PCI DSS 8.4.1: MFA is implemented for all non-console access into the CDE for personnel with administrative
PCI DSS v4.0.1 control 8.4.1: the requirement in full, the 2 testing procedures an assessor uses to verify it, and the related controls in section 8.4.
Requirement 8: Identify Users and Authenticate Access to System Components › Section 8.4
MFA is implemented for all non-console access into the CDE for personnel with administrative access.
Summary
Administrators authenticate with more than a password to reach the cardholder data environment.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 8.4.1.a | Examine network and/or system configurations to verify MFA is required for all non-console into the CDE for personnel with administrative access. |
| 8.4.1.b | Observe administrator personnel logging into the CDE and verify that MFA is required. |
The narrowest of the three MFA controls and usually the first one implemented. Read the three together, because they overlap and only their union is the obligation: this one covers administrative non-console access to the CDE, 8.4.3 covers remote access from outside the network that could reach or affect the CDE, and 8.4.2 covers all non-console access into the CDE regardless of role or origin. An entity that implements this one alone has MFA for admins and nothing for everyone else, which is the common shape. However the factors are delivered, 8.5.1 governs how the MFA system itself must behave.
What to prepare
- The list of accounts with administrative access to CDE systems.
- Evidence MFA is enforced on each administrative path, including the ones that are not the main console.
- Coverage for third parties with administrative access, who are frequently outside the identity provider.
How to implement it
1. Enumerate administrative paths, not administrators. A jump host, a database client, a cloud provider API and an out-of-band management card are each a way in, and coverage is usually complete on the first and absent on the last.
2. Include vendors and support. External administrators are administrators; their access often predates the identity provider and sits outside it.
3. Treat this as the floor, not the ceiling. Meeting it does not meet 8.4.2, and reading it as the whole MFA obligation is the commonest misreading in Requirement 8.
4. Check emergency access. A break-glass administrator account exempted from MFA is a bypass, which 8.5.1 tests directly.
Where this commonly fails
- MFA for administrators taken as the whole requirement, leaving ordinary CDE access single-factor.
- Third-party administrators outside the enforcement point.
- Management interfaces and out-of-band access excluded because they are not the primary console.
- A break-glass account with MFA disabled and no documented, time-limited authorisation.
Related controls
Others in section 8.4:
| Control | What it requires |
|---|---|
| 8.4.2 | MFA is implemented for all non-console access into the CDE |
| 8.4.3 | MFA is implemented for all remote access originating from outside the entity’s network… |
← 8.3.11 · All controls · 8.4.2 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.