NIST 800-171 Controls · Identification & Authentication
IA.2.084 — Allow temporary password use with immediate change requirement
Allow temporary password use for system logons with an immediate change to a permanent password.
What IA.2.084 means in plain English
When IT creates a new account or resets a forgotten password, they give the employee a temporary password. The system must force the employee to change that temporary password the very first time they log in — the employee should never be allowed to keep using the temporary password day-to-day. This is a standard feature in Windows and Microsoft 365: when you create an account, you check the box "User must change password at next logon." For your team, make this part of every new account setup and every password reset procedure.
The assessment question
“Is the "user must change password at next logon" flag set whenever a temporary or reset password is issued — and is it technically enforced so the user cannot bypass it?”
How to implement IA.2.084
- For every new Windows account creation or password reset, check the "User must change password at next logon" option in Active Directory Users and Computers or Azure AD.
- In Microsoft 365, when resetting a user's password, always leave the "Require this user to change their password when they first sign in" toggle enabled.
- Document this requirement as a mandatory step in your New Employee Onboarding and Password Reset procedures.
- Verify the enforcement by logging in with a reset account and confirming the password change prompt appears before any other action is possible.
- Train the helpdesk person (even if that is you, the owner) to never skip this step when creating or resetting accounts.
Evidence your assessor will ask for
- Screenshot of the new user creation screen showing "must change password at next logon" selected
- Password Reset Procedure document specifying mandatory temporary password with forced change
- Test log showing a newly reset account prompted for password change on first login
Does AI prompt monitoring help with this control? Honestly, no.
IA.2.084 is met through the remediation steps above, not through AI traffic controls — an AI prompt firewall neither satisfies nor substitutes for it. We map AI monitoring only to the controls it genuinely evidences (flow control, boundary protection, audit, and incident support); for the full picture of where it does help, see the mapping guide linked below.
Full mapping: which 800-171 controls AI prompt monitoring evidences →
More Identification & Authentication controls
Identify system users, processes, and devices
IA.1.077Authenticate identities of users, processes, and devices
IA.2.078Use multifactor authentication for local and network access
IA.2.079Employ replay-resistant authentication mechanisms
IA.2.080Prevent reuse of identifiers
IA.2.081Disable identifiers after defined period of inactivity
Score yourself against all 110 controls
The free ShieldReady assessment walks every NIST 800-171 requirement, computes your SPRS score, and shows exactly which gaps cost the most points.