We recently updated our security policy in ics-2022 to enforce MFA for all users accessing the HR core module. The policy shows as active in the Security Management console, but users are still able to log in with just username and password without being prompted for the second factor.
I’ve verified that MFA is enabled at the tenant level and users have enrolled their authentication devices (mostly Microsoft Authenticator and SMS). The strange part is that MFA works correctly for other modules like financial accounting and procurement - it’s only HR core where it’s not being enforced.
I’m concerned about security compliance since HR core contains sensitive employee data. Has anyone dealt with MFA policy assignment issues specific to certain modules? I’m wondering if there’s a policy override setting I’m missing or if the audit logs would show why the MFA requirement is being bypassed.
Here’s the complete solution addressing all three focus areas:
MFA Policy Assignment Correction:
The root cause is module-specific authentication rules overriding your tenant-wide MFA policy. To properly enforce MFA in HR core:
Navigate to HR Administration > Security Settings > Authentication Rules
Identify all rules with ‘MFA Required’ set to ‘No’ or ‘Optional’
For the ‘Internal Users - Password Only’ rule:
Change ‘MFA Required’ from ‘No’ to ‘Yes’
Set ‘MFA Methods’ to allow both ‘Authenticator App’ and ‘SMS’ (match your tenant settings)
Update ‘Rule Priority’ if needed - ensure no lower-priority rules can override
Create an exception rule for service accounts:
Rule Name: ‘Service Accounts - API Access’
Authentication Type: ‘OAuth Client Credentials’
Applies To: Security group ‘SVC_ACCOUNTS_HR’
Priority: Higher than interactive user rules
MFA Required: N/A (token-based authentication)
Policy Override Investigation:
ics-2022 has a complex policy hierarchy that you must understand:
Module rules (Priority 1-100): Highest precedence - evaluated first
Role-based policies (Priority 101-200): Applied if no module rule matches
Tenant-wide settings (Priority 201+): Fallback when no specific rules apply
To audit all potential overrides:
Security Management > Policy Analyzer > Run MFA Compliance Check
This will list all rules that could bypass MFA requirements
Review each rule’s ‘Effective Users’ count and ‘Last Applied’ timestamp
Look for rules with broad scope (e.g., ‘All Internal Users’) that might inadvertently include HR core users
Common override scenarios in HR core:
Legacy ‘HR_ADMIN’ role may have MFA exemption from pre-MFA era
Emergency access accounts with ‘Password Only’ flag set
Import/integration user accounts with relaxed authentication
Audit Log Analysis:
The audit logs are critical for understanding why MFA was bypassed. Enable detailed authentication logging:
System Configuration > Audit Settings > Authentication Events: Enable ‘Detailed’
Review logs for pattern: `event_type=LOGIN AND module=HR_CORE AND mfa_status=BYPASSED
Key fields to examine:
policy_rule_matched: Shows which rule was applied
bypass_reason: Explains why MFA was skipped
user_role: May reveal role-based policy issues
authentication_source: Distinguishes UI vs API access
For your specific case, the logs showing ‘MODULE_POLICY_OVERRIDE’ confirm that the HR core module rule took precedence over your tenant MFA policy. After updating the rule, verify with a test login and check logs for:
mfa_status=REQUIRED
policy_rule_matched=Internal Users - Password Only (Modified)
mfa_method_used=authenticator_app
authentication_result=SUCCESS
Post-Implementation Validation:
Test with multiple user types:
Regular HR users: Should require MFA
HR administrators: Should require MFA
Service accounts: Should use OAuth tokens (no MFA prompt)
Emergency access: Define clear exception process
Monitor compliance:
Run weekly reports on MFA enforcement rates
Set up alerts for any ‘MFA_BYPASSED’ events in HR core
Review exception rules monthly to ensure they’re still necessary
Document the policy hierarchy in your security runbook so future administrators understand why module-specific rules exist and how they interact with tenant policies.
The key lesson: Always check module-level authentication settings when tenant-wide policies don’t seem to apply. ics-2022’s granular security model provides flexibility but requires careful policy management to avoid gaps.
This draft is based on general Infor CloudSuite knowledge. It has not been verified against your specific version and environment. Practitioners: verify the steps and share your experience below.
Check the module-level security settings. HR core has its own authentication policy layer that can override tenant-wide settings. Go to HR Administration > Security Settings > Authentication Rules and see if there’s a legacy policy still active that allows password-only authentication. These module policies take precedence over global MFA settings.
You’re right - I found an authentication rule in HR core labeled ‘Internal Users - Password Only’ with priority 1. It was created before we implemented MFA and I didn’t realize it would override the tenant policy. Should I just delete this rule or modify it to require MFA?
Don’t delete it outright - you might have legitimate exceptions like service accounts or emergency access accounts. Instead, modify the rule to add an MFA requirement and set specific user groups as exceptions if needed. Make sure to review the rule’s scope - it might be applying to a broader user base than intended. Also check if there are multiple authentication rules with different priorities that could conflict.
I’ve implemented MFA across multiple CloudSuite modules and there’s a critical detail about policy precedence in ics-2022. The authentication engine evaluates rules in this order: module-specific rules (highest priority), role-based policies, then tenant-wide settings (lowest priority). If any higher-priority rule allows password-only authentication, it will bypass MFA requirements from lower-priority policies. You need to audit all authentication rules in HR core, not just the obvious ones. Look for rules associated with specific roles like HR_MANAGER or HR_ADMIN that might have less restrictive authentication requirements. Also check the audit logs - they’ll show which policy rule was applied during each login attempt and why MFA was skipped.
I checked the audit logs and found that the ‘Internal Users - Password Only’ rule is indeed being matched for HR core logins. The logs show ‘MFA_REQUIREMENT: BYPASSED’ with reason ‘MODULE_POLICY_OVERRIDE’. I’ve modified the rule to require MFA but now I’m worried about service accounts that use HR core APIs. How do I exclude those from MFA without creating a security gap?
Service accounts should use API keys or OAuth client credentials, not user authentication flows. Create a separate authentication rule specifically for API access that uses token-based authentication instead of MFA. Make sure these service accounts are in a dedicated security group and the rule only applies to API endpoints, not interactive UI access.