in, with no warning built into the flow itself. Telling people ahead of time — and pointing them to an authenticator app like Google Authenticator or Authy — heads off most support requests before they start.
Lost device process
If a user loses their MFA device and can't log in, contact APBnet™ support to reset their MFA enrollment. The user will need to re-enroll with their new device. There is no self-service bypass — this is by design for security.
Related guides
Configuring Allowed Domains & Whitelisting
Set up allowed email domains and network whitelisting alongside MFA.
Read the guide →
Managing Device Access Controls
Control which devices are authorized to access APBnet™.
Read the guide →
Program Admin: Controlling Feature Access
Feature-level settings sit with Program Admin — a separate role from IT Admin.
Read the guide →