3.5.9 — Change Temp Passwords Immediately
What It Says
Section titled “What It Says”Allow temporary password use for system logons with an immediate change to a permanent password.
What It Actually Means
Section titled “What It Actually Means”Every temporary password — for new accounts, password resets, unlocked accounts — must be changed on first login. The system forces it, it’s not optional.
Why: temp passwords are often simpler (IT needs to communicate them), known by the IT person who set them, and sometimes shared via insecure channels. They’re meant to be replaced immediately.
Three things to get right:
- Forced change on first login — the ‘User must change password at next logon’ flag is set
- Secure delivery — temp passwords aren’t emailed in plain text
- Short expiry — if the user doesn’t log in within 24 hours, the temp password expires
Pass or Fail
Section titled “Pass or Fail”Your assessor needs a “yes” to every row:
| # | Question | What “yes” looks like |
|---|---|---|
| 1 | Is temporary password use allowed only with an immediate change to a permanent password? | System forces password change on first login — ‘must change at next logon’ flag set |
What to Have Ready on Assessment Day
Section titled “What to Have Ready on Assessment Day”Documents they’ll review: Identification and authentication policy; procedures addressing authenticator management; system security plan; system configuration settings
People they’ll talk to: Personnel with account management responsibilities; personnel with information security responsibilities
Live demos they’ll ask for: Mechanisms implementing temporary password management
The Assessor’s Playbook
Section titled “The Assessor’s Playbook”These are the actual questions. Have answers ready.
- “Walk me through creating a new user account. Is the ‘must change at next logon’ flag set?”
- “How do you deliver temporary passwords to users? Is it secure?”
- “What happens if a temp password isn’t used within 24 hours?”
- “Show me a recently created account — was the password changed on first login?”
Where Companies Trip Up
Section titled “Where Companies Trip Up”No forced change flag. Account created without ‘must change at next logon’ — user keeps the temp password indefinitely.
Temp passwords emailed in plain text. IT sends ‘Your password is TempPass123!’ in an email. Use a secure delivery method — verbal, encrypted message, or secure portal.
No expiry on unused temp passwords. A temp password set for a new hire who doesn’t start for two weeks sits active and vulnerable. Set a 24-hour expiry.
How to Talk About This
Section titled “How to Talk About This”Connected Requirements
Section titled “Connected Requirements”| Requirement | Why it matters here |
|---|---|
| 3.5.7 — Password Rules | The permanent password must meet complexity requirements |
| 3.5.10 — Never Plain Text | Temp passwords must also be protected during delivery |
Implementation
Section titled “Implementation”Step-by-step guides for Microsoft 365, AWS, Azure, and GCP are available to Ancitus clients.
Start a conversation →CMMC Practice ID: IA.L2-3.5.9 | SPRS Weight: 1 point | POA&M Eligible: Yes