- Free Edition
- Quick Links
- MFA
- Microsoft Entra ID Security
- Self-Service Password Management
- Single Sign-On
- Password Synchronizer
- Password Policy Enforcer
- Employee Self-Service
- Reporting and auditing
- Integrations
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- Exchange Reporter Plus Exchange Server Auditing & Reporting
- EventLog Analyzer Real-time Log Analysis & Reporting
- M365 Manager Plus Microsoft 365 Management & Reporting Tool
- DataSecurity Plus File server auditing & data discovery
- RecoveryManager Plus Enterprise backup and recovery tool
- SharePoint Manager Plus SharePoint Reporting and Auditing
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools
What are CJIS password requirements?
The Criminal Justice Information Services Division (CJIS) is a division of the Federal Bureau of Investigation (FBI) that sets mandatory security controls for any organization with access to criminal justice information (CJI), including law enforcement agencies, courts, contractors, and correctional facilities.
CJIS v6.1, released June 25, 2026, maintains alignment with NIST SP 800-63B, requiring length-based standards, breach screening, annual memorized secret rotation, and risk-based authentication controls in place of rigid composition rules. The table below explains selected password and authentication requirements and how ManageEngine ADSelfService Plus helps your organization comply.
CJIS password requirements and ADSelfService Plus capabilities
Password requirements
| CJIS Control | Requirement | How ADSelfService Plus Helps |
|---|---|---|
| IA-5 [P1] — Minimum password length | If chosen by the subscriber, memorized secrets shall be at least 8 characters in length. If chosen by the CSP or verifier using an approved random number generator, memorized secrets shall be at least 6 characters in length. | ADSelfService Plus's Password Policy Enforcer allows admins to configure a minimum and maximum password length, enforced across Active Directory and Entra ID users. |
| IA-5 [P1] — Banned password list | Verifiers shall maintain a list of commonly used, expected, or compromised passwords and compare prospective secrets against it during creation, change, or reset. If a match is found, the user shall be required to choose a different password. | ADSelfService Plus integrates with Have I Been Pwned to screen passwords against their breached passwords database at the point of creation or reset, blocking any compromised credential. Admins can also configure custom banned word lists for context-specific terms. |
| IA-5 [P1] — Banned list updates | The banned password list shall be updated quarterly and when organizational passwords are suspected of compromise. | Admins can update ADSelfService Plus's custom banned word lists at any time. The Have I Been Pwned integration reflects the service's continuously updated breach database. |
| IA-5 [P1] — Password hints | Verifiers shall not permit the subscriber to store a hint that is accessible to an unauthenticated claimant. Verifiers shall also not prompt subscribers to use specific types of information (e.g., security questions) when choosing memorized secrets. | ADSelfService Plus allows administrators to configure identity verification methods used during self-service password reset and account unlock. Password hints are not stored or displayed during any self-service operation, meaning unauthenticated users cannot access hint information at any point in the reset or unlock workflow.Note that security questions are available as an optional authenticator in ADSelfService Plus. Administrators should ensure this factor is disabled for CJIS-regulated users, as CJIS policy prohibits prompting users to use specific types of information when choosing memorized secrets. |
| IA-6 [P3] — Password display | Authentication feedback shall be obscured during the authentication process to protect against exploitation by unauthorized individuals. Acceptable methods include displaying asterisks when users type passwords, or displaying feedback for a very limited time before obscuring it. | ADSelfService Plus does not display passwords by default; users may optionally reveal their entry. |
| IA-5 [P1] — Forced reset on compromise | Verifiers shall force a change of memorized secret if there is evidence of compromise of the authenticator. | Administrators can immediately trigger a forced password reset for any user in Active Directory or Entra ID whose credentials have been flagged as potentially compromised. |
| IA-5 [P1] — Annual rotation | Memorized secret authenticators shall be changed or refreshed at least annually, or when there is evidence of authenticator compromise. | ADSelfService Plus allows administrators to configure scheduled password expiration policies across Active Directory and Entra ID, prompting users to reset their passwords on a defined cycle to satisfy the CJIS annual rotation requirement. |
| AC-7 [Existing] — Unsuccessful logon attempts | The system shall enforce a limit of consecutive invalid access attempts and automatically lock the account or node for an organization-defined time period, or lock until released by an administrator. | ADSelfService Plus allows administrators to configure the failed login attempt threshold and lockout duration to meet their agency's defined policy. Account lockout until released by an administrator is the primary control per v6.1 AC-7, which enforces a limit of five consecutive invalid attempts within a 15-minute window. Timed-unlock is available as an operational exception. |
MFA and access control requirements
| CJIS Control | Requirement | How ADSelfService Plus Helps |
|---|---|---|
| IA-2(1) [P1] — MFA for privileged accounts | Multi-factor authentication shall be employed for access to privileged accounts. | ADSelfService Plus enforces endpoint MFA for privileged account logins across endpoint, VPN, OWA, RDP, and cloud application access, with the option to apply stricter factor requirements to administrator accounts. |
| IA-2(2) [P1] — MFA for non-privileged accounts | Multi-factor authentication shall be employed for access to non-privileged accounts. | ADSelfService Plus provides context-based MFA with 20 different authentication factors—including FIDO passkeys, biometrics, YubiKey, and TOTPs—enforced across all organizational user accounts. |
| AC-17 [P1] — Remote access | The agency shall establish usage restrictions and implementation guidance for each type of remote access allowed, and authorize each type of remote access prior to allowing such connections. | ADSelfService Plus enforces authentication policies at VPN, RDP, and OWA entry points, ensuring only authorized users can initiate remote sessions to CJI systems. |
| IA-2 [P1] — MFA for remote sessions | Multi-factor authentication shall be employed for access to both privileged and non-privileged accounts—including remote access sessions. | ADSelfService Plus endpoint MFA enforces two or more authentication factors across VPN, RDP, OWA, and cloud application logins, satisfying the IA-2 MFA mandate for all remote CJI access. |
| IA-4 [P2] — Unique identification | Each person authorized to access CJI shall be uniquely identified. Authentication factors shall be specific to an individual and shall not be shared between multiple users. | ADSelfService Plus uniquely stores and identifies each user, assigning authenticators individually and prohibiting the sharing of authentication factors across users. |
Simplify CJIS compliance with ADSelfService Plus
ADSelfService Plus offers the Password Policy Enforcer, access policies, and MFA capabilities to help your organization meet CJIS v6.0 password requirements and authentication standards.
