"Ensure the most secure Authentication Methods are used" Change
under review
D
Dru DuBay
This control requires that FIDO2 security key, Microsoft Authenticator and Temporary Access Pass are enabled. Our focus is on Passkeys, as Microsoft Authenticator is no longer enough. When we disable Authenticator as an option, leaving only Passkeys and TAP, this control gets flagged.
In environments where we are pushing Passkeys as the new standard, we often disable Microsoft Authenticator as an option, primarily due to its Passwordless option. If you have the Passwordless option enabled, it changes the registration flow in the Microsoft Authenticator app and asks the user to register their device with the company, creating an extra step and change in the process. Users also question this part, as often this is their personal device.
I think this control is more about NOT USING weak authentication methods. But as it currently sits, we are being flagged for being more secure.
B
Ben Wildman
updated the status to
under review
Hi Dru, thanks for this, its under review just now.