Password Policy Enforcer
The Password Policy Enforcer allows you to enforce a custom password policy that seamlessly integrates with built-in Active Directory and Entra ID password policies—during self-service password resets and password changes—helping you meet CJIS authenticator management requirements:
- Screen against breach databases: Block compromised passwords at the point of creation by screening against Have I Been Pwned's breach corpus, satisfying the CJIS banned password list requirement.
- Maintain custom banned word lists: Add agency-specific terms to the banned list to block context-specific passwords as required by CJIS policy.
- Enforce length and history requirements: Set a minimum password length and prevent reuse of prior passwords across all Active Directory and Entra ID users.
- Suppress password hints: Disable stored password hints during identity verification, in compliance with CJIS policy.
- Provide real-time password feedback: Display which policy rules are satisfied as the user types, reducing failed attempts and help desk calls.
- Enforce policy across all change channels: Apply consistent rules across the self-service portal, mobile app, Windows Ctrl+Alt+Del screen, and ADUC console.
Endpoint MFA
ADSelfService Plus offers endpoint MFA for both Active Directory-joined and Entra ID-joined systems, helping your organization meet the CJIS mandate for MFA across all CJI access points:
- Enforce two-factor authentication: Authenticate users with adaptive MFA in addition to their username and password, satisfying the CJIS requirement for two or more authentication factors.
- Choose from 20+ authenticators: Select from authenticators spanning all three CJIS-recognized factor categories, including FIDO2 security keys, biometrics, smart cards, PIV certificates, push notifications, YubiKey, Duo Security, and RSA SecurID.
- Secure all CJI access points: Enforce MFA across endpoint logins, VPN sessions, OWA, RDP, and cloud applications, covering both local and remote access.
- Support offline authentication: Enable offline MFA using a locally cached authenticator state for field officers and remote workers authenticating before a VPN connection is established.
- Apply stricter controls to privileged accounts: Enforce stronger authentication factors for administrator and privileged accounts independently of standard user policies.
- Prevent concurrent sessions: Block multiple active sessions for a single user simultaneously, supporting CJIS concurrent session controls.
Highlights of ADSelfService Plus
Password self-service
Eliminate lengthy help desk calls for Windows Active Directory users by empowering them with self-service password reset and account unlock capabilities.
One identity with single sign-on
Get seamless one-click access to more than 100 cloud applications. With enterprise single sign-on, users can access all their cloud applications using their Windows Active Directory credentials.
Password synchronization
Synchronize Windows Active Directory user passwords and account changes across multiple systems automatically, including Microsoft 365, Google Workspace, IBM iSeries, and more.
MFA
Enable context-based MFA with 20 different authentication factors for endpoint, application, VPN, OWA, and RDP logins.
Password and account expiration notifications
Notify Windows Active Directory users of their impending password and account expiration via email and SMS notifications.
Password Policy Enforcer
Strong passwords resist various hacking threats. Enforce Windows Active Directory users to adhere to compliant passwords by displaying password complexity requirements.
Frequently asked questions
Under CJIS v6.1 IA-5, the minimum password length is 8 characters for subscriber-chosen passwords and 6 characters for verifier-assigned passwords. No additional complexity requirements are imposed. ADSelfService Plus's Password Policy Enforcer allows administrators to configure and enforce the minimum length requirement across Active Directory and Entra ID users.
CJIS login requirements include unique user identification (IA-4), multi-factor authentication combining at least two factor types for all CJI access (IA-2), a maximum of five consecutive invalid login attempts within a 15-minute period before automatic account lockout until released by an administrator (AC-7), and prevention of concurrent active sessions for a single user ID unless operationally authorized (AC-2, AC-12). MFA became mandatory under CJIS version 5.9.5 and was reinforced in v6.1. ADSelfService Plus directly addresses each of these controls through its MFA, Password Policy Enforcer, and account lockout configuration capabilities.
CJIS v6.0 explicitly restructured its password requirements to align with NIST SP 800-63B, replacing composition rules and mandatory periodic rotation with length-based standards, breach-based screening, and compromise-triggered resets. ADSelfService Plus supports this alignment through its Password Policy Enforcer for length and complexity controls, its Have I Been Pwned integration for breach screening at the point of password change, and its admin-triggered forced reset capability for responding to compromise events.